dependabot[bot] opened a new pull request, #40325: URL: https://github.com/apache/beam/pull/40325
Bumps [com.diffplug.spotless](https://github.com/diffplug/spotless) from 7.2.1 to 8.10.3. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/diffplug/spotless/releases">com.diffplug.spotless's releases</a>.</em></p> <blockquote> <h2>Gradle Plugin v8.10.3</h2> <h3>Changes</h3> <ul> <li>Generate formatter defaults from version catalog. (<a href="https://redirect.github.com/diffplug/spotless/pull/3045">#3045</a>)</li> <li>Bump default <code>gson</code> version <code>2.13.2</code> -> <code>2.14.0</code>. (<a href="https://redirect.github.com/diffplug/spotless/pull/3045">#3045</a>)</li> <li>Bump default <code>zjsonpatch</code> version <code>0.4.14</code> -> <code>0.4.16</code>. (<a href="https://redirect.github.com/diffplug/spotless/pull/3045">#3045</a>)</li> <li>Bump default <code>jackson-dataformat-yaml</code> version <code>2.14.1</code> -> <code>2.20.1</code>. (<a href="https://redirect.github.com/diffplug/spotless/pull/3045">#3045</a>)</li> <li>Bump default <code>ktfmt</code> version <code>0.63</code> -> <code>0.64</code>. (<a href="https://redirect.github.com/diffplug/spotless/pull/2988">2988</a>)</li> <li>Bump default <code>cleanthat</code> version <code>2.25</code> -> <code>2.26</code>. (<a href="https://redirect.github.com/diffplug/spotless/pull/2882">#2882</a>)</li> <li>Bump default <code>jackson</code> version <code>2.20.1</code> -> <code>2.22.2</code>. (<a href="https://redirect.github.com/diffplug/spotless/pull/2819">#2819</a>)</li> <li>Bump default <code>javaparser</code> version <code>3.27.1</code> -> <code>3.28.2</code>. (<a href="https://redirect.github.com/diffplug/spotless/pull/3065">#3065</a>)</li> <li>Bump default <code>palantir-java-format</code> version <code>2.80.0</code> -> <code>2.98.0</code>. (<a href="https://redirect.github.com/diffplug/spotless/pull/3068">#3068</a>)</li> <li>Bump default <code>scalafmt</code> version <code>3.8.1</code> -> <code>3.11.5</code>. (<a href="https://redirect.github.com/diffplug/spotless/pull/2173">#2173</a>)</li> <li>Bump default <code>google-java-format</code> version <code>1.30.0</code> -> <code>1.36.1</code>. (<a href="https://redirect.github.com/diffplug/spotless/pull/3075">#3075</a>)</li> <li>Bump default <code>gherkin-utils</code> version <code>10.0.0</code> -> <code>12.0.2</code>. (<a href="https://redirect.github.com/diffplug/spotless/pull/2979">#2979</a>)</li> <li>We no longer publish a plugin marker for the legacy <code>com.diffplug.gradle.spotless</code> id, which has been redirecting to <code>com.diffplug.spotless</code> since 4.0. Builds that still request it now fail with <code>Plugin [id: 'com.diffplug.gradle.spotless'] was not found</code> instead of the migration message. (<a href="https://redirect.github.com/diffplug/spotless/pull/3086">#3086</a>)</li> </ul> <h3>Fixed</h3> <ul> <li>Fix release signing by using Gradle's required eight-digit signing subkey ID. (<a href="https://redirect.github.com/diffplug/spotless/pull/3105">#3105</a>)</li> <li>Fix race when creating the npm install cache directory. ((<a href="https://redirect.github.com/diffplug/spotless/pull/3096">#3096</a>)</li> <li>GrEclipse no longer emits expected OSGi and nested-jar warnings during initialization. (<a href="https://redirect.github.com/diffplug/spotless/issues/2445">#2445</a>)</li> <li><code>typescript</code> <code>prettier()</code> no longer emits a warning when its parser is already set to <code>typescript</code>. (<a href="https://redirect.github.com/diffplug/spotless/pull/3098">#3098</a>)</li> <li><code>versionCatalog()</code> preserves standalone comments at section boundaries and the end of the file. (<a href="https://redirect.github.com/diffplug/spotless/issues/3048">#3048</a>)</li> <li><code>versionCatalog()</code> preserves