For the past two weeks I've been dreading the first of the month…. Well dreading, but also super curious. How many PR’s will Solrbot open? What new challenging dependency upgrades will we have to tackle? Will it ever end.
I just rewatched Pacific Rim with the teen, and the challenges of fighting of the Kaiju are somewhat similar to the challenges of fighting off dependency upgrades. Dealing with dependency updates is a “must do” thing, not a “yay, this is fun” thing. So, last night the breach between our nice stable up to date Solr and the rest of the software ecosystem opened up again (thanks Solrbot and Jan’s hard work!) and the dependencies came marching through. Every few minutes another PR popped open…. Boom boom boom, 17 brand new PRs that someone has to deal with. At first I was a bit bummed…. I thought it might be just a few PRs after all the hardworking we’ve done to catch up on dependencies. But then I thought about the “We are cancelling the apocalypse” speech that the given in the movie (https://johnjronline.wordpress.com/2021/04/08/pacific-rim-2013-we-are-canceling-the-apocalypse-scene-9-10-movieclips/) and I thought…. What can I learn from that movie? One thing is that our dependency updates are sometimes easy to deal with and other times really challenging. In Pacific Rim, the Kaiju come in different “categories” from an easy Category 1 to a terrifying Category 5 (and up!)…. Wouldn’t it be nice to categorize our dependency updates so we know how much thinking is needed for each one? Likewise, by naming the individual Kaiju, it makes it easier to refer to them, understand their specific characteristics (can they fly, do they have acid breathe, etc). Maybe we can name our Dependency updates as well? We kind of almost do that with the grouping logic that Solrbot uses anyway. Plus, honestly, how can I make dependency management more fun? So, with that long preamble, here are this month’s Breach Report: https://claude.ai/artifact/HxtVJmaE3wcExeptY7yLgW?sk=HG4tZy6ogQKaewKqcEPvWg Cat Name PR Title V Slattern Revamp Solr Extraction Module to work with Tika 4 IV Otachi Update Jersey jetty-http to v3 (branch_9x) III Knifehead Update all non-major dependencies III Yamarashi Update gRPC and Netty III Atticon Update Web server stack to v12.1.13 II Raythe Update Telemetry (OpenTelemetry & Prometheus) II Clawhook Update AWS SDK to v2.55.6 II Onibaba Update Jackson BOM to v2.22.3 II Androc Update Google Cloud II Itak Update Logging to v2.0.20 II Ragnarok Update ZooKeeper & Curator to v3.9.6 II Crusherbone Update Jackson BOM to v2.22.3 (branch_9x) I Hardship Update Avatica-core to v1.29.0 I Hammerjaw Update Admin UI I Ceptid Update Okio to v3.18.2 I Tengu Update GitHub Actions I Karloff Update GitHub Actions (branch_9x) I Erupture Update all non-major test dependencies (branch_9x) Disclaimer The information contained in this communication from the sender is confidential. It is intended solely for use by the recipient and others authorized to receive it. If you are not the recipient, you are hereby notified that any disclosure, copying, distribution or taking action in relation of the contents of this information is strictly prohibited and may be unlawful. This email has been scanned for viruses and malware, and may have been automatically archived by Mimecast, a leader in email security and cyber resilience. Mimecast integrates email defenses with brand protection, security awareness training, web security, compliance and other essential capabilities. Mimecast helps protect large and small organizations from malicious activity, human error and technology failure; and to lead the movement toward building a more resilient world. To find out more, visit our website.
