mirror of
https://github.com/vitorpamplona/amethyst.git
synced 2026-10-05 19:28:25 +00:00
Sweep every dependency coordinate in the version catalog, the hardcoded
ones in the module build scripts, the Gradle wrapper and the GitHub
Actions against their upstream metadata, and take the newest release
that keeps each pin on the same stability channel it was already on.
Version catalog:
firebaseBom 34.17.0 -> 34.18.0
jacksonModuleKotlin 2.22.1 -> 2.22.2
okhttp 5.4.0 -> 5.5.0
sonarqubeGradlePlugin 7.3.1.8318 -> 7.4.0.8496
spotless 8.9.0 -> 8.10.0
vico-charts-compose 3.2.3 -> 3.3.0
vico had been held back at 3.2.3 because the only newer builds were the
3.3.0-next prereleases; 3.3.0 has since shipped stable, so the pin moves
without leaving the stable channel.
sonarqube-gradle-plugin is published on the Gradle plugin portal, not
Maven Central — the `3.3` that Central still serves for that coordinate
is a stale line unrelated to the current 7.x releases. It stays LGPL-3.0
and build-time only, gated behind the local.properties sonar opt-in in
the root build script, so nothing new enters a shipped artifact.
Gradle wrapper 9.7.0 -> 9.7.1, with distributionSha256Sum updated to the
checksum published for 9.7.1.
Already current, so untouched: every other catalog ref (AGP, Kotlin,
compose-multiplatform, the compose BOM, media3, coil, ktor, secp256k1,
camera, sqlite, ...), the hardcoded coordinates in the module build
scripts (tink-android 1.23.0, tracing-perfetto 1.0.1, opus-java 1.1.1,
jna 5.19.1, nucleus.notification-* 1.15.7, kotlinx-crypto-* 0.0.4), and
every GitHub Action — the floating major tags are all on their newest
major and setup-java is already pinned at v5.7.0, the newest release.
Left alone on purpose:
- appfunctions stays at 1.0.0-alpha09: `appfunctions` and
`appfunctions-compiler` publish alpha10 but `appfunctions-service`
still stops at alpha09, and all three share the ref.
- composeRuntimeAnnotation stays at 1.12.0 because it has to track
whatever the compose BOM pins, and 2026.08.00 is still the newest.
- The org.jetbrains.compose.material3 pin stays at 1.9.0 — everything
above it is a 1.10/1.11/1.12 alpha.
- The @moq/* npm pins in nestsClient/tests/browser-interop, which the
directory's REV file ties to the moq-relay git rev in
hang-interop/REV; bumping the 0.2.x (moq-lite-03) line is a
wire-protocol change that has to move with the Rust relay pin.
- quartz/tools/tsmls-vector-gen stays on ts-mls 2.0.0-rc.10. That
generator emits the committed MLS KAT vector with fresh randomness
each run, so moving it means regenerating and re-verifying the
fixture, not a routine version bump. Its @noble/* deps already float
on caret ranges.
- The Docker base images (eclipse-temurin:21, rustc 1.95.0) are
toolchain pins tied to the JDK target and the moq-relay pin.
No new dependencies are introduced, so no new licenses enter the build.
Verified: :amethyst:compilePlayDebugKotlin, :desktopApp/:cli/:geode/
:relayBench compileKotlin and spotlessCheck all pass on Gradle 9.7.1.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01RnezWP7LpA6amBCVxtGQ5b