chore(deps): update dependencies, Gradle wrapper and CI actions

Sweep every dependency coordinate in the version catalog, the hardcoded
ones in amethyst/build.gradle.kts, the Gradle wrapper and the GitHub
Actions against their upstream metadata, and take the newest release
that keeps each pin on the same stability channel it was already on.

Version catalog:
  appcompat                1.7.1         -> 1.8.0
  benchmark                1.5.0-alpha07 -> 1.5.0-rc01
  biometricKtx             1.2.0-alpha05 -> 1.4.0-alpha02
  composeBom               2026.06.01    -> 2026.08.00
  composeRuntimeAnnotation 1.11.4        -> 1.12.0
  composemediaplayer       0.11.3        -> 0.11.4
  firebaseBom              34.16.0       -> 34.17.0
  fragmentKtx              1.8.9         -> 1.9.0
  ksp                      2.3.10        -> 2.3.11
  ktor                     3.5.1         -> 3.5.2
  media3                   1.10.1        -> 1.11.0
  secp256k1KmpJniAndroid   0.23.0        -> 0.24.0
  uiautomator              2.3.0         -> 2.4.0
  webkit                   1.16.0        -> 1.17.0

composeRuntimeAnnotation is not an independent choice: the 2026.08.00
BOM pins runtime/foundation at 1.12.0, so the standalone annotation
artifact has to move with it.

A shared version ref can only advance to the lowest release available
across every artifact that uses it. `appfunctions` is the one ref here
where the artifacts do not publish in lockstep: `appfunctions` and
`appfunctions-compiler` are at alpha10 but `appfunctions-service` stops
at alpha09, so the ref stays at alpha09 and a comment now records the
cap. Every other multi-artifact ref (media3, secp256k1, ktor, benchmark,
coil, camera, ...) agrees across all of its artifacts.

Hardcoded in amethyst/build.gradle.kts:
  tink-android              1.17.0 -> 1.23.0
  tracing-perfetto(+binary) 1.0.0  -> 1.0.1

Gradle wrapper 9.5.0 -> 9.7.0 (distributionSha256Sum updated to the
checksum published for 9.7.0), and actions/setup-java v5.6.0 -> v5.7.0
across build, create-release and smoke-test-desktop. Every other action
already floats on its current major tag.

Left alone on purpose:
  - vico stays at 3.2.3; the only newer build is the 3.3.0-next.2
    prerelease and the current pin is stable.
  - negentropy-kmp stays at v1.2.0, already the newest; the 1.0.1 that
    shows up in Maven metadata is an older artifact under a different
    tag scheme.
  - AGP, Kotlin, compose-multiplatform and the JetBrains material3 pin
    are all already the latest stable; newer builds are alphas/RCs.
  - The @moq/* npm pins in nestsClient/tests/browser-interop, because
    that directory's REV file ties the 0.2.x (moq-lite-03) line to the
    moq-relay git rev pinned in hang-interop/REV. Bumping to 0.3.x is a
    wire-protocol change that has to move with the Rust relay pin.

