matrei commented on PR #16519: URL: https://github.com/apache/grails-core/pull/16519#issuecomment-5999067824
@jdaugherty Agreed, the test apps should be updated, but not through these Dependabot PRs. I'd close all six: - **Bootstrap 3.3.6 → 3.3.7-1** (#16440, #16445, #16439) puts the same version in every `build.gradle` that declares `org.webjars:bootstrap`. In the four `ldap/*` apps, that downgrades Bootstrap from 4.1.3 to 3.3.7-1. It also leaves `application.js`/`application.css` requiring `webjars/bootstrap/3.3.6/...` and `webjars/bootstrap/4.1.3/...`, so those requires point at versions that aren't on the classpath anymore. The checks pass anyway because nothing tests whether the assets load. - **jquery-ui 1.10.3 → 1.10.4-1** (#16441, #16444, #16438) also bumps `jquery-ui-themes` to 1.10.4-1, a version that was never published (Maven Central goes from 1.10.3 to 1.11.0). Every build fails with `Could not find org.webjars:jquery-ui-themes:1.10.4-1`. This one is the spring-security-ui plugin itself, which ships, and its assets hardcode `webjars/jquery-ui/1.10.3/...` too. For the test apps, a separate PR could switch the `cas` and `ldap` examples to the BOM-managed `org.webjars.npm` jquery/bootstrap without versions, and use `%` in place of the version directory in the require paths, as `create-app` does. The same `%` fix applies to the `mail` and `redis` examples on 8.0.x. I'd leave jquery-ui in the spring-security-ui plugin alone on 7.x, since that's a shipped artifact and not a patch-level change. We should also add an `org.webjars` ignore to the `/grails-forge` entries in `dependabot.yml`, or these PRs will come back. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
