Skip to content

[improve][test] Upgrade test libraries - #26351

Merged
nodece merged 1 commit into
apache:masterfrom
lhotari:lh-improve-test-libs
Aug 18, 2026
Merged

nodece merged 1 commit into
apache:masterfrom
lhotari:lh-improve-test-libs

Conversation

@lhotari

@lhotari lhotari commented Aug 17, 2026

Copy link
Copy Markdown
Member

Motivation

The test-scope libraries in the version catalog have drifted behind. WireMock in particular is stuck
at 2.35.1 because the artifact it used was discontinued, and org.json 20231013 predates the fix for
CVE-2026-59171.

Modifications

gradle/libs.versions.toml:

library from to
awaitility 4.2.0 4.3.0
hamcrest 2.2 3.0
objenesis 3.3 3.6
byte-buddy 1.17.7 1.18.12
kerby 2.1.1 2.1.2
consolecaptor 1.0.3 1.0.4
jsonassert (skyscreamer) 1.5.0 1.5.3
rest-assured 5.4.0 5.5.7
org.json 20231013 20260814
docker-java-core 3.4.1 3.7.1
WireMock 2.35.1 3.13.2

WireMock changes coordinates. com.github.tomakehurst:wiremock-jre8-standalone was discontinued
after 3.0.1; the 3.x line is published as org.wiremock:wiremock-standalone. The catalog entry
changes module, not just version. No test sources change: the Java packages are unchanged
(com.github.tomakehurst.wiremock.*), and the deprecated ResponseTransformer that
AsyncHttpConnectorTest implements is still present in 3.13.2 alongside its ResponseTransformerV2
replacement.

byte-buddy-agent is added to the catalog. Mockito 5.23.0 declares both byte-buddy and
byte-buddy-agent at 1.17.7, and Pulsar uses MockedStatic / MockedConstruction, which need the
inline mock maker. The catalog previously pinned only byte-buddy, so raising it alone would have
left the enforced platform pinning byte-buddy at 1.18.12 while byte-buddy-agent stayed at
Mockito's 1.17.7. Declaring both keeps them in lockstep — verified via
./gradlew :pulsar-proxy:dependencies --configuration testRuntimeClasspath, which now shows both
resolving to 1.18.12.

rest-assured stays on the 5.x line. 6.0.0 raises the baseline to Java 17 (fine on its own) but
also requires Groovy 5. Groovy is an unpinned transitive of rest-assured, so that would move Groovy
4→5 across four test modules at once; 5.5.7 is the newest 5.x release.

Left unchanged, already current:

  • Testcontainers stays at 1.21.4 — that is already the newest 1.x release; the next release is
    2.0.0, a new major line.
  • testng 7.12.0, mockito 5.23.0, assertj 3.27.7 (4.0.0-M1 is a milestone).

hamcrest 3.0 — the only documented breaking change is the Java 8 bytecode baseline. The three
classes Pulsar imports (CoreMatchers, MatcherAssert, Matchers) were confirmed present in the
3.0 jar.

org.json 20260814 includes the fix for CVE-2026-59171 (unbounded BigInteger/BigDecimal parsing).
It is a test-scope dependency in pulsar-functions-utils.

Verifying this change

  • Make sure that the change passes the CI checks.

This change is already covered by existing tests. Verified locally:

  • ./gradlew sanityCheck — all main and test sources compile
  • ./gradlew checkBinaryLicense
  • WireMock 3.13.2: AsyncHttpConnectorTest (9 tests) and
    AuthenticationProviderOpenIDIntegrationTest (21 tests) — both green
  • Mockito inline mock maker on byte-buddy 1.18.12 / objenesis 3.6: ProxyExtensionUtilsTest,
    PulsarByteBufAllocator*Test and AuthenticationAthenzTest (16 tests total) — all green
  • org.json / jsonassert / WireMock: pulsar-functions-utils full test suite (154 tests) — green

Does this pull request potentially affect one of the following parts:

  • Dependencies (add or upgrade a dependency)
  • The public API
  • The schema
  • The default values of configurations
  • The threading model
  • The binary protocol
  • The REST endpoints
  • The admin CLI options
  • The metrics
  • Anything that affects deployment

- awaitility        4.2.0     -> 4.3.0
- hamcrest          2.2       -> 3.0
- objenesis         3.3       -> 3.6
- byte-buddy        1.17.7    -> 1.18.12
- kerby             2.1.1     -> 2.1.2
- consolecaptor     1.0.3     -> 1.0.4
- jsonassert        1.5.0     -> 1.5.3
- rest-assured      5.4.0     -> 5.5.7
- org.json          20231013  -> 20260814
- docker-java-core  3.4.1     -> 3.7.1
- WireMock          2.35.1    -> 3.13.2

WireMock also changes coordinates: com.github.tomakehurst:wiremock-jre8-standalone was
discontinued after 3.0.1 and the 3.x line is published as org.wiremock:wiremock-standalone.
The Java packages are unchanged (com.github.tomakehurst.wiremock.*), and the deprecated
ResponseTransformer used by AsyncHttpConnectorTest is still present, so no test sources
change.

byte-buddy-agent is added to the version catalog so the enforced platform pins it to the
same version as byte-buddy. Mockito depends on both, and Pulsar uses MockedStatic and
MockedConstruction, which need the inline mock maker; letting the two artifacts diverge
would break it.

org.json 20260814 includes the fix for CVE-2026-59171 (unbounded BigInteger/BigDecimal
parsing). It is a test-scope dependency.

rest-assured stays on the 5.x line: 6.0.0 requires Groovy 5, an unpinned transitive that
would change across four test modules at once.

Testcontainers is left at 1.21.4, which is already the newest 1.x release; testng 7.12.0,
mockito 5.23.0 and assertj 3.27.7 are also already current.

Assisted-by: Claude Code (Opus 5)
@lhotari lhotari added this to the 5.0.0-M2 milestone Aug 17, 2026
@lhotari lhotari added the area/dependency Pull requests that update a dependency file label Aug 17, 2026
@nodece
nodece merged commit 6cfb191 into apache:master Aug 18, 2026
52 of 55 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/dependency Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants