jdaugherty commented on code in PR #16408:
URL: https://github.com/apache/grails-core/pull/16408#discussion_r4184871136
##########
AGENTS.md:
##########
@@ -144,7 +144,7 @@ All managed dependency versions live in
`dependencies.gradle` (the single source
- **Do not suppress validation to work around a bump.** `allowedBomOverrides`
(per-project ext) and dependency exclusions are reserved for an explicit,
documented conflict or an agreed-upon workaround — never as a shortcut to
silence a version the BOM should simply manage. Comment the reason when you
must use one.
- **A dependency managed in more than one BOM must use the *same* version
everywhere.** Versions appear in `gradleBomDependencyVersions` (build tooling /
`grails-gradle-bom`), `bomDependencyVersions` (`grails-bom`), and per-BOM
`customBomVersions` blocks (e.g. `grails-hibernate7-bom`). `grails-bom`
re-declares the gradle-BOM constraints, and the Hibernate BOMs are consumed via
`enforcedPlatform`. Declaring one coordinate (e.g. `org.ow2.asm:asm`) at two
different versions across these maps produces irreconcilable strict constraints
and breaks `enforcedPlatform` resolution. Pin it once, consistently.
- **Only libraries the Grails project also works on may use a snapshot
version.** Between releases, `dependencies.gradle` often points at a
`-SNAPSHOT` or release-candidate version of one of our own libraries, such as
the Asset Pipeline (`cloud.wondrify`), SiteMesh 3 (`org.sitemesh`), or the
Grails Publish plugin (`org.apache.grails.gradle:grails-publish`). These are
switched to their published version before a Grails release (see `RELEASE.md`).
Do not suggest replacing them with a released version, and do not flag them in
reviews. Never use a snapshot of any other library, such as Jackson or Spring.
The snapshot repositories in `GrailsRepoSettingsPlugin` only serve the
`org.apache.grails*`, `org.apache.groovy*`, `cloud.wondrify*`, and
`org.sitemesh*` groups, so a snapshot of any other library will not resolve
(unless `GRAILS_INCLUDE_MAVEN_LOCAL` is set for a local build). Do not widen
those content filters to get one.
-- **Prefer inheriting from the Spring Boot BOM.** Do not re-pin a coordinate
that `spring-boot-dependencies` (4.1.x) already manages unless you are
intentionally overriding it to a newer version (e.g. a security fix); note the
reason inline.
+- **Prefer inheriting from the Spring Boot BOM.** Do not re-pin a coordinate
that `spring-boot-dependencies` (4.2.x) already manages unless you are
intentionally overriding it to a newer version (e.g. a security fix); note the
reason inline.
Review Comment:
Let's drop the specific version so this doesn't have to be updated over and
over?
##########
grails-skills/developer/skills/grails-developer/SKILL.md:
##########
@@ -30,9 +30,9 @@ Activate this skill when developing with Grails, including:
## Technology Stack
-Grails is built on:
-- **Spring Boot**: 4.1.x
-- **Spring Framework**: 7.0.x
+Current Grails is built on:
Review Comment:
Is the current really necessary?
##########
dependencies.gradle:
##########
@@ -75,37 +75,25 @@ ext {
'bootstrap-icons.version' : '1.13.1',
'bootstrap.version' : '5.3.8',
'checker-qual.version' : '3.55.1',
- 'commons-codec.version' : '1.22.1',
'geb-spock.version' : '8.0.1',
// Pinned deliberately as a drift tripwire even though it matches
Spring Boot's
// managed version: graphql-java-extended-scalars (below) is NOT
managed by Spring
// Boot and must be upgraded in lockstep with graphql-java.
Keeping this pin makes
// the dependency validator flag any Spring Boot graphql-java bump
so we re-check
// extended-scalars compatibility. See
https://github.com/apache/grails-core/issues/15674
- 'graphql-java.version' : '25.0',
+ 'graphql-java.version' : '26.1',
Review Comment:
There are breaking changes in 26.0 -
https://github.com/graphql-java/graphql-java/releases#release-v26.0 I see no
mention of this in the upgrade guide but it needs mentioned. We also need to
make sure the api changes (nullable returns) are not going to affect us.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]