Skip to content

Commit a90624c

Browse files
feat: bump vulnerable dependencies
bump coverage
1 parent c37121e commit a90624c

File tree

12 files changed

+186
-172
lines changed

12 files changed

+186
-172
lines changed

build.gradle

Lines changed: 23 additions & 22 deletions
Original file line numberDiff line numberDiff line change
@@ -1,14 +1,14 @@
11
plugins {
2-
id "com.github.mxenabled.coppuccino" version "3.2.1"
2+
id "com.github.mxenabled.coppuccino" version "4.4.2"
33
id "groovy"
44
id "java"
55
id "maven-publish"
66
id "java-gradle-plugin"
7-
id "org.jetbrains.kotlin.jvm" version "1.6.10"
7+
id "org.jetbrains.kotlin.jvm" version "2.1.0"
88
}
99

1010
group "com.mx.vogue"
11-
version "1.0.3" // x-release-please-version
11+
version "2.0.0-SNAPSHOT" // x-release-please-version
1212
sourceCompatibility = 1.8
1313

1414
repositories {
@@ -19,22 +19,17 @@ repositories {
1919
}
2020

2121
dependencies {
22-
implementation "org.apache.bcel:bcel:[6.6.0,7.0[" // Security update
23-
implementation "org.jetbrains.kotlin:kotlin-stdlib-jdk8"
22+
implementation "org.apache.bcel:bcel:[6.11.0,7.0[" // Security update
23+
implementation "org.jetbrains.kotlin:kotlin-stdlib-jdk8:2.1.0"
2424
implementation "com.google.code.gson:gson:[2.0,3.0["
25-
implementation "com.fasterxml.jackson.dataformat:jackson-dataformat-yaml:2.13.3"
26-
implementation "com.github.ben-manes.versions:com.github.ben-manes.versions.gradle.plugin:0.42.0"
27-
implementation "com.github.spotbugs:spotbugs-annotations:4.7.2" // For annotating classes and methods to suppress SpotBugs violations
25+
//FIXME this is pulling in snakeyaml 2.0, which is breaking higher libraries because we are not ready for it
26+
//upgrade to 2.15.0 after snakeyaml2
27+
implementation "com.fasterxml.jackson.dataformat:jackson-dataformat-yaml:2.14.3"
28+
implementation "com.github.ben-manes.versions:com.github.ben-manes.versions.gradle.plugin:0.53.0"
29+
implementation "com.github.spotbugs:spotbugs-annotations:4.9.8" // For annotating classes and methods to suppress SpotBugs violations
2830

29-
constraints {
30-
implementation ("com.thoughtworks.xstream:xstream:1.4.19") { because "It resolves a bajillion CVEs" }
31-
}
32-
33-
// Unit tests
34-
testRuntimeOnly "org.junit.jupiter:junit-jupiter-engine:[5.8.0,5.9.0["
35-
testImplementation "org.junit.jupiter:junit-jupiter-api:[5.8.0,5.9.0["
36-
testImplementation "org.mockito:mockito-inline:[4.0,5.0["
37-
testImplementation "org.spockframework:spock-core:2.2-M1-groovy-3.0"
31+
api "org.mockito:mockito-inline:[4.0,5.0["
32+
api "org.spockframework:spock-core:2.4-M6-groovy-3.0"
3833
}
3934

4035
gradlePlugin {
@@ -53,30 +48,36 @@ gradlePlugin {
5348
compileKotlin {
5449
kotlinOptions {
5550
jvmTarget = "1.8"
56-
} }
51+
}
52+
}
5753

5854
compileTestKotlin {
5955
kotlinOptions {
6056
jvmTarget = "1.8"
61-
} }
57+
}
58+
}
6259

6360
coppuccino {
6461
kotlin { enabled = true }
6562
coverage {
66-
minimumCoverage = 0.70
63+
minimumCoverage = 0.73
6764
excludes = [
6865
"com/mx/vogue/core/models/**"
6966
]
7067
}
7168
}
7269

7370
sourceSets {
74-
test { groovy { srcDirs "src/test/groovy" } }
71+
test {
72+
groovy {
73+
srcDirs "src/test/groovy"
74+
}
75+
}
7576
}
7677

7778
test { useJUnitPlatform() }
7879

7980
wrapper {
80-
gradleVersion = "7.4.1"
81+
gradleVersion = "7.6.3"
8182
distributionType = Wrapper.DistributionType.ALL
8283
}

gradle.lockfile

Lines changed: 126 additions & 129 deletions
Large diffs are not rendered by default.

gradle/wrapper/gradle-wrapper.jar

2.04 KB
Binary file not shown.
Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,6 @@
11
distributionBase=GRADLE_USER_HOME
22
distributionPath=wrapper/dists
3-
distributionUrl=https\://services.gradle.org/distributions/gradle-7.4.1-bin.zip
3+
distributionUrl=https\://services.gradle.org/distributions/gradle-7.6.3-all.zip
4+
networkTimeout=10000
45
zipStoreBase=GRADLE_USER_HOME
56
zipStorePath=wrapper/dists

gradlew

Lines changed: 14 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -55,7 +55,7 @@
5555
# Darwin, MinGW, and NonStop.
5656
#
5757
# (3) This script is generated from the Groovy template
58-
# https://github.com/gradle/gradle/blob/master/subprojects/plugins/src/main/resources/org/gradle/api/internal/plugins/unixStartScript.txt
58+
# https://github.com/gradle/gradle/blob/HEAD/subprojects/plugins/src/main/resources/org/gradle/api/internal/plugins/unixStartScript.txt
5959
# within the Gradle project.
6060
#
6161
# You can find Gradle at https://github.com/gradle/gradle/.
@@ -80,10 +80,10 @@ do
8080
esac
8181
done
8282

83-
APP_HOME=$( cd "${APP_HOME:-./}" && pwd -P ) || exit
84-
85-
APP_NAME="Gradle"
83+
# This is normally unused
84+
# shellcheck disable=SC2034
8685
APP_BASE_NAME=${0##*/}
86+
APP_HOME=$( cd "${APP_HOME:-./}" && pwd -P ) || exit
8787

8888
# Add default JVM options here. You can also use JAVA_OPTS and GRADLE_OPTS to pass JVM options to this script.
8989
DEFAULT_JVM_OPTS='"-Xmx64m" "-Xms64m"'
@@ -143,12 +143,16 @@ fi
143143
if ! "$cygwin" && ! "$darwin" && ! "$nonstop" ; then
144144
case $MAX_FD in #(
145145
max*)
146+
# In POSIX sh, ulimit -H is undefined. That's why the result is checked to see if it worked.
147+
# shellcheck disable=SC3045
146148
MAX_FD=$( ulimit -H -n ) ||
147149
warn "Could not query maximum file descriptor limit"
148150
esac
149151
case $MAX_FD in #(
150152
'' | soft) :;; #(
151153
*)
154+
# In POSIX sh, ulimit -n is undefined. That's why the result is checked to see if it worked.
155+
# shellcheck disable=SC3045
152156
ulimit -n "$MAX_FD" ||
153157
warn "Could not set maximum file descriptor limit to $MAX_FD"
154158
esac
@@ -205,6 +209,12 @@ set -- \
205209
org.gradle.wrapper.GradleWrapperMain \
206210
"$@"
207211

212+
# Stop when "xargs" is not available.
213+
if ! command -v xargs >/dev/null 2>&1
214+
then
215+
die "xargs is not available"
216+
fi
217+
208218
# Use "xargs" to parse quoted args.
209219
#
210220
# With -n1 it outputs one arg per line, with the quotes and backslashes removed.

gradlew.bat

Lines changed: 9 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -14,7 +14,7 @@
1414
@rem limitations under the License.
1515
@rem
1616

17-
@if "%DEBUG%" == "" @echo off
17+
@if "%DEBUG%"=="" @echo off
1818
@rem ##########################################################################
1919
@rem
2020
@rem Gradle startup script for Windows
@@ -25,7 +25,8 @@
2525
if "%OS%"=="Windows_NT" setlocal
2626

2727
set DIRNAME=%~dp0
28-
if "%DIRNAME%" == "" set DIRNAME=.
28+
if "%DIRNAME%"=="" set DIRNAME=.
29+
@rem This is normally unused
2930
set APP_BASE_NAME=%~n0
3031
set APP_HOME=%DIRNAME%
3132

@@ -40,7 +41,7 @@ if defined JAVA_HOME goto findJavaFromJavaHome
4041

4142
set JAVA_EXE=java.exe
4243
%JAVA_EXE% -version >NUL 2>&1
43-
if "%ERRORLEVEL%" == "0" goto execute
44+
if %ERRORLEVEL% equ 0 goto execute
4445

4546
echo.
4647
echo ERROR: JAVA_HOME is not set and no 'java' command could be found in your PATH.
@@ -75,13 +76,15 @@ set CLASSPATH=%APP_HOME%\gradle\wrapper\gradle-wrapper.jar
7576

