Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions .github/workflows/osv-scanner.yml
Original file line number Diff line number Diff line change
Expand Up @@ -17,15 +17,15 @@ permissions: read-all
jobs:
scan-scheduled:
if: ${{ github.event_name == 'push' || github.event_name == 'schedule' || github.event_name == 'workflow_dispatch' }}
uses: "google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml@v2.5.1"
uses: "google/osv-scanner-action/.github/workflows/osv-scanner-reusable.yml@v2.6.0"
permissions:
actions: read
contents: read
security-events: write

scan-pr:
if: ${{ github.event_name == 'pull_request' }}
uses: "google/osv-scanner-action/.github/workflows/osv-scanner-reusable-pr.yml@v2.5.1"
uses: "google/osv-scanner-action/.github/workflows/osv-scanner-reusable-pr.yml@v2.6.0"
permissions:
actions: read
contents: read
Expand Down
4 changes: 2 additions & 2 deletions CLAUDE.md
Original file line number Diff line number Diff line change
Expand Up @@ -398,8 +398,8 @@ assume it has already been updated.
| Dependency | Version | Used by |
|---|---|---|
| `net.ladenthin:llama` | 5.2.0 | `srcmorph` (`provider` package only) — llama.cpp JNI binding; its own SLF4J binding is excluded transitively (see "Java 8 bytecode floor") |
| `org.slf4j:slf4j-api` | 2.0.18 (converged in the parent) | `srcmorph`, `srcmorph-cli`, the plugin |
| `org.slf4j:slf4j-simple` | 2.0.18 (converged in the parent) | `srcmorph-cli` (runtime binding) |
| `org.slf4j:slf4j-api` | 2.0.19 (converged in the parent) | `srcmorph`, `srcmorph-cli`, the plugin |
| `org.slf4j:slf4j-simple` | 2.0.19 (converged in the parent) | `srcmorph-cli` (runtime binding) |
| `ch.qos.logback:logback-classic` | 1.6.3 (converged in the parent) | `srcmorph` (**test scope only** — `ListAppender` capture) |
| `com.fasterxml.jackson.core:jackson-databind` | pinned in parent | `srcmorph-cli` (JSON config) |
| `com.fasterxml.jackson.dataformat:jackson-dataformat-yaml` | pinned in parent | `srcmorph-cli` (YAML config) |
Expand Down
11 changes: 11 additions & 0 deletions TODO.md
Original file line number Diff line number Diff line change
Expand Up @@ -28,6 +28,17 @@ everything below is genuinely still open.
so publishing that release is the likelier fix. Decide which, then re-run CI to confirm — this is
the one item here that blocks everything else in the repo.

- **Second latent red behind the one above: `spotbugs:check` fails on `srcmorph` with 4 findsecbugs
findings.** Found 2026-09-20 by compiling the reactor against a locally installed
`net.ladenthin:llama:5.2.0-SNAPSHOT` (`-Dllama.version=5.2.0-SNAPSHOT -DskipTests verify`), the
only way to get past the unresolvable pin: `LlamaCppJniProviderSupport` (introduced by `45b619c`,
2026-09-05) raises `CRLF_INJECTION_LOGS` ×2 and `IMPROPER_UNICODE` ×2, all reported at line 49, and
nothing in `srcmorph/spotbugs-exclude.xml` covers the class. It is invisible today only because
every CI run dies at the dependency step before spotbugs runs; the moment the 5.2.0 pin resolves,
`Code style (spotless) + package graph` goes red on this instead. Reproduced on the unmodified
`origin/main` tree, so it is not an artefact of the dependency sweep. Fix the code or add a
justified suppression per `../workspace/policies/spotbugs-suppressions.md` in the same change
that unblocks the pin.
- **The sixteen GPU classifier fat jars are verified structurally, never launched.** Since 1.2.0
`.github/verify-classifier-fatjars.sh` asserts each is the artifact its name claims (one jar per
classifier, a native for the promised OS/arch, a native set that differs from the default jar's, so
Expand Down
2 changes: 1 addition & 1 deletion srcmorph-cli/pom.xml
Original file line number Diff line number Diff line change
Expand Up @@ -59,7 +59,7 @@ SPDX-License-Identifier: Apache-2.0
<fb-contrib.version>7.7.4</fb-contrib.version>
<findsecbugs.version>1.14.0</findsecbugs.version>
<spotless.version>3.10.2</spotless.version>
<palantir-java-format.version>2.97.0</palantir-java-format.version>
<palantir-java-format.version>2.98.0</palantir-java-format.version>

<project.build.outputTimestamp>2026-09-01T07:56:35Z</project.build.outputTimestamp>
</properties>
Expand Down
4 changes: 2 additions & 2 deletions srcmorph-maven-plugin/pom.xml
Original file line number Diff line number Diff line change
Expand Up @@ -98,7 +98,7 @@ SPDX-License-Identifier: Apache-2.0
<fb-contrib.version>7.7.4</fb-contrib.version>
<findsecbugs.version>1.14.0</findsecbugs.version>
<spotless.version>3.10.2</spotless.version>
<palantir-java-format.version>2.97.0</palantir-java-format.version>
<palantir-java-format.version>2.98.0</palantir-java-format.version>

<ai.index.output.directory>${project.basedir}/src/site/ai</ai.index.output.directory>

Expand Down Expand Up @@ -347,7 +347,7 @@ SPDX-License-Identifier: Apache-2.0
<plugin>
<groupId>org.codehaus.mojo</groupId>
<artifactId>exec-maven-plugin</artifactId>
<version>3.6.3</version>
<version>3.6.4</version>
</plugin>
<plugin>
<groupId>org.jacoco</groupId>
Expand Down
2 changes: 1 addition & 1 deletion srcmorph/pom.xml
Original file line number Diff line number Diff line change
Expand Up @@ -91,7 +91,7 @@ SPDX-License-Identifier: Apache-2.0
<fb-contrib.version>7.7.4</fb-contrib.version>
<findsecbugs.version>1.14.0</findsecbugs.version>
<spotless.version>3.10.2</spotless.version>
<palantir-java-format.version>2.97.0</palantir-java-format.version>
<palantir-java-format.version>2.98.0</palantir-java-format.version>

<project.build.outputTimestamp>2026-09-01T07:56:35Z</project.build.outputTimestamp>
</properties>
Expand Down
Loading