No new dependencies are introduced, so no new licenses enter the build.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013UYmEazSQkEwsVCvrG96mB
This commit is contained in:
Claude
2026-08-14 16:05:52 +00:00
parent 7e500f4266
commit 10336d8ed4
6 changed files with 33 additions and 30 deletions
+5 -5
View File
@@ -22,7 +22,7 @@ jobs:
uses: actions/checkout@v7
- name: Set up JDK 21
uses: actions/setup-java@v5.6.0
uses: actions/setup-java@v5.7.0
with:
distribution: 'temurin'
java-version: 21
@@ -69,7 +69,7 @@ jobs:
uses: actions/checkout@v7
- name: Set up JDK 21
uses: actions/setup-java@v5.6.0
uses: actions/setup-java@v5.7.0
with:
distribution: 'temurin'
java-version: 21
@@ -126,7 +126,7 @@ jobs:
uses: actions/checkout@v7
- name: Set up JDK 21
uses: actions/setup-java@v5.6.0
uses: actions/setup-java@v5.7.0
with:
distribution: 'temurin'
java-version: 21
@@ -161,7 +161,7 @@ jobs:
uses: actions/checkout@v7
- name: Set up JDK 21
uses: actions/setup-java@v5.6.0
uses: actions/setup-java@v5.7.0
with:
distribution: 'temurin'
java-version: 21
@@ -220,7 +220,7 @@ jobs:
uses: actions/checkout@v7
- name: Set up JDK 21
uses: actions/setup-java@v5.6.0
uses: actions/setup-java@v5.7.0
with:
distribution: 'temurin'
java-version: 21
+4 -4
View File
@@ -78,7 +78,7 @@ jobs:
uses: actions/checkout@v7
- name: Set up JDK 21
uses: actions/setup-java@v5.6.0
uses: actions/setup-java@v5.7.0
with:
distribution: 'temurin'
java-version: 21
@@ -405,7 +405,7 @@ jobs:
uses: actions/checkout@v7
- name: Set up JDK 21
uses: actions/setup-java@v5.6.0
uses: actions/setup-java@v5.7.0
with:
distribution: 'temurin'
java-version: 21
@@ -662,7 +662,7 @@ jobs:
uses: actions/checkout@v7
- name: Set up JDK 21
uses: actions/setup-java@v5.6.0
uses: actions/setup-java@v5.7.0
with:
distribution: 'temurin'
java-version: 21
@@ -953,7 +953,7 @@ jobs:
uses: actions/checkout@v7
- name: Set up JDK 21
uses: actions/setup-java@v5.6.0
uses: actions/setup-java@v5.7.0
with:
distribution: 'temurin'
java-version: 21
+2 -2
View File
@@ -28,7 +28,7 @@ jobs:
uses: actions/checkout@v7
- name: Set up JDK 21
uses: actions/setup-java@v5.6.0
uses: actions/setup-java@v5.7.0
with:
distribution: 'temurin'
java-version: 21
@@ -66,7 +66,7 @@ jobs:
uses: actions/checkout@v7
- name: Set up JDK 21
uses: actions/setup-java@v5.6.0
uses: actions/setup-java@v5.7.0
with:
distribution: 'temurin'
java-version: 21
+3 -3
View File
@@ -331,7 +331,7 @@ ksp {
// TODO: until google merges and unifiedpush updates https://github.com/tink-crypto/tink-java-apps/pull/5
configurations.all {
val tink = "com.google.crypto.tink:tink-android:1.17.0"
val tink = "com.google.crypto.tink:tink-android:1.23.0"
resolutionStrategy {
force(tink)
dependencySubstitution {
@@ -396,8 +396,8 @@ dependencies {
// adb shell am broadcast -a androidx.tracing.perfetto.action.ENABLE_TRACING \
// -n com.vitorpamplona.amethyst.debug/androidx.tracing.perfetto.TracingReceiver
debugImplementation("androidx.compose.runtime:runtime-tracing")
debugImplementation("androidx.tracing:tracing-perfetto:1.0.0")
debugImplementation("androidx.tracing:tracing-perfetto-binary:1.0.0")
debugImplementation("androidx.tracing:tracing-perfetto:1.0.1")
