matrei commented on PR #16519:
URL: https://github.com/apache/grails-core/pull/16519#issuecomment-5999067824

   @jdaugherty Agreed, the test apps should be updated, but not through these 
Dependabot PRs. I'd close all six:
   
   - **Bootstrap 3.3.6 → 3.3.7-1** (#16440, #16445, #16439) puts the same 
version in every `build.gradle` that declares `org.webjars:bootstrap`. In the 
four `ldap/*` apps, that downgrades Bootstrap from 4.1.3 to 3.3.7-1. It also 
leaves `application.js`/`application.css` requiring 
`webjars/bootstrap/3.3.6/...` and `webjars/bootstrap/4.1.3/...`, so those 
requires point at versions that aren't on the classpath anymore. The checks 
pass anyway because nothing tests whether the assets load.
   - **jquery-ui 1.10.3 → 1.10.4-1** (#16441, #16444, #16438) also bumps 
`jquery-ui-themes` to 1.10.4-1, a version that was never published (Maven 
Central goes from 1.10.3 to 1.11.0). Every build fails with `Could not find 
org.webjars:jquery-ui-themes:1.10.4-1`. This one is the spring-security-ui 
plugin itself, which ships, and its assets hardcode 
`webjars/jquery-ui/1.10.3/...` too.
   
   For the test apps, a separate PR could switch the `cas` and `ldap` examples 
to the BOM-managed `org.webjars.npm` jquery/bootstrap without versions, and use 
`%` in place of the version directory in the require paths, as `create-app` 
does. The same `%` fix applies to the `mail` and `redis` examples on 8.0.x. I'd 
leave jquery-ui in the spring-security-ui plugin alone on 7.x, since that's a 
shipped artifact and not a patch-level change.
   
   We should also add an `org.webjars` ignore to the `/grails-forge` entries in 
`dependabot.yml`, or these PRs will come back.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to