Skip to content

Bump byte-buddy.version from 1.14.6 to 1.14.7 - #3161

Merged
scordio merged 1 commit into
mainfrom
dependabot/maven/byte-buddy.version-1.14.7
Aug 28, 2023
Merged

scordio merged 1 commit into
mainfrom
dependabot/maven/byte-buddy.version-1.14.7

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 28, 2023

Copy link
Copy Markdown
Contributor

Bumps byte-buddy.version from 1.14.6 to 1.14.7.
Updates net.bytebuddy:byte-buddy from 1.14.6 to 1.14.7

Release notes

Sourced from net.bytebuddy:byte-buddy's releases.

Byte Buddy 1.14.7

  • Correctly read minor version from class file.
  • Catch type resolution errors when applying Plugin.Engine.
Changelog

Sourced from net.bytebuddy:byte-buddy's changelog.

28. August 2023: version 1.14.7

  • Correctly read minor version from class file.
  • Catch type resolution errors when applying Plugin.Engine.
Commits
  • 0613ecb [maven-release-plugin] prepare release byte-buddy-1.14.7
  • 98d5648 [release] Release new version
  • dc5970d Add missing type.
  • c64c518 Fix tests.
  • 39271e0 [release] Release new version
  • 8265ef6 Merge pull request #1513 from stiemannkj1/issue-1512-engine-crashes-on-types-...
  • addd088 Fixes: #1512 Plugin Engine crashes on types with missing dependencies even wh...
  • b7f94db Merge pull request #1510 from SylvainJuge/java1-version
  • 9409ecc fix reading bytecode version for java 1
  • 76d90b1 Add method that allows the resolution of type names of annotations even if th...
  • Additional commits viewable in compare view

Updates net.bytebuddy:byte-buddy-agent from 1.14.6 to 1.14.7

Release notes

Sourced from net.bytebuddy:byte-buddy-agent's releases.

Byte Buddy 1.14.7

  • Correctly read minor version from class file.
  • Catch type resolution errors when applying Plugin.Engine.
Changelog

Sourced from net.bytebuddy:byte-buddy-agent's changelog.

28. August 2023: version 1.14.7

  • Correctly read minor version from class file.
  • Catch type resolution errors when applying Plugin.Engine.
Commits
  • 0613ecb [maven-release-plugin] prepare release byte-buddy-1.14.7
  • 98d5648 [release] Release new version
  • dc5970d Add missing type.
  • c64c518 Fix tests.
  • 39271e0 [release] Release new version
  • 8265ef6 Merge pull request #1513 from stiemannkj1/issue-1512-engine-crashes-on-types-...
  • addd088 Fixes: #1512 Plugin Engine crashes on types with missing dependencies even wh...
  • b7f94db Merge pull request #1510 from SylvainJuge/java1-version
  • 9409ecc fix reading bytecode version for java 1
  • 76d90b1 Add method that allows the resolution of type names of annotations even if th...
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps `byte-buddy.version` from 1.14.6 to 1.14.7.

Updates `net.bytebuddy:byte-buddy` from 1.14.6 to 1.14.7
- [Release notes](https://github.com/raphw/byte-buddy/releases)
- [Changelog](https://github.com/raphw/byte-buddy/blob/master/release-notes.md)
- [Commits](raphw/byte-buddy@byte-buddy-1.14.6...byte-buddy-1.14.7)

Updates `net.bytebuddy:byte-buddy-agent` from 1.14.6 to 1.14.7
- [Release notes](https://github.com/raphw/byte-buddy/releases)
- [Changelog](https://github.com/raphw/byte-buddy/blob/master/release-notes.md)
- [Commits](raphw/byte-buddy@byte-buddy-1.14.6...byte-buddy-1.14.7)

---
updated-dependencies:
- dependency-name: net.bytebuddy:byte-buddy
  dependency-type: direct:production
  update-type: version-update:semver-patch
- dependency-name: net.bytebuddy:byte-buddy-agent
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot Bot added the dependabot: Maven A dependency upgrade for Maven raised by Dependabot label Aug 28, 2023
@github-actions

Copy link
Copy Markdown

Qodana Community for JVM

It seems all right 👌

No new problems were found according to the checks applied

💡 Qodana analysis was run in the pull request mode: only the changed files were checked

View the detailed Qodana report

To be able to view the detailed Qodana report, you can either:

  1. Register at Qodana Cloud and configure the action
  2. Use GitHub Code Scanning with Qodana
  3. Host Qodana report at GitHub Pages
  4. Inspect and use qodana.sarif.json (see the Qodana SARIF format for details)

To get *.log files or any other Qodana artifacts, run the action with upload-result option set to true,
so that the action will upload the files as the job artifacts:

      - name: 'Qodana Scan'
        uses: JetBrains/[email protected]
        with:
          upload-result: true
Contact Qodana team

Contact us at [email protected]

@scordio
scordio merged commit 5ab0b76 into main Aug 28, 2023
@scordio
scordio deleted the dependabot/maven/byte-buddy.version-1.14.7 branch August 28, 2023 22:13
@NotMyFault

Copy link
Copy Markdown

Hey @scordio,

would it be possible to publish a new release including this change? The current version of byte-buddy does not support Java 21 yet :(

Compiling assertj from source and using assertj-core in a downstream project, I can verify that my tests are passing and
Java 21 (65) is not supported by the current version of Byte Buddy which officially supports Java 20 (64)
is gone.

@scordio

scordio commented Aug 30, 2023

Copy link
Copy Markdown
Member

Hi @NotMyFault, AssertJ no longer shades Byte Buddy (#2477) so it should be possible to override its version with an explicit declaration of the dependency.

Would that work for you?

@NotMyFault

Copy link
Copy Markdown

AssertJ no longer shades Byte Buddy (#2477)

Oh, I wasn't aware of that! Currently, I'm using assertj-core 3.24.2, but apparently byte-buddy is a provided dependency still:

Screenshot 2023-08-30 at 17 55 26

Compiling from source ships byte-buddy 1.14.7, as this PR updates to. Therefore, I was confident cutting a new release addresses the former issue:

Screenshot 2023-08-30 at 17 56 23

Shouldn't it be the case that byte-buddy is no longer shipped/managed, according to your comment?

@scordio

scordio commented Aug 30, 2023 •

Copy link
Copy Markdown
Member

It is indeed a transitive dependency, but something like the following should work (assuming you use Maven):

<dependencyManagement>
  <dependencies>
    <dependency>
      <groupId>net.bytebuddy</groupId>
      <artifactId>byte-buddy</artifactId>
      <version>1.14.7</version>
    </dependency>
  </dependencies>
</dependencyManagement>

<dependencies>
  <dependency>
    <groupId>org.assertj</groupId>
    <artifactId>assertj-core</artifactId>
    <version>3.24.2</version>
    <scope>test</scope>
</dependencies>

mvn dependency:tree yields:

[INFO] +- org.assertj:assertj-core:jar:3.24.2:test
[INFO] |  \- net.bytebuddy:byte-buddy:jar:1.14.7:test

@NotMyFault

NotMyFault commented Aug 30, 2023 •

Copy link
Copy Markdown

(assuming you use Maven):

Yeah, I called mvn dependency:tree for the screenshots. Unfortunately, putting a per-repository overwrite in place doesn't seem bulletproof for ~90 repositories, depending on assertj-core directly.
I think a new release would facilitate updating and testing downstream projects on Java 21.

I'm not familiar with this project's release cycle, but Java 21 released to GA on September the 19th, and I don't want to push you on anything at this time, there are still ~3 weeks left.

@scordio

scordio commented Aug 30, 2023

Copy link
Copy Markdown
Member

I checked where we updated Byte Buddy to version 1.12.21 (23afe18) and we were already testing on Java 21 (https://github.com/assertj/assertj/actions/runs/3854187439/job/10479168806), which was working because of -Dnet.bytebuddy.experimental=true.

Might also be an option in case you can centralize such a setting.

I'm not familiar with this project's release cycle

We don't have a fixed release cycle but we're already working on finalizing 3.25.0. However, we cannot really promise anything better than Soon™ 🙂

Java 21 released to GA on September the 19th, and I don't want to push you on anything at this time, there are still ~3 weeks left.

Three weeks for work done during our free time is not a lot in the end 😅 however, we might consider dropping some topics from 3.25.0 to allow for better interoperability with Java 21 (cc @assertj/core).

@NotMyFault

Copy link
Copy Markdown

Might also be an option in case you can centralize such a setting.

Unfortunately, assertj-core is not part of our parent pom 😔

Three weeks for work done during our free time is not a lot in the end 😅 however, we might consider dropping some topics from 3.25.0 to allow for better interoperability with Java 21 (cc @assertj/core).

No worries, I don't expect or rely on a release on - or until - that date 😄
I'm just testing our projects looking for issues with Java 21 to see where we're at, take all the time you need.

A friendly and responsive maintainer in OSS is already more than I can appreciate 🙏

@scordio

scordio commented Aug 30, 2023

Copy link
Copy Markdown
Member

@NotMyFault just FYI, we discussed internally that we'll shrink the scope of 3.25.0 and try to get it released as soon as we can.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependabot: Maven A dependency upgrade for Maven raised by Dependabot

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants