Skip to content

Commit 1285f16

Browse files
committed
build(deps): bump build plugins and analysis tooling to current
Pure version maintenance, no behaviour change in the library. Two groups: Cross-repo drift, closed. The four sibling repos deliberately run the same toolchain versions, and BitcoinAddressFinder pulled ahead when its Dependabot PRs were merged. This brings the rest back in step: maven-compiler-plugin 3.15.0 -> 3.16.0 maven-surefire-plugin 3.5.6 -> 3.6.0 nullaway 0.14.0 -> 0.14.1 Behind current upstream in all four repos: git-commit-id-maven-plugin 10.0.0 -> 10.0.1 spotless-maven-plugin 3.10.1 -> 3.10.2 spotbugs-maven-plugin 4.10.4.0 -> 4.10.4.1 checker / checker-qual 4.2.2 -> 4.2.3 lombok 1.18.46 -> 1.18.48 slf4j-api / slf4j-simple 2.0.18 -> 2.0.19 The compiler and surefire versions also live under different property names in llama-langchain4j (compiler.plugin.version, surefire.version) and llama-kotlin (surefire.version); those are bumped too, so the reactor is internally consistent rather than only the core module. The checker bump moves ONE property that feeds both the annotation processor and the qualifiers, and that coupling is the point: the Nullness Checker resolves its own qualifiers through javac's symbol table, so the two must share a major version. That is the lesson from the 3.55.1 pin reverted in #412; the prose in the checker-qual comment is updated to match. Deliberately NOT bumped: jqwik stays at 1.9.3. Releases from 1.10.0 on print a prompt-injection string aimed at AI coding agents, and the workspace policy (policies/jqwik-prompt-injection.md) requires rejecting any PR that moves it. Dependabot will keep proposing it. A worthwhile side effect of surefire 3.6.0, verified by diffing the per-class reports before and after: a class whose @BeforeAll assumption aborts the whole class is now reported as SKIPPED instead of as `tests=0, skipped=0`. That is exactly the blind spot CLAUDE.md documents under "CI model policy" -- the shape that let every model-gated class silently contribute nothing while the job stayed green. Locally, model-free, it turns 25 classes and 256 tests from invisible into visibly skipped (1486/17 -> 1742/273). CI has the models, so those classes still run there; what changes is that a run which fails to provide them can no longer look like a full pass. Verified locally in this repo: mvn clean verify green, ctest 520/520, PIT 319/319 mutations killed (100%), the class-file gate clean over llama/target including a real `-P assembly` fat jar (1904 classes, 0 above major 52). slf4j-simple 2.0.19 was checked entry by entry rather than in aggregate: its only major-53 entry is META-INF/versions/9/module-info.class, which a classpath JVM never loads and the gate skips by design -- identical to 2.0.18. The fat jar carries the 7 slf4j-simple entries and 0 checkerframework classes, as intended. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01AnNYn8W1xuVxVJtyL34GyH
1 parent c6b0c35 commit 1285f16

3 files changed

Lines changed: 13 additions & 13 deletions

File tree

‎llama-kotlin/pom.xml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -64,7 +64,7 @@ SPDX-License-Identifier: MIT
6464
<kotlinx.coroutines.version>1.11.0</kotlinx.coroutines.version>
6565
<junit.version>6.1.3</junit.version>
6666
<hamcrest.version>3.0</hamcrest.version>
67-
<surefire.version>3.5.6</surefire.version>
67+
<surefire.version>3.6.0</surefire.version>
6868
<source.plugin.version>3.4.0</source.plugin.version>
6969
<jar.plugin.version>3.5.1</jar.plugin.version>
7070
</properties>

‎llama-langchain4j/pom.xml‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -62,8 +62,8 @@ SPDX-License-Identifier: MIT
6262
<hamcrest.version>3.0</hamcrest.version>
6363
<!-- Plugin versions are kept in lockstep with the core pom.xml. This module has no
6464
parent, so it cannot inherit their pluginManagement and must pin them here. -->
65-
<compiler.plugin.version>3.15.0</compiler.plugin.version>
66-
<surefire.version>3.5.6</surefire.version>
65+
<compiler.plugin.version>3.16.0</compiler.plugin.version>
66+
<surefire.version>3.6.0</surefire.version>
6767
<source.plugin.version>3.4.0</source.plugin.version>
6868
<javadoc.plugin.version>3.12.0</javadoc.plugin.version>
6969
</properties>

‎llama/pom.xml‎

Lines changed: 10 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -56,16 +56,16 @@ SPDX-License-Identifier: MIT
5656
<properties>
5757
<sonar.organization>bernardladenthin</sonar.organization>
5858
<jspecify.version>1.0.1</jspecify.version>
59-
<lombok.version>1.18.46</lombok.version>
59+
<lombok.version>1.18.48</lombok.version>
6060
<errorprone.version>2.50.0</errorprone.version>
61-
<nullaway.version>0.14.0</nullaway.version>
61+
<nullaway.version>0.14.1</nullaway.version>
6262
<!-- Checker Framework: the processor AND the checker-qual qualifiers it resolves.
6363
Both run on the build JDK and neither ships (checker-qual is provided scope), so
6464
this tracks the newest release. -->
65-
<checker.version>4.2.2</checker.version>
65+
<checker.version>4.2.3</checker.version>
6666
<jackson.version>2.22.2</jackson.version>
6767
<reactor.version>3.8.7</reactor.version>
68-
<slf4j.version>2.0.18</slf4j.version>
68+
<slf4j.version>2.0.19</slf4j.version>
6969
<logback.version>1.6.3</logback.version>
7070
<animal-sniffer.version>1.27</animal-sniffer.version>
7171
<junit.version>6.1.3</junit.version>
@@ -90,10 +90,10 @@ SPDX-License-Identifier: MIT
9090
section "jqwik prompt-injection in test output" for full context. -->
9191
<jqwik.version>1.9.3</jqwik.version>
9292
<archunit.version>1.5.0</archunit.version>
93-
<spotbugs.version>4.10.4.0</spotbugs.version>
93+
<spotbugs.version>4.10.4.1</spotbugs.version>
9494
<fb-contrib.version>7.7.4</fb-contrib.version>
9595
<findsecbugs.version>1.14.0</findsecbugs.version>
96-
<spotless.version>3.10.1</spotless.version>
96+
<spotless.version>3.10.2</spotless.version>
9797
<palantir-java-format.version>2.97.0</palantir-java-format.version>
9898
<project.build.sourceEncoding>UTF-8</project.build.sourceEncoding>
9999
<project.build.outputTimestamp>2026-09-01T07:57:45Z</project.build.outputTimestamp>
@@ -199,7 +199,7 @@ SPDX-License-Identifier: MIT
199199
org.checkerframework.framework.qual.DoesNotUnrefineReceiver". Processor and
200200
qualifiers must share a major version.
201201
202-
provided scope resolves both constraints at once: 4.2.2 is on the compile
202+
provided scope resolves both constraints at once: 4.2.3 is on the compile
203203
classpath where the checker needs it, and provided is excluded from consumers'
204204
transitive graph AND from the fat jar (jar-with-dependencies takes scope
205205
runtime), so no checker-qual class of any version reaches a consumer's JVM.
@@ -349,7 +349,7 @@ SPDX-License-Identifier: MIT
349349
<plugin>
350350
<groupId>io.github.git-commit-id</groupId>
351351
<artifactId>git-commit-id-maven-plugin</artifactId>
352-
<version>10.0.0</version>
352+
<version>10.0.1</version>
353353
</plugin>
354354
<plugin>
355355
<groupId>org.apache.maven.plugins</groupId>
@@ -359,7 +359,7 @@ SPDX-License-Identifier: MIT
359359
<plugin>
360360
<groupId>org.apache.maven.plugins</groupId>
361361
<artifactId>maven-compiler-plugin</artifactId>
362-
<version>3.15.0</version>
362+
<version>3.16.0</version>
363363
</plugin>
364364
<plugin>
365365
<groupId>org.apache.maven.plugins</groupId>
@@ -389,7 +389,7 @@ SPDX-License-Identifier: MIT
389389
<plugin>
390390
<groupId>org.apache.maven.plugins</groupId>
391391
<artifactId>maven-surefire-plugin</artifactId>
392-
<version>3.5.6</version>
392+
<version>3.6.0</version>
393393
<configuration>
394394
<!--
395395
Tests in the `vmlens` package are meaningful only when run

0 commit comments

Comments
 (0)