This repository was archived by the owner on Aug 27, 2026. It is now read-only.
Repository navigation
[release/10.0.1xx] Backport Maven hardening and feed routing - #1498
Merged
jonathanpeppers merged 1 commit intoAug 21, 2026
Merged
Conversation
Backport cache path containment, Maven artifact validation, and release-applicable dotnet-public-maven routing for Maven tests and java-source-utils. Co-authored-by: Copilot App <[email protected]>
There was a problem hiding this comment.
Pull request overview
This PR backports Maven hardening and feed-routing changes into the release/10.0.1xx line to make Maven artifact handling safer (coordinate validation + cache path containment) and to align Java/Gradle dependency resolution with the dotnet-public-maven feed in CI scenarios.
Changes:
- Added strict validation for Maven artifact coordinates in
Artifact(constructor +TryParse) and expanded test coverage. - Centralized cache-path construction in
CachedMavenRepository.GetArtifactFilePath()and enforced that resolved cache paths remain underCacheDirectory, with dedicated tests. - Updated
java-source-utilsGradle settings to use shared repository configuration when embedded, with a CI-oriented fallback feed routing; removed project-localmavenCentral()from the module build file.
Reviewed changes
Copilot reviewed 7 out of 7 changed files in this pull request and generated no comments.
Show a summary per file
| File | Description |
|---|---|
| tools/java-source-utils/settings.gradle | Routes plugin/dependency repositories via shared settings when available, with CI fallback to dotnet-public-maven. |
| tools/java-source-utils/build.gradle | Removes project-local repositories { mavenCentral() } so settings-based repository management is authoritative. |
| tests/Java.Interop.Tools.Maven-Tests/Extensions/MavenProjectResolver.cs | Routes integration-test resolution through dotnet-public-maven for both “central” and “google”. |
| tests/Java.Interop.Tools.Maven-Tests/CachedMavenRepositoryTests.cs | Adds coverage for cache layout and path-escape prevention behavior. |
| tests/Java.Interop.Tools.Maven-Tests/ArtifactTests.cs | Adds coordinate validation coverage for ctor/TryParse/Parse, including traversal and illegal character cases. |
| src/Java.Interop.Tools.Maven/Repositories/CachedMavenRepository.cs | Adds GetArtifactFilePath() and routes all cache-path usage through it with containment enforcement. |
| src/Java.Interop.Tools.Maven/Models/Artifact.cs | Implements coordinate/version validation and makes TryParse reject malformed inputs (including null). |
💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.
jonathanpeppers
added a commit
to dotnet/android
that referenced
this pull request
Aug 24, 2026
## Summary - backport `1c4d41c09eec` so direct Maven mirroring fails when any requested coordinate produces no payloads - update `external/Java.Interop` from `33992194b9373e9322244612c94ed9941b9bc2fd` to dotnet/java-interop#1498's single release backport commit `7c110bfad3ee0a87f303609426167722ccb4ba77` - include the release-applicable Java.Interop Maven test and java-source-utils routing that could not be carried by the main-branch subtree patch - seed the release JavaParser 3.18.0 dependency graph into `dotnet-public-maven` for anonymous CI resolution ## Backport mapping | Main change | Release equivalent | | --- | --- | | `ce636392a229` / #11711, `3c62389651c2` / #12055, Android portions of `466da4a84dc2` / #12199, and `adffb38fd731` / #12368 | `659cd98e7fb9` / #12397 | | `8df1e87799f1` / #12198, `7ace3137a4fa` / #12336, `c09c89aa1f2e` / #12338, `13727e665929` / #12335, and `d57b8c42f131` / #12367 | `352831edcba6` / #12396 | | approved .NET tool feed portion of `fa00357649bb` / #11701 | `dc9a8524138e` / #12420 | | `1c4d41c09eec` / #12412 | `24252012aaf6` in this PR | | Java.Interop hardening plus release-applicable routing from `466da4a84dc2` | dotnet/java-interop#1498, pinned here at `7c110bfad3ee0a87f303609426167722ccb4ba77` | The later Dependabot-only Google Maven exposure and unrelated Gradle/dependency version churn are intentionally excluded. The final Java.Interop pin supersedes the earlier hardening-only candidate without amending or force-pushing commits. ## Validation - Java.Interop.Tools.Maven tests: 106 passed, 0 failed - CI-mode `java-source-utils` `jar` build resolved through `dotnet-public-maven` and succeeded after the mirror helper seeded the full transitive graph - `mirror-dependencies.ps1` parsed successfully with the PowerShell parser - Java.Interop final SHA is exactly one commit on top of the release pin - `git diff --check origin/release/10.0.1xx..HEAD` Co-authored-by: Copilot App <[email protected]>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Supersedes #1495 with the complete release-applicable Maven backport as exactly one commit on top of the Java.Interop commit pinned by dotnet/android
release/10.0.1xx(33992194b9373e9322244612c94ed9941b9bc2fd).Backports:
CacheDirectorydotnet-public-mavenmavenCentral()and use Android's shared approved repository settings when embedded, with an equivalent standalone Java.Interop fallbackThe Kotlin Gradle fixture from Android main is intentionally excluded because it does not exist at this release pin.
Validation:
compileJava: succeeded entirely throughdotnet-public-mavenJavaType.java) unrelated to repository routingFeed prerequisite: the release JavaParser
3.18.0dependency graph must be mirrored intodotnet-public-mavenfor anonymous CI resolution. The complete graph has been seeded and fresh-cache resolution is confirmed.