Repository navigation
[improve][build] Upgrade misc tooling, annotation and utility libraries - #26359
Merged
Merged
Conversation
- lombok 1.18.42 -> 1.18.46 - swagger (lib and plugin) 2.2.50 -> 2.2.53 - error_prone_annotations 2.45.0 -> 2.50.0 - spotbugs-annotations 4.9.6 -> 4.10.3 - jspecify 1.0.0 -> 1.0.1 - joda-time 2.10.10 -> 2.14.3 - ant 1.10.12 -> 1.10.17 - javassist 3.25.0-GA -> 3.32.0-GA - jline3 4.2.1 -> 4.3.1 - jna 5.18.1 -> 5.19.1 - java-semver 0.9.0 -> 0.10.2 - typetools 0.5.0 -> 0.6.3 - zt-zip 1.17 -> 1.18.2 - ipaddress 5.5.0 -> 5.6.2 - oshi 6.4.0 -> 6.12.0 - athenz 1.12.42 -> 1.12.45 - auth0 java-jwt 4.5.2 -> 4.6.0 - auth0 jwks-rsa 0.23.1 -> 0.24.1 error_prone_annotations and spotbugs-annotations are annotation-only artifacts; neither Error Prone nor SpotBugs is applied as a build plugin. java-semver 0.10.2 keeps the whole deprecated 0.9.x API that Pulsar uses (Version.valueOf, BUILD_AWARE_ORDER, greaterThan), so BrokerVersionFilter and PersistentTopicsBase need no source change. oshi stops at 6.12.0 rather than 7.0.0: at 7.0.0 the oshi-core-java11 artifact became a pom-only relocation stub redirecting to com.github.oshi:oshi-core, which is a coordinate change rather than a version bump. 6.12.0 splits out a new oshi-common artifact, which is added to the server LICENSE. guice is deliberately left at 5.1.0: TestNG 7.12.0 declares guice 5.1.0, and Guice 7 switches from javax.inject to jakarta.inject. jclouds is the only consumer that needs Guice 7, and jclouds-shaded already forces it locally, so raising the catalog pin would push TestNG onto a Guice it was not built against for no benefit. Assisted-by: Claude Code (Opus 5)
nodece
approved these changes
Aug 18, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Motivation
The remaining small tooling, annotation and utility libraries in the version catalog are behind.
Grouped into one PR because each is individually low risk.
Modifications
gradle/libs.versions.toml:Plus the corresponding jar names in the server and shell distribution
LICENSE.bin.txtfiles.error_prone_annotationsandspotbugs-annotationsare annotation-only artifacts; neither ErrorProne nor SpotBugs is applied as a build plugin, so those two carry no analysis behaviour change.
java-semver 0.10.2 is a drop-in. Inspecting the published jar confirms it retains the whole
deprecated 0.9.x API that Pulsar uses —
Version.valueOf(String),Version.BUILD_AWARE_ORDERandgreaterThan— soBrokerVersionFilterandPersistentTopicsBaseneed no source change. Onebehaviour note for reviewers:
equals()became build-metadata-aware in 0.10.x, andBrokerVersionFiltercompares versions withequals.oshi stops at 6.12.0 rather than 7.0.0. At 7.0.0 the
oshi-core-java11artifact became apom-only relocation stub redirecting to
com.github.oshi:oshi-core— its own POM says "Deprecated:use oshi-core instead". That is a coordinate change rather than a version bump and does not belong in
a bulk update. 6.12.0 splits out a new
oshi-commonartifact, which is added to the server LICENSE.guice is deliberately left at 5.1.0. TestNG 7.12.0 declares
com.google.inject:guice5.1.0, andGuice 7 switches from
javax.injecttojakarta.inject. Since the version catalog drives thepulsar-dependenciesenforced platform, raising it would push TestNG onto a Guice it was not builtagainst across every test run. jclouds is the only consumer that actually needs Guice 7, and
jclouds-shadedalready forces it locally, so there is nothing to gain. A comment recording this isadded to the catalog.
Verifying this change
This change is a trivial rework / code cleanup without any test coverage.
Verified locally with
./gradlew sanityCheckand./gradlew checkBinaryLicense.Does this pull request potentially affect one of the following parts: