On 9x, I dealt with Erupture and Tengu, both simple category 1's. On main (and will be backported to 10x) I dealt with Tengu.
For some reason Otachi, a Jersey 2 to 3 on 9x showed up. It's a Category 4, and I don't think it should have opened up at all, we aren't updating Jersey on 9x a major version. So will dig int a bit. Our nightly builds are failing due to a develocity token being expired, even though tests are passing. I pinged David on slack. On 2026-10-01 15:57 UTC Eric Pugh via dev wrote: > For the past two weeks I've been dreading the first of the month…. Well > dreading, but also super curious. How many PR’s will Solrbot open? What > new challenging dependency upgrades will we have to tackle? Will it ever end. > > I just rewatched Pacific Rim with the teen, and the challenges of fighting of > the Kaiju are somewhat similar to the challenges of fighting off dependency > upgrades. Dealing with dependency updates is a “must do” thing, not a “yay, > this is fun” thing. > > So, last night the breach between our nice stable up to date Solr and the > rest of the software ecosystem opened up again (thanks Solrbot and Jan’s hard > work!) and the dependencies came marching through. Every few minutes > another PR popped open…. Boom boom boom, 17 brand new PRs that someone has > to deal with. > > At first I was a bit bummed…. I thought it might be just a few PRs after all > the hardworking we’ve done to catch up on dependencies. But then I thought > about the “We are cancelling the apocalypse” speech that the given in the > movie > (https://johnjronline.wordpress.com/2021/04/08/pacific-rim-2013-we-are-canceling-the-apocalypse-scene-9-10-movieclips/) > and I thought…. What can I learn from that movie? > > One thing is that our dependency updates are sometimes easy to deal with and > other times really challenging. In Pacific Rim, the Kaiju come in different > “categories” from an easy Category 1 to a terrifying Category 5 (and up!)…. > Wouldn’t it be nice to categorize our dependency updates so we know how much > thinking is needed for each one? > > Likewise, by naming the individual Kaiju, it makes it easier to refer to > them, understand their specific characteristics (can they fly, do they have > acid breathe, etc). Maybe we can name our Dependency updates as well? We > kind of almost do that with the grouping logic that Solrbot uses anyway. > > Plus, honestly, how can I make dependency management more fun? > > So, with that long preamble, here are this month’s Breach Report: > https://claude.ai/artifact/HxtVJmaE3wcExeptY7yLgW?sk=HG4tZy6ogQKaewKqcEPvWg > > Cat Name PR Title > V Slattern Revamp Solr Extraction Module to work with Tika 4 > IV Otachi Update Jersey jetty-http to v3 (branch_9x) > III Knifehead Update all non-major dependencies > III Yamarashi Update gRPC and Netty > III Atticon Update Web server stack to v12.1.13 > II Raythe Update Telemetry (OpenTelemetry & Prometheus) > II Clawhook Update AWS SDK to v2.55.6 > II Onibaba Update Jackson BOM to v2.22.3 > II Androc Update Google Cloud > II Itak Update Logging to v2.0.20 > II Ragnarok Update ZooKeeper & Curator to v3.9.6 > II Crusherbone Update Jackson BOM to v2.22.3 (branch_9x) > I Hardship Update Avatica-core to v1.29.0 > I Hammerjaw Update Admin UI > I Ceptid Update Okio to v3.18.2 > I Tengu Update GitHub Actions > I Karloff Update GitHub Actions (branch_9x) > I Erupture Update all non-major test dependencies (branch_9x) > > Disclaimer > > The information contained in this communication from the sender is > confidential. It is intended solely for use by the recipient and others > authorized to receive it. If you are not the recipient, you are hereby > notified that any disclosure, copying, distribution or taking action in > relation of the contents of this information is strictly prohibited and may > be unlawful. > > This email has been scanned for viruses and malware, and may have been > automatically archived by Mimecast, a leader in email security and cyber > resilience. Mimecast integrates email defenses with brand protection, > security awareness training, web security, compliance and other essential > capabilities. Mimecast helps protect large and small organizations from > malicious activity, human error and technology failure; and to lead the > movement toward building a more resilient world. To find out more, visit our > website. > --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
