Skip to content

Drop stale entries from the Java SDK dependency trust list - #73792

Merged
potiuk merged 1 commit into
apache:mainfrom
potiuk:drop-stale-java-sdk-checksums
Sep 27, 2026
Merged

potiuk merged 1 commit into
apache:mainfrom
potiuk:drop-stale-java-sdk-checksums

Conversation

@potiuk

@potiuk potiuk commented Sep 27, 2026

Copy link
Copy Markdown
Member

The regenerate-java-sdk-verification-metadata hook added in #71869 drops checksums that no Java SDK build task resolves any more. But java-sdk/gradle/verification-metadata.xml on main still had entries for versions superseded by earlier dependency bumps (jackson 2.22.1, spotbugs-annotations 4.10.3, junit-bom 6.1.2). The hook therefore rewrites the file on every run, and CI image checks / Static checks fails on every PR regardless of what it touches (e.g. #73782).

This applies exactly the diff the hook produced in CI. It only removes entries; nothing new is trusted.


Was generative AI tooling used to co-author this PR?
  • Yes — Claude Code (Opus 5)

Generated-by: Claude Code (Opus 5) following the guidelines

🤖 Generated with Claude Code

The regenerate-java-sdk-verification-metadata hook added in apache#71869 drops
checksums that no Java SDK build task resolves any more, but the trust
list on main still carried entries for versions superseded by earlier
dependency bumps. The hook therefore rewrites the file in every run, and
static checks fail on every PR regardless of what it touches.

Generated-by: Claude Opus 5

@henry3260 henry3260 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for the quick fix

@potiuk
potiuk merged commit a72b735 into apache:main Sep 27, 2026
62 checks passed
@potiuk
potiuk deleted the drop-stale-java-sdk-checksums branch September 27, 2026 14:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants