Skip to content

Remove the pinned dependency digest check - #26

Merged
lhotari merged 1 commit into
mainfrom
remove-dependency-digests
Sep 24, 2026
Merged

lhotari merged 1 commit into
mainfrom
remove-dependency-digests

Conversation

@lhotari

@lhotari lhotari commented Sep 24, 2026

Copy link
Copy Markdown
Collaborator

Summary

The shaded modules checked every embedded external library against a SHA-256 digest, pinned by file name in the agent's and the correlator's build scripts. That check was specific to this build, and every dependency update had to repeat the digests by hand. Dependabot's grouped updates would have needed the same manual step.

This PR removes it:

  • Removed: the VerifyDependencyDigests task and its registration in jonoffcpu.shaded-jar-conventions, including shadowJar's dependency on it.
  • Removed: the digest maps in jonoffcpu-agent/build.gradle.kts and jonoffcpu-correlator/build.gradle.kts, and extractJmcWriterSources's dependency on the check.
  • Moved: the sha256 helpers, which the native bundle checksum checks still use, to NativeBundles.kt.
  • Updated: the headers of the convention plugin and the version catalog.

Gradle's dependency locking remains available if resolved versions ever need to be locked.

These checks are unaffected:

  • the native bundle SHA256SUMS check
  • the Gradle wrapper's distributionSha256Sum
  • the pinned container image digests

Verification

  • ./gradlew :jonoffcpu-agent:check :jonoffcpu-correlator:check passes: 308 tests, 0 failures.
  • Running with --configuration-cache-problems=warn reports no problems, and the second run reuses the configuration cache.
  • spotlessApply is clean.

The shaded modules checked their embedded libraries against SHA-256
digests pinned by file name in each module's build script, a
build-specific mechanism that every dependency update had to repeat.
Remove the VerifyDependencyDigests task, its registration in the
shaded-JAR convention plugin and the digest maps of the agent and the
correlator. The SHA-256 helpers the native bundle checks use move to
NativeBundles.kt. Gradle's dependency locking remains available should
resolved versions ever need to be locked.
@lhotari lhotari added the maintenance Build, CI, dependency and other maintenance changes label Sep 24, 2026
@lhotari
lhotari merged commit 1ad7814 into main Sep 24, 2026
7 checks passed
@lhotari
lhotari deleted the remove-dependency-digests branch September 24, 2026 16:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

maintenance Build, CI, dependency and other maintenance changes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant