jdaugherty commented on PR #15341: URL: https://github.com/apache/grails-core/pull/15341#issuecomment-5917543478
@sanjana2505006 thanks for the patience on this one. I pushed a commit to your branch (after merging current `7.0.x`) that gets the guard working end to end, since a few things had moved underneath it since April: - **The settings plugin could no longer apply on `7.0.x`.** We added the Sonatype vulnerability scan plugin to `build-logic` in May. It is a fat jar that bundles Guava 29 without relocating it, and because `build-logic` is a pluginManagement included build, that copy ended up on every settings classloader and tripped DAGP's "requires Guava 33.1.0 or higher" check. The scan plugin now lives in its own `build-logic/vulnerability-scan` project, so only the modules that apply it load it, in a project-scope classloader. Same plugin id, nothing else changes for the modules. - **Only duplicate classes fail the build.** `onAny` is now `warn` and `onDuplicateClassWarnings` is `fail`, so the unused/transitive/configuration advice stays advisory instead of turning every module red. - **The duplicates that exist today are excluded by class name.** A full `buildHealth` over the repository found four pairs, all libraries that deliberately ship another library's classes: `tomcat-embed-core` vs `jakarta.servlet-api`, `spring-jcl` vs `jcl-over-slf4j`, Angus `jakarta.mail` vs `jakarta.mail-api`, and jline 2 vs jansi. DAGP matches duplicate-class exclusions on class names rather than coordinates, so each has a commented `excludeRegex` entry in the shared script. Dropping `jcl-over-slf4j` is the real fix for the second one, but it is declared as `api` in 37 modules and changes published POMs, so that is a follow-up. - **Two of our own tasks wrote into the main classes directory.** DAGP reads `classesDirs` directly, and `copyAstClasses` (Grails plugin Gradle plugin) and the gson-templates `compileViews` task also write there, which made Gradle's implicit-dependency validation fail in ten modules. Both now declare themselves as producers of the main `classesDirs`; the plugin change has a TestKit spec. - **CI enforces it.** `buildHealth` runs with every `./gradlew build` in the workflow, and the root jobs also run `:build-logic-root:buildHealth`. Docs in `AGENTS.md` and the `build-logic` README are updated, and the plugin is bumped to 3.19.2. Verified locally: settings evaluate in all four builds, `buildHealth` is green in each with zero duplicates left, and a deliberately introduced duplicate that the module's code references does fail the build. One caveat worth knowing: DAGP only reports a duplicate for classes the analyzed module itself references, which is noted in the config comments. I will take it out of draft once CI confirms. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