7677
:end
7778
@rem End local scope for the variables with windows NT shell
78-
if "%ERRORLEVEL%"=="0" goto mainEnd
79+
if %ERRORLEVEL% equ 0 goto mainEnd
7980

8081
:fail
8182
rem Set variable GRADLE_EXIT_CONSOLE if you need the _script_ return code instead of
8283
rem the _cmd.exe /c_ return code!
83-
if not "" == "%GRADLE_EXIT_CONSOLE%" exit 1
84-
exit /b 1
84+
set EXIT_CODE=%ERRORLEVEL%
85+
if %EXIT_CODE% equ 0 set EXIT_CODE=1
86+
if not ""=="%GRADLE_EXIT_CONSOLE%" exit %EXIT_CODE%
87+
exit /b %EXIT_CODE%
8588

8689
:mainEnd
8790
if "%OS%"=="Windows_NT" endlocal

settings.gradle

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -7,4 +7,4 @@ pluginManagement {
77
}
88
}
99

10-
rootProject.name = "vogue"
10+
rootProject.name = "vogue"

src/main/kotlin/com/mx/vogue/VoguePlugin.kt

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -38,7 +38,7 @@ import org.gradle.api.Project
3838
import org.gradle.api.logging.LogLevel
3939

4040
class VoguePlugin : Plugin<Project> {
41-
@Suppress("MaxLineLength")
41+
@Suppress("ktlint:standard:max-line-length")
4242
override fun apply(project: Project) {
4343
var dependenciesExtension = project.extensions.create("vogue", VogueDependenciesExtension::class.java)
4444

src/main/kotlin/com/mx/vogue/core/ReportRenderer.kt

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -79,12 +79,12 @@ private fun buildUpgradeMessages(dependencyContexts: List<DependencyContext>, bu
7979
}
8080
}
8181

82-
@Suppress("MaxLineLength")
82+
@Suppress("ktlint:standard:max-line-length")
8383
private fun buildWarningUpgradeMessage(dependencyContext: DependencyContext): String {
8484
return " - ${yellow(getPackage(dependencyContext.versionsPluginDependency))} [${green(dependencyContext.current.toString())} -> ${green(dependencyContext.latest.toString())}]\n"
8585
}
8686

87-
@Suppress("MaxLineLength")
87+
@Suppress("ktlint:standard:max-line-length")
8888
private fun buildErrorUpgradeMessage(dependencyContext: DependencyContext): String {
8989
return " - ${red(getPackage(dependencyContext.versionsPluginDependency))} [${green(dependencyContext.current.toString())} -> ${green(dependencyContext.latest.toString())}]\n"
9090
}

src/main/kotlin/com/mx/vogue/core/ReportUtils.kt

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -14,6 +14,7 @@
1414
* limitations under the License.
1515
*/
1616
@file:Suppress("TooManyFunctions")
17+
1718
package com.mx.vogue.core
1819

1920
import com.mx.vogue.core.exceptions.VogueProcessingException
@@ -51,7 +52,6 @@ fun getPackage(versionsPluginDependency: VersionsPluginDependency): String {
5152
return "${versionsPluginDependency.group}:${versionsPluginDependency.name}"
5253
}
5354

54-
@SuppressFBWarnings("BC_BAD_CAST_TO_ABSTRACT_COLLECTION")
5555
fun getPackageRule(versionsPluginDependency: VersionsPluginDependency, packageRules: List<PackageRule>): PackageRule? {
5656
return packageRules.firstOrNull {
5757
Regex(it.`package`).containsMatchIn(getPackage(versionsPluginDependency))
@@ -76,7 +76,7 @@ fun filterStaleSuppressions(packageRules: List<PackageRule>?): List<PackageRule>
7676
}.toList()
7777
}
7878

79-
@Suppress("MaxLineLength")
79+
@Suppress("ktlint:standard:max-line-length")
8080
fun reportStaleSuppressions(packageRules: List<PackageRule>?) {
8181
if (packageRules == null) {
8282
return
@@ -101,7 +101,7 @@ fun reportStaleSuppressions(packageRules: List<PackageRule>?) {
101101
}
102102
}
103103

104-
@Suppress("MaxLineLength", "ThrowsCount", "ReturnCount")
104+
@Suppress("ktlint:standard:max-line-length", "ThrowsCount", "ReturnCount")
105105
fun shouldSuppressPackageRule(packageRule: PackageRule?): Boolean {
106106
if (packageRule == null) {
107107
return false

0 commit comments

Comments
 (0)