entries when comments contain unmatched brackets, preserves commas inside quoted strings, and keeps significant line boundaries in multiline entries. (<a href="https://redirect.github.com/diffplug/spotless/pull/3042">#3042</a>)</li> <li><code>versionCatalog()</code> now reports unfinished entries as lints at their starting line. These fail formatting by default, so upgrading may expose catalog errors that previously caused silent data loss. (<a href="https://redirect.github.com/diffplug/spotless/pull/3042">#3042</a>)</li> <li>Stop calling deprecated <code>Configuration.setVisible</code> from Gradle 9.0.0 (<a href="https://redirect.github.com/diffplug/spotless/pull/3053">#3053</a>)</li> <li>Eclipse JDT formatter step no longer fails with <code>NoClassDefFoundError</code> or <code>NoSuchMethodError</code> when lombok is active as a JVM agent (e.g. <code>-javaagent:lombok.jar</code> in Eclipse/VS Code/Cursor). (<a href="https://redirect.github.com/diffplug/spotless/issues/2795">#2795</a>)</li> </ul> <h2>Gradle Plugin v8.10.2</h2> <h3>Fixed</h3> <ul> <li><code>shortenFullyQualifiedTypes()</code> now shortens fully-qualified types used in expression contexts (such as static method calls, static fields, and enum constants) while avoiding imports that would change how existing unqualified type references resolve. (<a href="https://redirect.github.com/diffplug/spotless/pull/3039">#3039</a>)</li> <li>Eclipse JDT formatter step no longer fails with <code>NoClassDefFoundError</code> when lombok is active as a JVM agent (e.g. <code>-javaagent:lombok.jar</code> in Eclipse/VS Code/Cursor). (<a href="https://redirect.github.com/diffplug/spotless/issues/2795">#2795</a>)</li> </ul> <h2>Gradle Plugin v8.10.1</h2> <h3>Fixed</h3> <ul> <li><code>prettier()</code> and other npm-based steps no longer fail to start on npm 12 (<code>EUNKNOWNCONFIG</code> from <code>--scripts-prepend-node-path</code>). (<a href="https://redirect.github.com/diffplug/spotless/issues/3024">#3024</a>)</li> <li><code>spotlessInternalRegisterDependencies</code> now writes its output under a build directory that is configured after the plugin is applied, instead of always under the default <code>build/</code>. (<a href="https://redirect.github.com/diffplug/spotless/issues/2114">#2114</a>)</li> <li><code>targetExclude</code> now accepts a Gradle <code>Directory</code>, <code>DirectoryProperty</code>, or <code>Provider<Directory></code> and excludes the files under it. Previously the directory was treated as a single file, so excluding one silently did nothing. (<a href="https://redirect.github.com/diffplug/spotless/issues/2667">#2667</a>)</li> </ul> <h2>Gradle Plugin v8.10.0</h2> <h3>Added</h3> <ul> <li>New <code>shortenFullyQualifiedTypes()</code> step for Java, which replaces fully-qualified type names with their simple names and adds the imports they need. Best combined with <code>importOrder()</code> and <code>removeUnusedImports()</code>. (<a href="https://redirect.github.com/diffplug/spotless/issues/2945">#2945</a>)</li> <li>Add embedded lockfiles to Eclipse JDT for every supported version (<code>4.9</code> through <code>4.40</code>), so <code>eclipse()</code> resolves from Maven Central instead of querying a P2 update site. Versions without an embedded lockfile still fall back to P2 provisioning. (<a href="https://redirect.github.com/diffplug/spotless/issues/1996">#1996</a>)</li> </ul> <h3>Fixed</h3> <ul> <li><code>removeUnusedImports</code> no longer fails on Java <code>import module</code> declarations. (<a href="https://redirect.github.com/diffplug/spotless/issues/2890">#2890</a>)</li> <li><code>expandWildcardImports()</code> now builds its type-solver classpath from each Java source set's compile