matrei opened a new pull request, #16526:
URL: https://github.com/apache/grails-core/pull/16526

   Adds an `org.webjars*` ignore to the three `/grails-forge` Dependabot 
entries for 7.0.x, 7.1.x and 7.2.x. The pattern also covers the 
`org.webjars.npm` and `org.webjars.bower` groups.
   
   The webjars pinned by the test example apps and the spring-security-ui 
plugin are referenced by versioned asset paths (e.g. 
`webjars/bootstrap/3.3.6/...`). Dependabot only changes the build file, so its 
bumps leave those paths pointing at a version that is no longer on the 
classpath. The recent PRs also showed two other problems:
   
   - #16439, #16440, #16445 applied Bootstrap 3.3.7-1 to every example that 
declares `org.webjars:bootstrap`, which downgraded the `ldap` examples from 
4.1.3.
   - #16438, #16441, #16444 bumped `jquery-ui-themes` to 1.10.4-1, a version 
that was never published, so every build failed.
   
   Webjar updates in these apps need the asset paths changed in the same 
commit, so they are better done by hand. See the discussion in 
https://github.com/apache/grails-core/pull/16519#issuecomment-5999067824.
   
   Dependabot reads its configuration from the default branch, so this takes 
effect once it is merged up to 8.0.x.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to