Skip to content

[improve][build] Upgrade Jakarta and servlet APIs within the Jakarta EE 10 level - #26354

Merged
nodece merged 1 commit into
apache:masterfrom
lhotari:lh-improve-jakarta-apis
Aug 18, 2026
Merged

nodece merged 1 commit into
apache:masterfrom
lhotari:lh-improve-jakarta-apis

Conversation

@lhotari

@lhotari lhotari commented Aug 17, 2026

Copy link
Copy Markdown
Member

Motivation

Several Jakarta API artifacts have newer patch releases within the Jakarta EE 10 level Pulsar
targets. Separately, javax.servlet-api was pinned at Servlet 3.1 while the Jetty ee8 environment
that consumes it actually implements Servlet 4.0.

Modifications

gradle/libs.versions.toml:

library from to
jakarta.activation-api 2.1.3 2.1.4
angus-activation 2.0.2 2.0.3
jakarta.xml.bind-api 4.0.2 4.0.5
javax.servlet-api 3.1.0 4.0.1

Plus the corresponding jar names in the server and shell distribution LICENSE.bin.txt files, and an
updated comment in the catalog explaining the servlet level pairing.

Each API is kept at the level its Jetty 12.1 environment actually implements. Checking the Jetty
12.1.12 POMs directly:

  • org.eclipse.jetty.ee10:jetty-ee10 declares ee10.jakarta.xml.bind.api.version = 4.0.5 — exactly
    what this PR moves to;
  • org.eclipse.jetty.ee8:jetty-ee8 declares ee8.jetty.servlet.api.version = 4.0.9
    (org.eclipse.jetty.toolchain:jetty-servlet-api), i.e. the ee8 environment implements Servlet 4.0,
    not the Servlet 3.1 previously pinned.

Please note: javax.servlet-api widens a public plugin surface

javax.servlet-api is what the PIP-472 AdditionalServlet plugin SPI compiles against. Raising it
from 3.1 to 4.0 widens that public plugin API surface. Plugins already compiled against Servlet 3.1
continue to work, since Servlet 4.0 is backward compatible; what changes is that new plugins may
start relying on Servlet 4.0 API. Flagging it explicitly because it is effectively a one-way door.

Deliberately not upgraded

These would move Pulsar past Jakarta EE 10 and out of step with the Jetty ee10 environment, so they
are left alone:

available why not
jakarta.ws.rs-api 4.0.0 Jakarta REST 4.0 is EE 11, and would require Jersey 4.x
jakarta.annotation-api 3.0.0 EE 11
jakarta.servlet-api 6.1.0 jetty-ee10 12.1.12 declares 6.0.0; Servlet 6.1 belongs to the ee11 environment
jakarta.validation-api 3.1.1 Bean Validation 3.1 is EE 11

Note that jakarta.validation-api is not declared directly by any Pulsar module, but the version
catalog drives the pulsar-dependencies enforced platform, so a bump there would still pin Bean
Validation 3.1 globally for the swagger and Jersey transitives.

Verifying this change

  • Make sure that the change passes the CI checks.

This change is a trivial rework / code cleanup without any test coverage.

Verified locally with ./gradlew sanityCheck and ./gradlew checkBinaryLicense.

Does this pull request potentially affect one of the following parts:

  • Dependencies (add or upgrade a dependency)
  • The public API
  • The schema
  • The default values of configurations
  • The threading model
  • The binary protocol
  • The REST endpoints
  • The admin CLI options
  • The metrics
  • Anything that affects deployment

The public API impact is the AdditionalServlet plugin SPI moving from Servlet 3.1 to Servlet 4.0,
described above.

…EE 10 level

- jakarta.activation-api  2.1.3 -> 2.1.4
- angus-activation        2.0.2 -> 2.0.3
- jakarta.xml.bind-api    4.0.2 -> 4.0.5
- javax.servlet-api       3.1.0 -> 4.0.1

Each API is kept at the level its Jetty 12.1 environment actually implements.
jakarta.xml.bind-api 4.0.5 is exactly what jetty-ee10 12.1.12 declares. javax.servlet-api
moves to 4.0.1 because the Jetty ee8 environment ships jetty-servlet-api 4.0.x, i.e. it
implements Servlet 4.0 rather than the Servlet 3.1 the catalog previously pinned.

Note on javax.servlet-api: this is the API the PIP-472 AdditionalServlet plugin SPI
compiles against, so raising it widens that public plugin surface from Servlet 3.1 to
Servlet 4.0. Plugins already compiled against Servlet 3.1 continue to work, since
Servlet 4.0 is backward compatible; what changes is that new plugins may start relying on
Servlet 4.0 API.

Deliberately not upgraded, because they would move Pulsar past Jakarta EE 10 and away
from the Jetty ee10 environment:
- jakarta.ws.rs-api 3.1.0 (4.0.0 is Jakarta REST 4.0, EE 11, and needs Jersey 4.x)
- jakarta.annotation-api 2.1.1 (3.0.0 is EE 11)
- jakarta.servlet-api 6.0.0 (jetty-ee10 12.1.12 declares 6.0.0; Servlet 6.1 is the ee11
  environment)
- jakarta.validation-api 3.0.2 (Bean Validation 3.1 is EE 11)

Assisted-by: Claude Code (Opus 5)
@lhotari lhotari added this to the 5.0.0-M2 milestone Aug 17, 2026
@lhotari lhotari added the area/dependency Pull requests that update a dependency file label Aug 17, 2026
@nodece
nodece merged commit 1d549c8 into apache:master Aug 18, 2026
58 of 65 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/dependency Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants