renovate-bot opened a new pull request, #6822: URL: https://github.com/apache/jmeter/pull/6822
This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [gradle/actions](https://redirect.github.com/gradle/actions) | action | minor | `v6.3.0` → `v6.4.0` | --- ### Release Notes <details> <summary>gradle/actions (gradle/actions)</summary> ### [`v6.4.0`](https://redirect.github.com/gradle/actions/releases/tag/v6.4.0) [Compare Source](https://redirect.github.com/gradle/actions/compare/v6.3.0...v6.4.0) #### Highlights ##### Gradle version support status in the Job Summary The actions now report the support status of every Gradle version used in a workflow, as job annotations and in the Job Summary ([#​1057](https://redirect.github.com/gradle/actions/issues/1057)). Thanks to [@​ov7a](https://redirect.github.com/ov7a) for the contribution. | version kind | job annotation | version table | below the table | | --------------------------------------------------------------------------------------- | -------------- | --------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------- | | **End-of-life** — two or more major versions behind the latest release | warning | :warning: | expandable section naming the affected release lines, pointing at the [Gradle Security Subscription](https://gradle.org/security-subscription/) | | **Out of date** — one major behind, or more than two minors behind on the current major | notice | :information\_source: | one-line legend pointing at the [Gradle release lifecycle](https://docs.gradle.org/current/userguide/feature_lifecycle.html#eol_support) docs | | **Current** | none | — | — | Deliberately *not* reported: patch releases (being on `9.7.0` when `9.7.1` exists is not flagged) and pre-releases (release candidates, milestones and snapshots never produce annotations). The latest Gradle release is determined from the wrapper checksum data already bundled with the action, so no network access is required. Note that these annotations are emitted independently of the `add-job-summary` setting: setting `add-job-summary: 'never'` suppresses the Job Summary itself, but the warning and notice annotations remain. ##### Gradle itself is now reported in the dependency graph The `dependency-submission` action now applies **v1.5.0** of the [GitHub Dependency Graph Gradle Plugin](https://redirect.github.com/gradle/github-dependency-graph-gradle-plugin) (up from v1.4.2) ([#​1069](https://redirect.github.com/gradle/actions/issues/1069)). The headline change is that the Gradle Build Tool running the build is now reported as an `org.gradle:gradle-core` dependency, so that **GitHub can surface known vulnerabilities in the version of Gradle used to run your build**. These are the coordinates that GitHub advisories for the Gradle Build Tool are published against. Details worth knowing: - The entry is always reported as a **direct** dependency with **development** scope. - It is **not** affected by the project, configuration or scope filters, so it appears even in graphs that filter aggressively. - Expect dependency graphs to gain this one new entry the first time a build runs after upgrading. ##### A new Gradle signing key, if you use dependency verification > \[!IMPORTANT] > If your build has [dependency verification](https://docs.gradle.org/current/userguide/dependency_verification.html#sec:signature-verification) > enabled, you must add a **second** trusted key before upgrading, or Dependency Graph generation will > fail signature verification. `github-dependency-graph-gradle-plugin` `1.5.0` is signed with a new Gradle signing subkey, and the key previously documented in our setup guide has been revoked upstream: | Artifact | Signing key | | -------------------------------------------------------------------- | --------------------------------------------------------- | | `org.gradle:github-dependency-graph-gradle-plugin` `1.5.0` and later | `E2879931BCA1A42E55F2D64DD9B2DFBD9F3298BA` (new) | | `org.gradle` plugin versions before the rotation | `7B79ADD11F8A779FE90FD3D0893A028475557671` (old, revoked) | | `com.gradle` Develocity Gradle plugin, including `4.5.0` | `7B79ADD11F8A779FE90FD3D0893A028475557671` (old, revoked) | Because the Develocity Gradle plugin is still signed with the old key, you should trust **both** keys rather than swapping one for the other — replacing the old key outright will break Develocity injection. The documented snippet in [docs/setup-gradle.md](https://redirect.github.com/gradle/actions/blob/3f5f9adaf7d9fecd50b5935e54106014257a94e6/docs/setup-gradle.md#dependency-verification) has been updated accordingly ([#​1071](https://redirect.github.com/gradle/actions/issues/1071)): ```xml <trusted-keys> <trusted-key id="7B79ADD11F8A779FE90FD3D0893A028475557671"> <trusting