Skip to content
This repository was archived by the owner on Aug 27, 2026. It is now read-only.

[release/10.0.1xx] Backport Maven hardening and feed routing - #1498

Merged
jonathanpeppers merged 1 commit into
release/10.0.1xxfrom
jonathanpeppers-backport-complete-maven
Aug 21, 2026
Merged

jonathanpeppers merged 1 commit into
release/10.0.1xxfrom
jonathanpeppers-backport-complete-maven

Conversation

@jonathanpeppers

@jonathanpeppers jonathanpeppers commented Aug 20, 2026 •

Copy link
Copy Markdown
Member

Supersedes #1495 with the complete release-applicable Maven backport as exactly one commit on top of the Java.Interop commit pinned by dotnet/android release/10.0.1xx (33992194b9373e9322244612c94ed9941b9bc2fd).

Backports:

The Kotlin Gradle fixture from Android main is intentionally excluded because it does not exist at this release pin.

Validation:

  • Java.Interop.Tools.Maven tests: 106 passed, 0 failed
  • java-source-utils assembly: succeeded
  • java-source-utils standalone CI-mode settings evaluation: succeeded
  • Fresh-cache java-source-utils compileJava: succeeded entirely through dotnet-public-maven
  • java-source-utils legacy suite: 16 passed before two existing missing-resource NPEs (JavaType.java) unrelated to repository routing

Feed prerequisite: the release JavaParser 3.18.0 dependency graph must be mirrored into dotnet-public-maven for anonymous CI resolution. The complete graph has been seeded and fresh-cache resolution is confirmed.

Backport cache path containment, Maven artifact validation, and release-applicable dotnet-public-maven routing for Maven tests and java-source-utils.

Co-authored-by: Copilot App <[email protected]>

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR backports Maven hardening and feed-routing changes into the release/10.0.1xx line to make Maven artifact handling safer (coordinate validation + cache path containment) and to align Java/Gradle dependency resolution with the dotnet-public-maven feed in CI scenarios.

Changes:

  • Added strict validation for Maven artifact coordinates in Artifact (constructor + TryParse) and expanded test coverage.
  • Centralized cache-path construction in CachedMavenRepository.GetArtifactFilePath() and enforced that resolved cache paths remain under CacheDirectory, with dedicated tests.
  • Updated java-source-utils Gradle settings to use shared repository configuration when embedded, with a CI-oriented fallback feed routing; removed project-local mavenCentral() from the module build file.

Reviewed changes

Copilot reviewed 7 out of 7 changed files in this pull request and generated no comments.

Show a summary per file
File Description
tools/java-source-utils/settings.gradle Routes plugin/dependency repositories via shared settings when available, with CI fallback to dotnet-public-maven.
tools/java-source-utils/build.gradle Removes project-local repositories { mavenCentral() } so settings-based repository management is authoritative.
tests/Java.Interop.Tools.Maven-Tests/Extensions/MavenProjectResolver.cs Routes integration-test resolution through dotnet-public-maven for both “central” and “google”.
tests/Java.Interop.Tools.Maven-Tests/CachedMavenRepositoryTests.cs Adds coverage for cache layout and path-escape prevention behavior.
tests/Java.Interop.Tools.Maven-Tests/ArtifactTests.cs Adds coordinate validation coverage for ctor/TryParse/Parse, including traversal and illegal character cases.
src/Java.Interop.Tools.Maven/Repositories/CachedMavenRepository.cs Adds GetArtifactFilePath() and routes all cache-path usage through it with containment enforcement.
src/Java.Interop.Tools.Maven/Models/Artifact.cs Implements coordinate/version validation and makes TryParse reject malformed inputs (including null).

💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.

@jonathanpeppers
jonathanpeppers merged commit 8e8291c into release/10.0.1xx Aug 21, 2026
3 checks passed
@jonathanpeppers
jonathanpeppers deleted the jonathanpeppers-backport-complete-maven branch August 21, 2026 17:07
jonathanpeppers added a commit to dotnet/android that referenced this pull request Aug 24, 2026
## Summary

- backport `1c4d41c09eec` so direct Maven mirroring fails when any requested coordinate produces no payloads
- update `external/Java.Interop` from `33992194b9373e9322244612c94ed9941b9bc2fd` to dotnet/java-interop#1498's single release backport commit `7c110bfad3ee0a87f303609426167722ccb4ba77`
- include the release-applicable Java.Interop Maven test and java-source-utils routing that could not be carried by the main-branch subtree patch
- seed the release JavaParser 3.18.0 dependency graph into `dotnet-public-maven` for anonymous CI resolution

## Backport mapping

| Main change | Release equivalent |
| --- | --- |
| `ce636392a229` / #11711, `3c62389651c2` / #12055, Android portions of `466da4a84dc2` / #12199, and `adffb38fd731` / #12368 | `659cd98e7fb9` / #12397 |
| `8df1e87799f1` / #12198, `7ace3137a4fa` / #12336, `c09c89aa1f2e` / #12338, `13727e665929` / #12335, and `d57b8c42f131` / #12367 | `352831edcba6` / #12396 |
| approved .NET tool feed portion of `fa00357649bb` / #11701 | `dc9a8524138e` / #12420 |
| `1c4d41c09eec` / #12412 | `24252012aaf6` in this PR |
| Java.Interop hardening plus release-applicable routing from `466da4a84dc2` | dotnet/java-interop#1498, pinned here at `7c110bfad3ee0a87f303609426167722ccb4ba77` |

The later Dependabot-only Google Maven exposure and unrelated Gradle/dependency version churn are intentionally excluded. The final Java.Interop pin supersedes the earlier hardening-only candidate without amending or force-pushing commits.

## Validation

- Java.Interop.Tools.Maven tests: 106 passed, 0 failed
- CI-mode `java-source-utils` `jar` build resolved through `dotnet-public-maven` and succeeded after the mirror helper seeded the full transitive graph
- `mirror-dependencies.ps1` parsed successfully with the PowerShell parser
- Java.Interop final SHA is exactly one commit on top of the release pin
- `git diff --check origin/release/10.0.1xx..HEAD`

Co-authored-by: Copilot App <[email protected]>
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants