On 9x, I dealt with Erupture and Tengu, both simple category 1's.  On main (and 
will be backported to 10x) I dealt with Tengu.

For some reason Otachi, a Jersey 2 to 3 on 9x showed up.  It's a Category 4, 
and I don't think it should have opened up at all, we aren't updating Jersey on 
9x a major version.  So will dig int a bit.

Our nightly builds are failing due to a develocity token being expired, even 
though tests are passing.  I pinged David on slack.



On 2026-10-01 15:57 UTC Eric Pugh via dev wrote:
> For the past two weeks I've been dreading the first of the month…. Well 
> dreading, but also super curious.   How many PR’s will Solrbot open?   What 
> new challenging dependency upgrades will we have to tackle?  Will it ever end.
> 
> I just rewatched Pacific Rim with the teen, and the challenges of fighting of 
> the Kaiju are somewhat similar to the challenges of fighting off dependency 
> upgrades.   Dealing with dependency updates is a “must do” thing, not a “yay, 
> this is fun” thing.
> 
> So, last night the breach between our nice stable up to date Solr and the 
> rest of the software ecosystem opened up again (thanks Solrbot and Jan’s hard 
> work!) and the dependencies came marching through.   Every few minutes 
> another PR popped open….  Boom boom boom, 17 brand new PRs that someone has 
> to deal with.   
> 
> At first I was a bit bummed…. I thought it might be just a few PRs after all 
> the hardworking we’ve done to catch up on dependencies.   But then I thought 
> about the “We are cancelling the apocalypse” speech that the given in the 
> movie 
> (https://johnjronline.wordpress.com/2021/04/08/pacific-rim-2013-we-are-canceling-the-apocalypse-scene-9-10-movieclips/)
>  and I thought….  What can I learn from that movie?
> 
> One thing is that our dependency updates are sometimes easy to deal with and 
> other times really challenging.   In Pacific Rim, the Kaiju come in different 
> “categories” from an easy Category 1 to a terrifying Category 5 (and up!)….   
> Wouldn’t it be nice to categorize our dependency updates so we know how much 
> thinking is needed for each one?
> 
> Likewise, by naming the individual Kaiju, it makes it easier to refer to 
> them, understand their specific characteristics (can they fly, do they have 
> acid breathe, etc).   Maybe we can name our Dependency updates as well?  We 
> kind of almost do that with the grouping logic that Solrbot uses anyway.
> 
> Plus, honestly, how can I make dependency management more fun?
> 
> So, with that long preamble, here are this month’s Breach Report: 
> https://claude.ai/artifact/HxtVJmaE3wcExeptY7yLgW?sk=HG4tZy6ogQKaewKqcEPvWg
> 
> Cat Name         PR Title
> V   Slattern     Revamp Solr Extraction Module to work with Tika 4
> IV  Otachi       Update Jersey jetty-http to v3 (branch_9x)
> III Knifehead    Update all non-major dependencies
> III Yamarashi    Update gRPC and Netty
> III Atticon      Update Web server stack to v12.1.13
> II  Raythe       Update Telemetry (OpenTelemetry & Prometheus)
> II  Clawhook     Update AWS SDK to v2.55.6
> II  Onibaba      Update Jackson BOM to v2.22.3
> II  Androc       Update Google Cloud
> II  Itak         Update Logging to v2.0.20
> II  Ragnarok     Update ZooKeeper & Curator to v3.9.6
> II  Crusherbone  Update Jackson BOM to v2.22.3 (branch_9x)
> I   Hardship     Update Avatica-core to v1.29.0
> I   Hammerjaw    Update Admin UI
> I   Ceptid       Update Okio to v3.18.2
> I   Tengu        Update GitHub Actions
> I   Karloff      Update GitHub Actions (branch_9x)
> I   Erupture     Update all non-major test dependencies (branch_9x)
> 
> Disclaimer
> 
> The information contained in this communication from the sender is 
> confidential. It is intended solely for use by the recipient and others 
> authorized to receive it. If you are not the recipient, you are hereby 
> notified that any disclosure, copying, distribution or taking action in 
> relation of the contents of this information is strictly prohibited and may 
> be unlawful.
> 
> This email has been scanned for viruses and malware, and may have been 
> automatically archived by Mimecast, a leader in email security and cyber 
> resilience. Mimecast integrates email defenses with brand protection, 
> security awareness training, web security, compliance and other essential 
> capabilities. Mimecast helps protect large and small organizations from 
> malicious activity, human error and technology failure; and to lead the 
> movement toward building a more resilient world. To find out more, visit our 
> website.
> 

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to