Repository navigation
[improve][test] Upgrade test libraries - #26351
Merged
Merged
Conversation
- awaitility 4.2.0 -> 4.3.0 - hamcrest 2.2 -> 3.0 - objenesis 3.3 -> 3.6 - byte-buddy 1.17.7 -> 1.18.12 - kerby 2.1.1 -> 2.1.2 - consolecaptor 1.0.3 -> 1.0.4 - jsonassert 1.5.0 -> 1.5.3 - rest-assured 5.4.0 -> 5.5.7 - org.json 20231013 -> 20260814 - docker-java-core 3.4.1 -> 3.7.1 - WireMock 2.35.1 -> 3.13.2 WireMock also changes coordinates: com.github.tomakehurst:wiremock-jre8-standalone was discontinued after 3.0.1 and the 3.x line is published as org.wiremock:wiremock-standalone. The Java packages are unchanged (com.github.tomakehurst.wiremock.*), and the deprecated ResponseTransformer used by AsyncHttpConnectorTest is still present, so no test sources change. byte-buddy-agent is added to the version catalog so the enforced platform pins it to the same version as byte-buddy. Mockito depends on both, and Pulsar uses MockedStatic and MockedConstruction, which need the inline mock maker; letting the two artifacts diverge would break it. org.json 20260814 includes the fix for CVE-2026-59171 (unbounded BigInteger/BigDecimal parsing). It is a test-scope dependency. rest-assured stays on the 5.x line: 6.0.0 requires Groovy 5, an unpinned transitive that would change across four test modules at once. Testcontainers is left at 1.21.4, which is already the newest 1.x release; testng 7.12.0, mockito 5.23.0 and assertj 3.27.7 are also already current. Assisted-by: Claude Code (Opus 5)
nodece
approved these changes
Aug 18, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Motivation
The test-scope libraries in the version catalog have drifted behind. WireMock in particular is stuck
at 2.35.1 because the artifact it used was discontinued, and org.json 20231013 predates the fix for
CVE-2026-59171.
Modifications
gradle/libs.versions.toml:WireMock changes coordinates.
com.github.tomakehurst:wiremock-jre8-standalonewas discontinuedafter 3.0.1; the 3.x line is published as
org.wiremock:wiremock-standalone. The catalog entrychanges module, not just version. No test sources change: the Java packages are unchanged
(
com.github.tomakehurst.wiremock.*), and the deprecatedResponseTransformerthatAsyncHttpConnectorTestimplements is still present in 3.13.2 alongside itsResponseTransformerV2replacement.
byte-buddy-agentis added to the catalog. Mockito 5.23.0 declares bothbyte-buddyandbyte-buddy-agentat 1.17.7, and Pulsar usesMockedStatic/MockedConstruction, which need theinline mock maker. The catalog previously pinned only
byte-buddy, so raising it alone would haveleft the enforced platform pinning
byte-buddyat 1.18.12 whilebyte-buddy-agentstayed atMockito's 1.17.7. Declaring both keeps them in lockstep — verified via
./gradlew :pulsar-proxy:dependencies --configuration testRuntimeClasspath, which now shows bothresolving to 1.18.12.
rest-assured stays on the 5.x line. 6.0.0 raises the baseline to Java 17 (fine on its own) but
also requires Groovy 5. Groovy is an unpinned transitive of rest-assured, so that would move Groovy
4→5 across four test modules at once; 5.5.7 is the newest 5.x release.
Left unchanged, already current:
2.0.0, a new major line.
hamcrest 3.0 — the only documented breaking change is the Java 8 bytecode baseline. The three
classes Pulsar imports (
CoreMatchers,MatcherAssert,Matchers) were confirmed present in the3.0 jar.
org.json 20260814 includes the fix for CVE-2026-59171 (unbounded BigInteger/BigDecimal parsing).
It is a test-scope dependency in
pulsar-functions-utils.Verifying this change
This change is already covered by existing tests. Verified locally:
./gradlew sanityCheck— all main and test sources compile./gradlew checkBinaryLicenseAsyncHttpConnectorTest(9 tests) andAuthenticationProviderOpenIDIntegrationTest(21 tests) — both greenProxyExtensionUtilsTest,PulsarByteBufAllocator*TestandAuthenticationAthenzTest(16 tests total) — all greenpulsar-functions-utilsfull test suite (154 tests) — greenDoes this pull request potentially affect one of the following parts: