[
https://issues.apache.org/jira/browse/KAFKA-20851?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18104885#comment-18104885
]
Dejan Stojadinović edited comment on KAFKA-20851 at 8/15/26 2:20 PM:
---------------------------------------------------------------------
-PR [https://github.com/apache/kafka/pull/23164] will stay in a draft state
until owasp dependency check plugin version 13.0.1 is released:-
[-https://github.com/dependency-check/DependencyCheck/milestone/107-]
was (Author: dejan2609):
PR [https://github.com/apache/kafka/pull/23164] will stay in a draft state
until owasp dependency check plugin version 13.0.1 is released:
[https://github.com/dependency-check/DependencyCheck/milestone/107]
> Version updates for build dependencies
> --------------------------------------
>
> Key: KAFKA-20851
> URL: https://issues.apache.org/jira/browse/KAFKA-20851
> Project: Kafka
> Issue Type: Task
> Components: build
> Reporter: Dejan Stojadinović
> Assignee: Dejan Stojadinović
> Priority: Minor
> Labels: Gradle, buid, gradle, jacoco, reporting, swagger, update
> Fix For: 4.5.0
>
>
> (on) *Action points:*
> * jacoco: 0.8.14 -->> 0.8.15
> * zinc: 1.12.0 -->> 1.12.1
> * swagger: 2.2.52 -->> 2.2.53
> * gradle-versions-plugin: 0.56.0 -->> 0.61.0 *(to improve `./gradlew
> dependencyUpdates` task result output)*
> * -owasp dependency check plugin: 12.2.2 -->> 13.0.0- {color:#ff0000}*( (!)
> {-}note: we would have to wait for 13.0.1{-})*{color}
> * spotbugs gradle plugin: 6.5.9 -->> 6.5.10
> * spotless gradle plugin: 8.4.0 -->> 8.9.0 *(note: extensively tested)*
> *Important notes and remarks:*
> * spotless gradle plugin version update is verified locally:
> ** {{./gradlew build -x test}} passes (spotlessCheck + checkstyle + spotbugs
> + compile all green)
> ** {{./gradlew clean spotlessApply --rerun-tasks --no-build-cache}} ran 1000
> times with 0 failures
> * gradle-versions-plugin:
> ** *_dependencyUpdates_* task output looks better now
> ** plugin developers used Kafka codebase for 0.57.0 and 0.58.0 versions :)
> *Release notes:*
> * jacoco: [https://github.com/jacoco/jacoco/releases/tag/v0.8.15]
> * zinc: [https://github.com/sbt/zinc/releases/tag/v1.12.1]
> * spotless gradle plugin:
> ** [https://github.com/diffplug/spotless/releases/tag/gradle%2F8.9.0]
> ** [https://github.com/diffplug/spotless/releases/tag/gradle%2F8.8.0]
> ** [https://github.com/diffplug/spotless/releases/tag/gradle%2F8.7.0]
> ** [https://github.com/diffplug/spotless/releases/tag/gradle%2F8.6.0]
> ** [https://github.com/diffplug/spotless/releases/tag/gradle%2F8.5.1]
> ** [https://github.com/diffplug/spotless/releases/tag/gradle%2F8.5.0]
> * gradle-versions-plugin:
> **
> [https://github.com/ben-manes/gradle-versions-plugin/tree/v0.61.0#migrating-from-prior-versions]
> ** [https://github.com/ben-manes/gradle-versions-plugin/releases/tag/v0.57.0]
> ** [https://github.com/ben-manes/gradle-versions-plugin/releases/tag/v0.58.0]
> ** [https://github.com/ben-manes/gradle-versions-plugin/releases/tag/v0.59.0]
> ** [https://github.com/ben-manes/gradle-versions-plugin/releases/tag/v0.60.0]
> ** [https://github.com/ben-manes/gradle-versions-plugin/releases/tag/v0.61.0]
> * owasp dependency-check plugin:
> [https://github.com/dependency-check/DependencyCheck/releases/tag/v13.0.0]
> * spotbugs gradle plugin:
> [https://github.com/spotbugs/spotbugs-gradle-plugin/releases/tag/6.5.10]
> * swagger:
> ** [https://github.com/swagger-api/swagger-core/releases/tag/v2.2.53]
> **
> [https://github.com/swagger-api/swagger-core/blob/v2.2.53/modules/swagger-gradle-plugin/README.md]
> ----
> h3. Additional notes and details about Gradle plugin version updates:
> {panel:title=1. Spotless gradle
> plugin|borderStyle=dashed|borderColor=#cccccc|titleBGColor=#f7d6c1|bgColor=#ffffce}
> Plugin issue [https://github.com/diffplug/spotless/issues/2850] is still
> pending (hence these version bump should be tested thoroughly (see test
> procedure below)
> * KAFKA-20182 and related GitHub PR's:
> ** [https://github.com/apache/kafka/pull/22012]
> ** [https://github.com/apache/kafka/pull/22025]
> (!) *Test procedure (note: must be done locally):*
> # *./gradlew build -x test* passes (/) (spotlessCheck + checkstyle +
> spotbugs + compile all)
> # run in a loop (hundreds of times): *./gradlew spotlessApply --rerun-tasks
> --no-build-cache*
> ** note: for loop testing I created this script -->
> {*}_repeatUntilBuildFails.sh_{*}:
> {code:java}
> #!/bin/bash
> counter=0
> while ./gradlew clean spotlessApply --rerun-tasks --no-build-cache; do
> ((counter++))
> echo
> "**************************************************************************"
> echo "### Build succeeded (execution number: $counter) -->> running
> again... ###"
> echo
> "**************************************************************************"
> done
> ((counter++))
> echo ">>> Build failed on execution number: $counter at $(date) <<<"
> {code}
> *Note: test procedure taken from here (see commit messages):*
> *
> [https://github.com/apache/kafka/commit/7aaf4de8207dda7809735597383d3771810a4385]
> *
> [https://github.com/apache/kafka/commit/2327e51926d666d979f8363dedf0894390430a7c]{panel}
> {panel:title=2.
