Skip to content

[improve][build] Upgrade Gradle plugins and move to the io.github.ben-manes.versions plugin id - #26350

Merged
nodece merged 1 commit into
apache:masterfrom
lhotari:lh-improve-gradle-plugins
Aug 18, 2026
Merged

nodece merged 1 commit into
apache:masterfrom
lhotari:lh-improve-gradle-plugins

Conversation

@lhotari

@lhotari lhotari commented Aug 17, 2026

Copy link
Copy Markdown
Member

Motivation

Several Gradle build plugins are behind. Separately, the com.github.ben-manes.versions plugin id
is now deprecated in favour of io.github.ben-manes.versions, to match current Gradle Plugin Portal
policy; the old id still receives releases but logs a deprecation warning on every build that applies
it.

Modifications

gradle/libs.versions.toml:

plugin from to
spotless 8.4.0 8.10.0
version-catalog-update 1.1.0 1.1.1
crlf (vlsi) 3.0.1 4.0.0
versions (ben-manes) com.github.ben-manes.versions:0.53.0 io.github.ben-manes.versions:0.61.0

The versions plugin is applied through alias(libs.plugins.versions) in the root build script, so
changing the coordinate in the catalog is sufficient — no build script edit is needed.

The remaining build plugins are already on their latest releases and are left unchanged:
shadow 9.6.1, graalvm-buildtools 1.1.9, rat 0.8.1, nar 0.1.3, idea-ext 1.4.1 and
protobuf 0.10.0. The swagger Gradle plugin tracks the shared swagger version reference and is
handled in the misc-libraries PR.

The vlsi crlf 4.x line requires Gradle 8.3+, Kotlin 1.9 and Java 8. Pulsar builds with Gradle 9.7, so
the floor is met.

lightproto is deliberately excluded

lightproto 0.8.0 is available but is not included here, because it is not a build-only change.
Regenerating the protocol sources against 0.8.0 and diffing them against 0.7.3 shows that the
generated serialization code path is rewritten:

  • writes move from Unsafe-style direct memory access (memoryAddress(), BYTE_ARRAY_BASE_OFFSET)
    to an array/scratch-buffer path, adding a per-message _scratch byte[] field;
  • field presence tracking moves from sentinel values to _bitField0 masks;
  • a new class is generated into the io.netty.buffer package to reach AbstractByteBuf's protected
    _getByte accessor and its readerIndex field directly, deliberately skipping Netty's per-byte
    bounds checks. Its own javadoc notes that it "creates a split package with netty-buffer under the
    JPMS module path" and that on truncated input a read may advance up to 9 bytes past the intended
    message limit.

That touches Pulsar's hottest serialization path and warrants its own PR with benchmarking, so it is
left for a follow-up.

Verifying this change

  • Make sure that the change passes the CI checks.

This change is a trivial rework / code cleanup without any test coverage.

Verified locally with ./gradlew quickCheck, ./gradlew sanityCheck and
./gradlew checkBinaryLicense (the last one builds both distributions, which exercises the crlf
plugin).

Does this pull request potentially affect one of the following parts:

  • Dependencies (add or upgrade a dependency)
  • The public API
  • The schema
  • The default values of configurations
  • The threading model
  • The binary protocol
  • The REST endpoints
  • The admin CLI options
  • The metrics
  • Anything that affects deployment

…-manes.versions plugin id

- spotless               8.4.0  -> 8.10.0
- version-catalog-update  1.1.0  -> 1.1.1
- crlf (vlsi)             3.0.1  -> 4.0.0
- versions (ben-manes)    0.53.0 -> 0.61.0, and the plugin id moves from
                          com.github.ben-manes.versions to io.github.ben-manes.versions

The com.github.ben-manes.versions plugin id is deprecated in favour of
io.github.ben-manes.versions, to match current Gradle Plugin Portal policy. The old id
still receives releases but logs a deprecation warning when applied.

The vlsi crlf 4.x line requires Gradle 8.3+, Kotlin 1.9 and Java 8; Pulsar builds with
Gradle 9.7, so the floor is met.

The remaining build plugins are already on their latest releases and are unchanged:
shadow 9.6.1, graalvm-buildtools 1.1.9, rat 0.8.1, nar 0.1.3, idea-ext 1.4.1 and
protobuf 0.10.0.

lightproto is deliberately left at 0.7.3 here and handled separately: 0.8.0 rewrites the
generated serialization code path, so it does not belong in a build-plugin bump.

Assisted-by: Claude Code (Opus 5)
@lhotari lhotari added the area/dependency Pull requests that update a dependency file label Aug 17, 2026
@lhotari lhotari added this to the 5.0.0-M2 milestone Aug 17, 2026
@nodece
nodece merged commit ac2b2d2 into apache:master Aug 18, 2026
51 of 53 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/dependency Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants