Files
amethyst/gradle/wrapper
Claude 2c9f70e9e8 chore(deps): update dependencies and the Gradle wrapper
Sweep every dependency coordinate in the version catalog, the hardcoded
ones in the module build scripts, the Gradle wrapper and the GitHub
Actions against their upstream metadata, and take the newest release
that keeps each pin on the same stability channel it was already on.

Version catalog:
  firebaseBom           34.17.0     -> 34.18.0
  jacksonModuleKotlin   2.22.1      -> 2.22.2
  okhttp                5.4.0       -> 5.5.0
  sonarqubeGradlePlugin 7.3.1.8318  -> 7.4.0.8496
  spotless              8.9.0       -> 8.10.0
  vico-charts-compose   3.2.3       -> 3.3.0

vico had been held back at 3.2.3 because the only newer builds were the
3.3.0-next prereleases; 3.3.0 has since shipped stable, so the pin moves
without leaving the stable channel.

sonarqube-gradle-plugin is published on the Gradle plugin portal, not
Maven Central — the `3.3` that Central still serves for that coordinate
is a stale line unrelated to the current 7.x releases. It stays LGPL-3.0
and build-time only, gated behind the local.properties sonar opt-in in
the root build script, so nothing new enters a shipped artifact.

Gradle wrapper 9.7.0 -> 9.7.1, with distributionSha256Sum updated to the
checksum published for 9.7.1.

Already current, so untouched: every other catalog ref (AGP, Kotlin,
compose-multiplatform, the compose BOM, media3, coil, ktor, secp256k1,
camera, sqlite, ...), the hardcoded coordinates in the module build
scripts (tink-android 1.23.0, tracing-perfetto 1.0.1, opus-java 1.1.1,
jna 5.19.1, nucleus.notification-* 1.15.7, kotlinx-crypto-* 0.0.4), and
every GitHub Action — the floating major tags are all on their newest
major and setup-java is already pinned at v5.7.0, the newest release.

Left alone on purpose:
  - appfunctions stays at 1.0.0-alpha09: `appfunctions` and
    `appfunctions-compiler` publish alpha10 but `appfunctions-service`
    still stops at alpha09, and all three share the ref.
  - composeRuntimeAnnotation stays at 1.12.0 because it has to track
    whatever the compose BOM pins, and 2026.08.00 is still the newest.
  - The org.jetbrains.compose.material3 pin stays at 1.9.0 — everything
    above it is a 1.10/1.11/1.12 alpha.
  - The @moq/* npm pins in nestsClient/tests/browser-interop, which the
    directory's REV file ties to the moq-relay git rev in
    hang-interop/REV; bumping the 0.2.x (moq-lite-03) line is a
    wire-protocol change that has to move with the Rust relay pin.
  - quartz/tools/tsmls-vector-gen stays on ts-mls 2.0.0-rc.10. That
    generator emits the committed MLS KAT vector with fresh randomness
    each run, so moving it means regenerating and re-verifying the
    fixture, not a routine version bump. Its @noble/* deps already float
    on caret ranges.
  - The Docker base images (eclipse-temurin:21, rustc 1.95.0) are
    toolchain pins tied to the JDK target and the moq-relay pin.

No new dependencies are introduced, so no new licenses enter the build.

Verified: :amethyst:compilePlayDebugKotlin, :desktopApp/:cli/:geode/
:relayBench compileKotlin and spotlessCheck all pass on Gradle 9.7.1.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01RnezWP7LpA6amBCVxtGQ5b
2026-08-22 14:30:17 +00:00
..
2023-01-11 13:31:20 -05:00