Skip to content

[improve][build] Upgrade misc tooling, annotation and utility libraries - #26359

Merged
nodece merged 1 commit into
apache:masterfrom
lhotari:lh-improve-misc-libs
Aug 18, 2026
Merged

nodece merged 1 commit into
apache:masterfrom
lhotari:lh-improve-misc-libs

Conversation

@lhotari

@lhotari lhotari commented Aug 17, 2026

Copy link
Copy Markdown
Member

Motivation

The remaining small tooling, annotation and utility libraries in the version catalog are behind.
Grouped into one PR because each is individually low risk.

Modifications

gradle/libs.versions.toml:

library from to
lombok 1.18.42 1.18.46
swagger (library and Gradle plugin) 2.2.50 2.2.53
error_prone_annotations 2.45.0 2.50.0
spotbugs-annotations 4.9.6 4.10.3
jspecify 1.0.0 1.0.1
joda-time 2.10.10 2.14.3
ant 1.10.12 1.10.17
javassist 3.25.0-GA 3.32.0-GA
jline3 4.2.1 4.3.1
jna 5.18.1 5.19.1
java-semver 0.9.0 0.10.2
typetools 0.5.0 0.6.3
zt-zip 1.17 1.18.2
ipaddress 5.5.0 5.6.2
oshi 6.4.0 6.12.0 (not 7.0.0)
athenz 1.12.42 1.12.45
auth0 java-jwt 4.5.2 4.6.0
auth0 jwks-rsa 0.23.1 0.24.1

Plus the corresponding jar names in the server and shell distribution LICENSE.bin.txt files.

error_prone_annotations and spotbugs-annotations are annotation-only artifacts; neither Error
Prone nor SpotBugs is applied as a build plugin, so those two carry no analysis behaviour change.

java-semver 0.10.2 is a drop-in. Inspecting the published jar confirms it retains the whole
deprecated 0.9.x API that Pulsar uses — Version.valueOf(String), Version.BUILD_AWARE_ORDER and
greaterThan — so BrokerVersionFilter and PersistentTopicsBase need no source change. One
behaviour note for reviewers: equals() became build-metadata-aware in 0.10.x, and
BrokerVersionFilter compares versions with equals.

oshi stops at 6.12.0 rather than 7.0.0. At 7.0.0 the oshi-core-java11 artifact became a
pom-only relocation stub redirecting to com.github.oshi:oshi-core — its own POM says "Deprecated:
use oshi-core instead". That is a coordinate change rather than a version bump and does not belong in
a bulk update. 6.12.0 splits out a new oshi-common artifact, which is added to the server LICENSE.

guice is deliberately left at 5.1.0. TestNG 7.12.0 declares com.google.inject:guice 5.1.0, and
Guice 7 switches from javax.inject to jakarta.inject. Since the version catalog drives the
pulsar-dependencies enforced platform, raising it would push TestNG onto a Guice it was not built
against across every test run. jclouds is the only consumer that actually needs Guice 7, and
jclouds-shaded already forces it locally, so there is nothing to gain. A comment recording this is
added to the catalog.

Verifying this change

  • Make sure that the change passes the CI checks.

This change is a trivial rework / code cleanup without any test coverage.

Verified locally with ./gradlew sanityCheck and ./gradlew checkBinaryLicense.

Does this pull request potentially affect one of the following parts:

  • Dependencies (add or upgrade a dependency)
  • The public API
  • The schema
  • The default values of configurations
  • The threading model
  • The binary protocol
  • The REST endpoints
  • The admin CLI options
  • The metrics
  • Anything that affects deployment

- lombok                   1.18.42    -> 1.18.46
- swagger (lib and plugin) 2.2.50     -> 2.2.53
- error_prone_annotations  2.45.0     -> 2.50.0
- spotbugs-annotations     4.9.6      -> 4.10.3
- jspecify                 1.0.0      -> 1.0.1
- joda-time                2.10.10    -> 2.14.3
- ant                      1.10.12    -> 1.10.17
- javassist                3.25.0-GA  -> 3.32.0-GA
- jline3                   4.2.1      -> 4.3.1
- jna                      5.18.1     -> 5.19.1
- java-semver              0.9.0      -> 0.10.2
- typetools                0.5.0      -> 0.6.3
- zt-zip                   1.17       -> 1.18.2
- ipaddress                5.5.0      -> 5.6.2
- oshi                     6.4.0      -> 6.12.0
- athenz                   1.12.42    -> 1.12.45
- auth0 java-jwt           4.5.2      -> 4.6.0
- auth0 jwks-rsa           0.23.1     -> 0.24.1

error_prone_annotations and spotbugs-annotations are annotation-only artifacts; neither
Error Prone nor SpotBugs is applied as a build plugin.

java-semver 0.10.2 keeps the whole deprecated 0.9.x API that Pulsar uses
(Version.valueOf, BUILD_AWARE_ORDER, greaterThan), so BrokerVersionFilter and
PersistentTopicsBase need no source change.

oshi stops at 6.12.0 rather than 7.0.0: at 7.0.0 the oshi-core-java11 artifact became a
pom-only relocation stub redirecting to com.github.oshi:oshi-core, which is a coordinate
change rather than a version bump. 6.12.0 splits out a new oshi-common artifact, which is
added to the server LICENSE.

guice is deliberately left at 5.1.0: TestNG 7.12.0 declares guice 5.1.0, and Guice 7
switches from javax.inject to jakarta.inject. jclouds is the only consumer that needs
Guice 7, and jclouds-shaded already forces it locally, so raising the catalog pin would
push TestNG onto a Guice it was not built against for no benefit.

Assisted-by: Claude Code (Opus 5)
@lhotari lhotari added the area/dependency Pull requests that update a dependency file label Aug 17, 2026
@lhotari lhotari added this to the 5.0.0-M2 milestone Aug 17, 2026
@nodece
nodece merged commit e2ed9ca into apache:master Aug 18, 2026
51 of 53 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/dependency Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants