jdaugherty commented on code in PR #16408: URL: https://github.com/apache/grails-core/pull/16408#discussion_r4198380294
########## grails-doc/src/en/guide/upgrading/upgrading91x.adoc: ########## @@ -0,0 +1,70 @@ +//// +Licensed to the Apache Software Foundation (ASF) under one +or more contributor license agreements. See the NOTICE file +distributed with this work for additional information +regarding copyright ownership. The ASF licenses this file +to you under the Apache License, Version 2.0 (the +"License"); you may not use this file except in compliance +with the License. You may obtain a copy of the License at + +https://www.apache.org/licenses/LICENSE-2.0 + +Unless required by applicable law or agreed to in writing, +software distributed under the License is distributed on an +"AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY +KIND, either express or implied. See the License for the +specific language governing permissions and limitations +under the License. +//// + +=== Upgrade Instructions for Grails 9.0 to Grails 9.1 + +This guide outlines the changes introduced in Grails 9.1 and the steps required to upgrade your application. + +==== 1. Spring Boot 4.2 and Spring Framework 7.1 + +Grails 9.1 moves from Spring Boot 4.1 to Spring Boot {springBootVersion} and from Spring Framework 7.0 to Spring Framework {springVersion}. +The managed versions that change include Spring Security 7.2, Spring Data 2026.1, Micrometer 1.18 and Reactor 2026.0. +Review the https://github.com/spring-projects/spring-boot/wiki/Spring-Boot-4.2-Release-Notes[Spring Boot 4.2 Release Notes] and the https://github.com/spring-projects/spring-framework/wiki/Spring-Framework-7.1-Release-Notes[Spring Framework 7.1 Release Notes] for the changes that affect your application. + +==== 2. graphql-java 26 for GraphQL Applications + +Spring Boot 4.2 manages graphql-java 26, so applications using the GraphQL plugin (`grails-data-graphql`) move from graphql-java 25 to graphql-java 26.1. +graphql-java 26.0 contains breaking changes, listed in its https://github.com/graphql-java/graphql-java/releases/tag/v26.0[release notes]. +The ones that can affect a Grails application are: + +* *Query complexity limits are enforced by default.* +A query nested more than 100 levels deep, or selecting more than 100,000 fields, now fails validation with a `MaxQueryDepthExceeded` or `MaxQueryFieldsExceeded` error. +To raise the limits, or to turn them off, set new defaults when the application starts, for example in `BootStrap.groovy`: ++ +[source,groovy] +---- +import graphql.validation.QueryComplexityLimits + +class BootStrap { + + def init = { + QueryComplexityLimits.setDefaultLimits(QueryComplexityLimits.newLimits() + .maxDepth(150) + .maxFieldsCount(200_000) + .build()) + // or, to turn the limits off: + // QueryComplexityLimits.setDefaultLimits(QueryComplexityLimits.NONE) + } +} +---- ++ +graphql-java's parser separately rejects a query nested more than about 165 levels deep, so a `maxDepth` above that has no effect. + +* *Schemas built in code are validated like schemas built from SDL.* +A non-null argument or input field can no longer be deprecated. Review Comment: graphql-java's rule (`DeprecatedInputObjectAndArgumentsAreValid`) only rejects a non-null argument or input field that has **no default value**; a non-null one with a default can still be deprecated. Suggest: ```suggestion A required argument or input field (non-null with no default value) can no longer be deprecated. ``` ########## grails-skills/developer/skills/grails-developer/SKILL.md: ########## @@ -30,9 +30,9 @@ Activate this skill when developing with Grails, including: ## Technology Stack -Grails is built on: -- **Spring Boot**: 4.1.x -- **Spring Framework**: 7.0.x +Current Grails is built on: Review Comment: Confirmed at 5d176de0da, thanks. ########## dependencies.gradle: ########## @@ -75,37 +75,25 @@ ext { 'bootstrap-icons.version' : '1.13.1', 'bootstrap.version' : '5.3.8', 'checker-qual.version' : '3.55.1', - 'commons-codec.version' : '1.22.1', 'geb-spock.version' : '8.0.1', // Pinned deliberately as a drift tripwire even though it matches Spring Boot's // managed version: graphql-java-extended-scalars (below) is NOT managed by Spring // Boot and must be upgraded in lockstep with graphql-java. Keeping this pin makes // the dependency validator flag any Spring Boot graphql-java bump so we re-check // extended-scalars compatibility. See https://github.com/apache/grails-core/issues/15674 - 'graphql-java.version' : '25.0', + 'graphql-java.version' : '26.1', Review Comment: Thanks, this covers it. I checked the guide against the 26.1 sources: the `additionalTypes` signature, `GraphQLTypeUtil.unwrapAll` returning a named type, the `QueryComplexityLimits` API and defaults, the two `MaxQuery*` error types and the parser depth figure all line up, and both new specs pass in CI. One wording precision on the deprecation rule in the upgrade guide, left inline there. ########## AGENTS.md: ########## @@ -144,7 +144,7 @@ All managed dependency versions live in `dependencies.gradle` (the single source - **Do not suppress validation to work around a bump.** `allowedBomOverrides` (per-project ext) and dependency exclusions are reserved for an explicit, documented conflict or an agreed-upon workaround — never as a shortcut to silence a version the BOM should simply manage. Comment the reason when you must use one. - **A dependency managed in more than one BOM must use the *same* version everywhere.** Versions appear in `gradleBomDependencyVersions` (build tooling / `grails-gradle-bom`), `bomDependencyVersions` (`grails-bom`), and per-BOM `customBomVersions` blocks (e.g. `grails-hibernate7-bom`). `grails-bom` re-declares the gradle-BOM constraints, and the Hibernate BOMs are consumed via `enforcedPlatform`. Declaring one coordinate (e.g. `org.ow2.asm:asm`) at two different versions across these maps produces irreconcilable strict constraints and breaks `enforcedPlatform` resolution. Pin it once, consistently. - **Only libraries the Grails project also works on may use a snapshot version.** Between releases, `dependencies.gradle` often points at a `-SNAPSHOT` or release-candidate version of one of our own libraries, such as the Asset Pipeline (`cloud.wondrify`), SiteMesh 3 (`org.sitemesh`), or the Grails Publish plugin (`org.apache.grails.gradle:grails-publish`). These are switched to their published version before a Grails release (see `RELEASE.md`). Do not suggest replacing them with a released version, and do not flag them in reviews. Never use a snapshot of any other library, such as Jackson or Spring. The snapshot repositories in `GrailsRepoSettingsPlugin` only serve the `org.apache.grails*`, `org.apache.groovy*`, `cloud.wondrify*`, and `org.sitemesh*` groups, so a snapshot of any other library will not resolve (unless `GRAILS_INCLUDE_MAVEN_LOCAL` is set for a local build). Do not widen those content filters to get one. -- **Prefer inheriting from the Spring Boot BOM.** Do not re-pin a coordinate that `spring-boot-dependencies` (4.1.x) already manages unless you are intentionally overriding it to a newer version (e.g. a security fix); note the reason inline. +- **Prefer inheriting from the Spring Boot BOM.** Do not re-pin a coordinate that `spring-boot-dependencies` (4.2.x) already manages unless you are intentionally overriding it to a newer version (e.g. a security fix); note the reason inline. Review Comment: Thanks, that reads well now. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