group="com.gradle"/> <trusting group="org.gradle"/> </trusted-key> <trusted-key id="E2879931BCA1A42E55F2D64DD9B2DFBD9F3298BA"> <trusting group="org.gradle"/> </trusted-key> </trusted-keys> ``` ##### `cache-provider: external` for externally managed Gradle User Home Builds that save and restore Gradle User Home by some other mechanism (Develocity Artifact Cache, for example) previously had to set `cache-disabled: true`, which was misleading: caching wasn't disabled, it just wasn't managed by this action, and the Job Summary reported it as "Disabled". `cache-provider: external` skips Gradle User Home restore/save exactly as `cache-disabled` does, but reports a distinct **External** status in the Job Summary explaining that caching is handled by another provider ([#​1059](https://redirect.github.com/gradle/actions/issues/1059)). ```yaml - uses: gradle/actions/setup-gradle@v6 with: cache-provider: 'external' ``` ##### Develocity access keys containing OIDC tokens now work Short-lived-token handling validated the `server=key[;server=key]*` access key format with a regex whose `key` portion was too strict, so an access key holding an OIDC token value was rejected outright. Worse, had it passed the regex, parsing split each entry on `=` and kept only the second field — silently **truncating** any key containing `=` (as JWT padding does) and sending the mangled key to the server. Both problems are fixed ([#​1061](https://redirect.github.com/gradle/actions/issues/1061)). ##### Job Summary attribution Job summaries produced by `setup-gradle` and `dependency-submission` now carry a top-level heading naming the action, so the block stays attributable when another action's summary content lands in the same job ([#​1058](https://redirect.github.com/gradle/actions/issues/1058)). ##### Updated defaults - GitHub Dependency Graph Gradle Plugin: **1.4.2 → 1.5.0** - 5 new known-good wrapper checksums for `wrapper-validation` (368 → 373 entries) #### What's Changed - Bump the github-actions group across 3 directories with 6 updates by [@​dependabot](https://redirect.github.com/dependabot)\[bot] in [#​1039](https://redirect.github.com/gradle/actions/pull/1039) - Bump the npm-dependencies group in /sources with 3 updates by [@​dependabot](https://redirect.github.com/dependabot)\[bot] in [#​1038](https://redirect.github.com/gradle/actions/pull/1038) - Add action heading to Gradle job summary by [@​bigdaz](https://redirect.github.com/bigdaz) in [#​1058](https://redirect.github.com/gradle/actions/pull/1058) - Add cache-provider: external to skip Gradle User Home caching by [@​bigdaz](https://redirect.github.com/bigdaz) in [#​1059](https://redirect.github.com/gradle/actions/pull/1059) - Relax Develocity access key format validation by [@​bigdaz](https://redirect.github.com/bigdaz) in [#​1061](https://redirect.github.com/gradle/actions/pull/1061) - Use the root-qualified `:wrapper` task by [@​cobexer](https://redirect.github.com/cobexer) in [#​1064](https://redirect.github.com/gradle/actions/pull/1064) - Report EOL and maintenance status for Gradle versions by [@​ov7a](https://redirect.github.com/ov7a) in [#​1057](https://redirect.github.com/gradle/actions/pull/1057) - Update dependencies by [@​bigdaz](https://redirect.github.com/bigdaz) in [#​1065](https://redirect.github.com/gradle/actions/pull/1065) - Update .tool-versions: node 24.18.0, gradle 9.7.1, java 17 by [@​bigdaz](https://redirect.github.com/bigdaz) in [#​1068](https://redirect.github.com/gradle/actions/pull/1068) - Combined automated updates: wrapper checksums, npm dependencies, setup-java by [@​bigdaz](https://redirect.github.com/bigdaz) in [#​1070](https://redirect.github.com/gradle/actions/pull/1070) - Bump dependency-graph-gradle-plugin to 1.5.0 by [@​bigdaz](https://redirect.github.com/bigdaz) in [#​1069](https://redirect.github.com/gradle/actions/pull/1069) - Document the new Gradle signing key for dependency verification by [@​bigdaz](https://redirect.github.com/bigdaz) in [#​1071](https://redirect.github.com/gradle/actions/pull/1071) #### New Contributors - [@​cobexer](https://redirect.github.com/cobexer) made their first contribution in [#​1064](https://redirect.github.com/gradle/actions/pull/1064) - [@​ov7a](https://redirect.github.com/ov7a) made their first contribution in [#​1057](https://redirect.github.com/gradle/actions/pull/1057) **Full Changelog**: <https://github.com/gradle/actions/compare/v6.3.0...v6.4.0> </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - "every 3 weeks on Monday" - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/apache/jmeter). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMjUuMSIsInVwZGF0ZWRJblZlciI6IjQ0LjEyNS4xIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==--> -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