debugImplementation("androidx.tracing:tracing-perfetto-binary:1.0.1")
implementation(project(":quartz"))
implementation(project(":commons"))
+17 -14
View File
@@ -13,20 +13,20 @@ android-compileSdk = "37"
android-minSdk = "26"
android-targetSdk = "37"
androidxJunit = "1.3.0"
appcompat = "1.7.1"
appcompat = "1.8.0"
audiowaveform = "1.1.2"
benchmark = "1.5.0-alpha07"
uiautomator = "2.3.0"
biometricKtx = "1.2.0-alpha05"
benchmark = "1.5.0-rc01"
uiautomator = "2.4.0"
biometricKtx = "1.4.0-alpha02"
coil = "3.5.0"
composeBom = "2026.06.01"
composeRuntimeAnnotation = "1.11.4"
composeBom = "2026.08.00"
composeRuntimeAnnotation = "1.12.0"
coreKtx = "1.19.0"
datastore = "1.2.1"
devWhyolegCryptography = "0.6.0"
espressoCore = "3.7.0"
firebaseBom = "34.16.0"
fragmentKtx = "1.8.9"
firebaseBom = "34.17.0"
fragmentKtx = "1.9.0"
gms = "4.5.0"
healthConnect = "1.1.0"
jacksonModuleKotlin = "2.22.1"
@@ -50,7 +50,7 @@ jlatexmath = "1.5"
markdown = "4d3b3dd173"
highlights = "1.1.0"
material3 = "1.9.0"
media3 = "1.10.1"
media3 = "1.11.0"
mockk = "1.14.11"
kotlinx-coroutines-test = "1.11.0"
negentropyKmp = "v1.2.0"
@@ -59,7 +59,7 @@ navigationCompose = "2.9.8"
okhttp = "5.4.0"
osmdroid = "6.1.20"
runner = "1.7.0"
secp256k1KmpJniAndroid = "0.23.0"
secp256k1KmpJniAndroid = "0.24.0"
schnorr256k1Kmp = "1.0.5"
securityCryptoKtx = "1.1.0"
slf4j = "2.0.18"
@@ -73,13 +73,13 @@ playServicesCast = "22.3.1"
vico-charts-compose = "3.2.3"
zelory = "3.0.1"
zoomable = "2.13.0"
composemediaplayer = "0.11.3"
composemediaplayer = "0.11.4"
jcodec = "0.2.5"
commonsImaging = "1.0.0-alpha6"
thumbnailator = "0.4.21"
zxing = "3.5.4"
zxingAndroidEmbedded = "4.3.0"
webkit = "1.16.0"
webkit = "1.17.0"
# Cross-process UI embedding (SurfaceControlViewHost wrapper) for the in-app browser surface. Apache-2.0.
privacysandboxUi = "1.0.0-alpha17"
windowCoreAndroid = "1.5.1"
@@ -92,14 +92,17 @@ kotlinTest = "2.4.10"
core = "1.7.0"
mavenPublish = "0.37.0"
sqlite = "2.7.0"
ktor = "3.5.1"
ktor = "3.5.2"
fourkoma = "1.2.0"
# Phase 2 (Gemini App Functions) — both still pre-stable as of May 2026.
# Scoped to the play flavor only (see amethyst/build.gradle.kts) so the
# fdroid channel doesn't pull in Google alpha dependencies.
# Capped by appfunctions-service: `appfunctions` and `appfunctions-compiler`
# publish alpha10, but -service stopped at alpha09, and all three share this
# ref. Check every artifact before bumping, not just the main one.
appfunctions = "1.0.0-alpha09"
ksp = "2.3.10"
ksp = "2.3.11"
[libraries]
abedElazizShe-video-compressor-fork = { group = "com.github.davotoula", name = "LightCompressor-enhanced", version.ref = "lightcompressor-enhanced" }
+2 -2
View File
@@ -1,7 +1,7 @@
#Wed Jan 04 09:23:50 EST 2023
distributionBase=GRADLE_USER_HOME
distributionUrl=https\://services.gradle.org/distributions/gradle-9.5.0-bin.zip
distributionSha256Sum=553c78f50dafcd54d65b9a444649057857469edf836431389695608536d6b746
distributionUrl=https\://services.gradle.org/distributions/gradle-9.7.0-bin.zip
distributionSha256Sum=84fbba45c7f4c64abc77460e1c00f541e9f960e3c7ed2538f1ede19eacd873ae
distributionPath=wrapper/dists
zipStorePath=wrapper/dists
zipStoreBase=GRADLE_USER_HOME