> Gradle-versions-plugin|borderStyle=dashed|borderColor=#cccccc|titleBGColor=#f7d6c1|bgColor=#e7ffce}
> *Rationale:*
> * I tried to update jacoco version (0.8.14 -->> 0.8.15) but stumbled upon on
> (turns out not to be an) issue:
> [https://github.com/ben-manes/gradle-versions-plugin/issues/1028]; however
> gradle-versions-plugin team covered this case in docs (they added a new
> section in their `README.md`):
> ** [https://github.com/ben-manes/gradle-versions-plugin/pull/1030]
> ** [https://github.com/ben-manes/gradle-versions-plugin/releases/tag/v0.57.0]
> * Upon testing plugin version 0.57.0, I filed another ticket:
> [https://github.com/ben-manes/gradle-versions-plugin/issues/1032] and while
> this was a non-issue (yet again) gradle-versions-plugin developers used my
> report and Kafka codebase to improve output for their `dependencyUpdates`
> task:
> ** [https://github.com/ben-manes/gradle-versions-plugin/pull/1035]
> ** [https://github.com/ben-manes/gradle-versions-plugin/pull/1036]
> **
> [https://github.com/ben-manes/gradle-versions-plugin/releases/tag/v0.58.0]{panel}
> {panel:title= 3. OWASP dependency-check plugin: >>> Note: will be handled
> elsewhere ! <<<
> |borderStyle=dashed|borderColor=#cccccc|titleBGColor=#f7d6c1|bgColor=#aae1ef}
> Plugin version 13.0.0 gradle tasks fail without valid NVD API key (see
> below); *this issue will be solved in a soon-to-be-released 13.0.1 patch*
> ([https://github.com/dependency-check/DependencyCheck/milestone/107]):
> * [https://github.com/dependency-check/DependencyCheck/issues/8715]
> * [https://github.com/dependency-check/DependencyCheck/pull/8716]
> Note: it seems this 13.0.0 issue is a regression (that has a workaround -->>
> [https://github.com/dependency-check/DependencyCheck/issues/8424#issuecomment-4253850117]):
> {code:java}
> ./gradlew dependencyCheckPurge dependencyCheckUpdate
> > Configure project :
> Starting build with version 4.4.0-SNAPSHOT (commit id 535dce1e) using Gradle
> 9.6.1, Java 25 and Scala 2.13.18
> Build properties: ignoreFailures=false, maxParallelForks=8,
> maxScalacThreads=8, maxTestRetries=0
> > Task :dependencyCheckUpdate
> Error updating the NVD Data
> org.owasp.dependencycheck.data.update.exception.UpdateException: Error
> updating the NVD Data
> at
> org.owasp.dependencycheck.data.update.NvdApiDataSource.processApi(NvdApiDataSource.java:387)
>
> ...
> at [email protected]/java.lang.Thread.run(Thread.java:1474)
> Caused by: io.github.jeremylong.openvulnerability.client.nvd.NvdApiException:
> Invalid API Key, length of 0 too short to provided a masked partial key
> at
> io.github.jeremylong.openvulnerability.client.nvd.NvdCveClient._next(NvdCveClient.java:436)
> at
> io.github.jeremylong.openvulnerability.client.nvd.NvdCveClient.next(NvdCveClient.java:356)
> at
> org.owasp.dependencycheck.data.update.NvdApiDataSource.processApi(NvdApiDataSource.java:343)
> ... 141 more
> > Task :dependencyCheckUpdate FAILED
> [Incubating] Problems report is available at:
> file:///home/dejan/kafka/build/reports/problems/problems-report.html
> FAILURE: Build failed with an exception.
> * What went wrong:
> Execution failed for task ':dependencyCheckUpdate' (registered by plugin
> 'org.owasp.dependencycheck').
> > Error updating the NVD Data
> * Try:
> > Run with --stacktrace option to get the stack trace.
> > Run with --info or --debug option to get more log output.
> > Get more help at https://help.gradle.org.
> Deprecated Gradle features were used in this build, making it incompatible
> with Gradle 10.
> You can use '--warning-mode all' to show the individual deprecation warnings
> and determine if they come from your own scripts or plugins.
> For more on this, please refer to
> https://docs.gradle.org/9.6.1/userguide/command_line_interface.html#sec:command_line_warnings
> in the Gradle documentation.
> BUILD FAILED in 51s
> 8 actionable tasks: 2 executed, 6 up-to-date
> {code}
> {panel}
--
This message was sent by Atlassian Jira
(v8.20.10#820010)