jdaugherty commented on PR #15341:
URL: https://github.com/apache/grails-core/pull/15341#issuecomment-5917644144

   @sanjana2505006 thanks for the patience on this one. I pushed a commit to 
your branch (after merging current `7.0.x`) that gets the guard working end to 
end, since a few things had moved underneath it since April:
   
   - **The settings plugin could no longer apply on `7.0.x`.** We added the 
Sonatype vulnerability scan plugin to `build-logic` in May. It is a fat jar 
that bundles Guava 29 without relocating it, and because `build-logic` is a 
pluginManagement included build, that copy ended up on every settings 
classloader and tripped DAGP's "requires Guava 33.1.0 or higher" check. The 
scan plugin now lives in its own `build-logic/vulnerability-scan` project, so 
only the modules that apply it load it, in a project-scope classloader. Same 
plugin id, nothing else changes for the modules.
   - **Only duplicate classes fail the build.** `onAny` is now `warn` and 
`onDuplicateClassWarnings` is `fail`, so the unused/transitive/configuration 
advice stays advisory instead of turning every module red.
   - **The duplicates that exist today are excluded by class name.** A full 
`buildHealth` over the repository found four pairs, all libraries that 
deliberately ship another library's classes: `tomcat-embed-core` vs 
`jakarta.servlet-api`, `spring-jcl` vs `jcl-over-slf4j`, Angus `jakarta.mail` 
vs `jakarta.mail-api`, and jline 2 vs jansi. DAGP matches duplicate-class 
exclusions on class names rather than coordinates, so each has a commented 
`excludeRegex` entry in the shared script. Dropping `jcl-over-slf4j` is the 
real fix for the second one, but it is declared as `api` in 37 modules and 
changes published POMs, so that is a follow-up.
   - **Two of our own tasks wrote into the main classes directory.** DAGP reads 
`classesDirs` directly, and `copyAstClasses` (Grails plugin Gradle plugin) and 
the gson-templates `compileViews` task also write there, which made Gradle's 
implicit-dependency validation fail in ten modules. Both now declare themselves 
as producers of the main `classesDirs`; the plugin change has a TestKit spec.
   - **CI enforces it.** A new Build Health workflow runs `buildHealth` with 
one job per composite build (the core job also covers the `build-logic` 
included build), uploads the reports and prints them in the job summary, the 
same shape as the Code Style workflow. Docs in `AGENTS.md` and the 
`build-logic` README are updated, and the plugin is bumped to 3.19.2.
   
   Verified locally: settings evaluate in all four builds, `buildHealth` is 
green in each with zero duplicates left, and a deliberately introduced 
duplicate that the module's code references does fail the build. One caveat 
worth knowing: DAGP only reports a duplicate for classes the analyzed module 
itself references, which is noted in the config comments.
   
   I will take it out of draft once CI confirms.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to