classpath instead of every resolvable configuration. Unrelated configurations (for example generated-code or custom resolvable configs that are not ready yet) are no longer resolved. (<a href="https://redirect.github.com/diffplug/spotless/issues/2998">#2998</a>)</li> <li><code>spotlessCheck</code> violation message now suggests the correct composite/included-build task path (e.g. <code>./gradlew :my-utils:spotlessApply</code>) instead of a bare <code>spotlessApply</code> / <code>:spotlessApply</code> that does not select included-build tasks. (<a href="https://redirect.github.com/diffplug/spotless/issues/2421">#2421</a>)</li> <li>Parallel multi-project builds no longer intermittently fail with "Cannot fingerprint input property 'stepsInternalEquality': ConfigurationCacheHackList cannot be serialized" / "Failed to provision P2 dependencies" when using <code>eclipse()</code> (or other P2-backed steps). Subprojects now share one deduping P2 provisioner and P2 queries are serialized process-wide. (<a href="https://redirect.github.com/diffplug/spotless/issues/3004">#3004</a>)</li> </ul> <h3>Changes</h3> <ul> <li>Default <code>google-java-format</code> remains <code>1.28.0</code> on JVM 17; bumps to <code>1.30.0</code> on JVM 21+; require at least <code>1.30.0</code> on JVM 25+ for <code>import module</code> support.</li> <li>Bump default <code>eclipse</code> version to latest <code>4.39</code> -> <code>4.40</code>. (<a href="https://redirect.github.com/diffplug/spotless/issues/1996">#1996</a>)</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/diffplug/spotless/commit/eae36d86664fb5b186eb4e082fd319709e528178"><code>eae36d8</code></a> Published gradle/8.10.3</li> <li><a href="https://github.com/diffplug/spotless/commit/61e2016ee3ac82fb565b587e04408ae45dc5b709"><code>61e2016</code></a> Published maven/3.10.3</li> <li><a href="https://github.com/diffplug/spotless/commit/49e0b074905b6360848f9ab9c54e6f015911e301"><code>49e0b07</code></a> Published lib/4.10.3</li> <li><a href="https://github.com/diffplug/spotless/commit/b7a77486c6e6aad738b68ffce4075949680362d5"><code>b7a7748</code></a> Fix release signing key ID format (<a href="https://redirect.github.com/diffplug/spotless/issues/3105">#3105</a>)</li> <li><a href="https://github.com/diffplug/spotless/commit/be8005aae5d5e17c6a2819b2c54df5268c5cf4c5"><code>be8005a</code></a> Document release signing correction (<a href="https://redirect.github.com/diffplug/spotless/issues/3105">#3105</a>)</li> <li><a href="https://github.com/diffplug/spotless/commit/073fe6199960d95f733dad9b4d9311c3148d4914"><code>073fe61</code></a> Use short signing subkey ID for release publishing</li> <li><a href="https://github.com/diffplug/spotless/commit/8ac44c7aa8c08ca9b00e86d4dd59d589e7da8f09"><code>8ac44c7</code></a> Fix race when creating the npm install cache directory (<a href="https://redirect.github.com/diffplug/spotless/issues/3096">#3096</a>)</li> <li><a href="https://github.com/diffplug/spotless/commit/3f2d95561185486350c02471dab99a28585e7b45"><code>3f2d955</code></a> Update dependency org.slf4j:slf4j-api to v2.0.20 (<a href="https://redirect.github.com/diffplug/spotless/issues/3100">#3100</a>)</li> <li><a href="https://github.com/diffplug/spotless/commit/0c70ca8904be526d40923f47b0fd8e9cfecfd33a"><code>0c70ca8</code></a> Merge branch 'main' into fix/npm-cache-directory-race</li> <li><a href="https://github.com/diffplug/spotless/commit/bbf44a47b7cbdd2c4f55880f9767f79f36c9b6ee"><code>bbf44a4</code></a> Fix GrEclipse initialization warnings (<a href="https://redirect.github.com/diffplug/spotless/issues/3097">#3097</a>)</li> <li>Additional commits viewable in <a href="https://github.com/diffplug/spotless/compare/gradle/7.2.1...gradle/8.10.3">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
