On Wed, 5 Aug 2026 22:09:09 GMT, Michael Strauß <[email protected]> wrote:

> Loading the project in IntelliJ fails during Gradle synchronization with 
> dependency verification errors for Groovy 4.0.28 artifacts. A normal 
> command-line task such as `gradlew help` does not reproduce the problem 
> because it does not request source artifacts for Gradle’s bundled Groovy 
> libraries. The underlying cause is that the Gradle 9.2 upgrade introduced 
> Groovy 4.0.28, but the committed verification metadata was never expanded for 
> the metadata files used specifically during IDE source resolution.
> 
> When IntelliJ imports the project with source downloading enabled, Gradle 
> attempts to attach sources for its local Groovy dependencies. Gradle performs 
> this resolution through its internal repository named Gradle Libs. The 
> project enables verification of dependency metadata:
> 
> <verify-metadata>true</verify-metadata>
> 
> 
> Source JARs are already trusted by the existing `*-sources.jar` rule. 
> Resolving those JARs, however, also requires Gradle module metadata and the 
> Groovy BOM metadata. These .module and .pom files are not present in 
> verification-metadata.xml, so Gradle rejects them.
> 
> This problem is fixed by adding checksums for the module metadata of every 
> Groovy 4.0.28 library bundled with Gradle 9.2.
> 
> ---------
> - [x] I confirm that I make this contribution in accordance with the [OpenJDK 
> Interim AI Policy](https://openjdk.org/legal/ai).

I also have this issue and solved it by adding:
`<trust file=".*groovy.*" regex="true"/>`, 
which really is not a good solution but worked for me. So thanks for solving 
this!

I can confirm this fixes the issue and is the correct way.

One question: How can we generate those entries in the future, e.g. for new 
Gradle versions?
When I run the command in the `README.txt` next to `verification-metadata.xml`, 
those entries are not added for me. Maybe we should update / add the steps into 
this file for the future?

-------------

Marked as reviewed by mhanl (Reviewer).

PR Review: https://git.openjdk.org/jfx/pull/2247#pullrequestreview-4889509877

Reply via email to