jdaugherty commented on PR #16025:
URL: https://github.com/apache/grails-core/pull/16025#issuecomment-5820089937

   I've pushed a set of updates to this branch: `f760fd63e4` through 
`9fe96f9f48`. Summary:
   
   **8.0.x merge (`f760fd63e4`)**
   - Resolved conflicts in `AGENTS.md`, `build-logic/plugins/build.gradle`, and 
`gradle/rat-root-config.gradle`. This includes the benchmarks move to 
`grails-test-examples/benchmarks`.
   - Dropped the RAT exclusion for `grails-bom/micronaut`, which no longer 
exists.
   
   **Review follow-ups that were marked resolved but not actually addressed 
(`61a5a2196d`)**
   - `.asf.yaml` is no longer excluded from RAT. It carries a license header 
and ships in the source zip, so RAT audits it.
   - `.worktrees/` is now excluded from the repository-conventions scans as 
well as from RAT and the zip. Each worktree is a complete checkout.
   - Restored the SpotBugs report block formatting in 
`GrailsCodeAnalysisPlugin`.
   - Removed an unused `ignoreFailures` provider.
   - Three specs could not fail when the behavior they claimed to cover broke. 
They now fail as intended, and each was verified by removing the behavior it 
covers:
     - the local-workflow recursion spec
     - the UTF-8 skill-decoding spec
     - the PMD opt-in spec, now a table covering each enable path alone and 
combined
   
   **GitHub Actions references**
   - Every `actions/*` SHA pin that landed on 8.0.x is reverted to its major 
version tag, taken from the pin's own `# vX.Y.Z` comment, so no action changes 
major version.
   - `validateRepositoryConventions` now rejects commit SHAs for `actions/*` 
and `apache/*`, so the pins can't come back.
   - Third-party actions, including `github/*`, stay SHA-pinned.
   - `validateActions` still passes, since it auto-approves these namespaces.
   - `AGENTS.md` now documents this policy.
   
   **Code review findings (`13b8c54c3d`)**
   - `.claude/worktrees/` (Claude Code's default worktree location) is excluded 
like `.worktrees/`. `.claude/settings.local.json` is ignored by git and RAT.
   - A `SKILL.md` symlinked into `.agents/skills` is validated by its 
repository path instead of being silently skipped.
   - `validateRepositoryConventions` is now kept up to date by Gradle and walks 
the checkout once. The walk skips nested build output and `node_modules`.
   - A `./...` action reference with no `action.yml` or `action.yaml` is now a 
violation.
   - `findRootGrailsCoreDir` fails with a clear error instead of returning 
null. The nearest `.asf.yaml` wins, so a nested worktree resolves to itself.
   - The redundant root check is replaced with 
`GradleUtils.isRootGrailsCoreDir`.
   - Malformed or non-mapping skill front matter now produces one violation, 
not four.
   - An explicit `-Pgrails.code-analysis.enabled.pmd=true|false` (or 
`spotbugs`) overrides module opt-ins.
   - "Modules analyzed" lists only modules whose report was read.
   - Removed a stray `worktrees/*` zip exclude.
   
   **Up-to-date analyzers (`937dc7472c`)**
   - The aggregate lane no longer deletes analyzer outputs on every run.
     - On the full repository, a second `aggregateStyleViolations 
aggregateAnalysisViolations` takes 15s instead of 3m 6s, with every CodeNarc, 
Checkstyle, and PMD task UP-TO-DATE.
   - Report markers now live in each module's own `build/`. Gradle only removes 
a NO-SOURCE task's previous outputs inside build directories it owns. With the 
markers in the root `build/`, deleting a module's sources left its old findings 
in the report.
   - New `cleanViolationReports` task forces full re-analysis.
     - The root project had no `clean`, so `./gradlew clean` never touched 
these reports. The plugin now registers a root `clean` that runs it.
     - `./gradlew clean aggregateViolations` now really starts fresh.
   - New `-PskipCodeAnalysis` skips PMD and SpotBugs only. `-PskipCodeStyle` 
still skips every analyzer, so existing CI jobs are unchanged. Skipped runs 
write "skipped" reports instead of reusing an earlier run's results.
   
   **Docs (`9fe96f9f48`)**
   - `DEVELOPMENT.md` documents `aggregateViolations`, `cleanViolationReports`, 
`validateRepositoryConventions`, both skip flags, and the per-module 
PMD/SpotBugs opt-in with its override properties.
   - `AGENTS.md` and the violation-fixer skill are updated to match.
   
   **Verification**
   - `build-logic` check: 180 tests, 0 failures.
   - `validateRepositoryConventions`, `validateActions`, and `rat` pass on the 
merged tree.
   - PMD passes on the four opted-in modules.
   - The PR description is updated to match.
   
   Still open: `snakeyamlVersion` in `gradle.properties` duplicates the version 
Spring Boot's BOM already manages. Leaving that for a follow-up.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to