codeconsole commented on code in PR #16408:
URL: https://github.com/apache/grails-core/pull/16408#discussion_r4189917248


##########
grails-skills/developer/skills/grails-developer/SKILL.md:
##########
@@ -30,9 +30,9 @@ Activate this skill when developing with Grails, including:
 
 ## Technology Stack
 
-Grails is built on:
-- **Spring Boot**: 4.1.x
-- **Spring Framework**: 7.0.x
+Current Grails is built on:

Review Comment:
   No. The 9.0.x merge brought back this PR's older wording; aabcc10999 
restores "Grails is built on:".
   



##########
AGENTS.md:
##########
@@ -144,7 +144,7 @@ All managed dependency versions live in 
`dependencies.gradle` (the single source
 - **Do not suppress validation to work around a bump.** `allowedBomOverrides` 
(per-project ext) and dependency exclusions are reserved for an explicit, 
documented conflict or an agreed-upon workaround — never as a shortcut to 
silence a version the BOM should simply manage. Comment the reason when you 
must use one.
 - **A dependency managed in more than one BOM must use the *same* version 
everywhere.** Versions appear in `gradleBomDependencyVersions` (build tooling / 
`grails-gradle-bom`), `bomDependencyVersions` (`grails-bom`), and per-BOM 
`customBomVersions` blocks (e.g. `grails-hibernate7-bom`). `grails-bom` 
re-declares the gradle-BOM constraints, and the Hibernate BOMs are consumed via 
`enforcedPlatform`. Declaring one coordinate (e.g. `org.ow2.asm:asm`) at two 
different versions across these maps produces irreconcilable strict constraints 
and breaks `enforcedPlatform` resolution. Pin it once, consistently.
 - **Only libraries the Grails project also works on may use a snapshot 
version.** Between releases, `dependencies.gradle` often points at a 
`-SNAPSHOT` or release-candidate version of one of our own libraries, such as 
the Asset Pipeline (`cloud.wondrify`), SiteMesh 3 (`org.sitemesh`), or the 
Grails Publish plugin (`org.apache.grails.gradle:grails-publish`). These are 
switched to their published version before a Grails release (see `RELEASE.md`). 
Do not suggest replacing them with a released version, and do not flag them in 
reviews. Never use a snapshot of any other library, such as Jackson or Spring. 
The snapshot repositories in `GrailsRepoSettingsPlugin` only serve the 
`org.apache.grails*`, `org.apache.groovy*`, `cloud.wondrify*`, and 
`org.sitemesh*` groups, so a snapshot of any other library will not resolve 
(unless `GRAILS_INCLUDE_MAVEN_LOCAL` is set for a local build). Do not widen 
those content filters to get one.
-- **Prefer inheriting from the Spring Boot BOM.** Do not re-pin a coordinate 
that `spring-boot-dependencies` (4.1.x) already manages unless you are 
intentionally overriding it to a newer version (e.g. a security fix); note the 
reason inline.
+- **Prefer inheriting from the Spring Boot BOM.** Do not re-pin a coordinate 
that `spring-boot-dependencies` (4.2.x) already manages unless you are 
intentionally overriding it to a newer version (e.g. a security fix); note the 
reason inline.

Review Comment:
   Done in c3e575bbbd.
   



##########
dependencies.gradle:
##########
@@ -75,37 +75,25 @@ ext {
             'bootstrap-icons.version'       : '1.13.1',
             'bootstrap.version'             : '5.3.8',
             'checker-qual.version'          : '3.55.1',
-            'commons-codec.version'         : '1.22.1',
             'geb-spock.version'             : '8.0.1',
             // Pinned deliberately as a drift tripwire even though it matches 
Spring Boot's
             // managed version: graphql-java-extended-scalars (below) is NOT 
managed by Spring
             // Boot and must be upgraded in lockstep with graphql-java. 
Keeping this pin makes
             // the dependency validator flag any Spring Boot graphql-java bump 
so we re-check
             // extended-scalars compatibility. See 
https://github.com/apache/grails-core/issues/15674
-            'graphql-java.version'          : '25.0',
+            'graphql-java.version'          : '26.1',

Review Comment:
   5d176de0da adds an "Upgrading from Grails 9.0 to Grails 9.1" section 
covering the 26.0 changes that reach a Grails app:
   - Query complexity limits are on by default (depth 100, 100,000 fields); 
`QueryComplexityLimits.setDefaultLimits(...)` changes or disables them. 
`QueryComplexityLimitsSpec` runs this against the plugin's generated schema.
   - Code-built schemas now reject a deprecated non-null argument or input 
field. The plugin only deprecates output fields, so its schema is unaffected.
   - Additional schema types must be named types; `Schema` already unwraps what 
interceptors add (31edfada06).
   
   Nullable returns: of the 115 graphql-java methods the plugin calls, 4 gained 
`@Nullable` in 26. `ExecutionResult.getData()`/`getExtensions()` are already 
handled in the controller, and all three `Field.getSelectionSet()` call sites 
in `EntityFetchOptions` null-check. `TypeResolutionEnvironment.getObject()` is 
never null, because `completeValue` returns before `resolveType` for a null 
value. The annotations don't change runtime behaviour. The validation rule 
predicate, `DirectiveInfo` and OneOf changes don't touch the plugin.
   



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to