Skip to content

Consolidate API dependency updates and Dependabot scans - #217

Merged
jmanico merged 1 commit into
mainfrom
fix/dependabot-reactor-dedup
Sep 28, 2026
Merged

jmanico merged 1 commit into
mainfrom
fix/dependabot-reactor-dedup

Conversation

@jmanico

@jmanico jmanico commented Sep 28, 2026

Copy link
Copy Markdown
Member

Summary

  • Update the published encoder-jsp provided API from JSP 2.2.1 to 2.3.3.
  • Update the Jakarta test classpath from Servlet 6.0.0 to 6.1.0 and EL 4.0.0 to 6.0.1.
  • Keep the older support APIs as explicit inputs for the 1.4.1 side of japicmp, while the 1.5 side resolves the new APIs.
  • Preserve the independent JSP 2.2.1 and Java 8-compatible Jakarta Servlet 5 / EL 4 packaged-consumer fixtures.
  • Scan the Maven reactor once from / in Dependabot while retaining the standalone /compatibility/dependencies scan, preventing duplicate module PRs.
  • Add policy regressions and document the consumer-POM and compatibility effects.

This consolidates and repairs the three unique updates proposed twice in #211–#216. Those PRs can be closed as superseded after this PR merges.

Compatibility

encoder-jsp still targets Java 8 bytecode and uses only the older JSP surface proven by the JSP 2.2.1 fixture; its published provided dependency now defaults to JSP 2.3.3. The Jakarta Servlet and EL updates are test-scope declarations: they remain visible in the published source POM but do not propagate into ordinary consumer dependency graphs or enter the adapter JAR.

Validation

  • JDK 17 clean reactor: 2,287 tests, zero failures/errors/skips; Checkstyle, Enforcer convergence/upper bounds, Animal Sniffer, coverage, japicmp, JPMS, OSGi, and packaged JSP engines passed.
  • JDK 21 and 25 clean reactors passed.
  • 28 release/CI policy tests passed.
  • 17 packaged-artifact guard tests passed.
  • Minimum JSP 2.2.1 and Jakarta Servlet 5 / EL 4 fixtures compiled with --release 8.
  • Packaged classpath, explicit/automatic JPMS, and Felix R6/R8 consumers passed on locally available JDKs 11, 17, 21, and 25.
  • Effective POMs and the generated dependency-submission build snapshot were inspected.
  • git diff --check passed.

Required PR checks provide the remaining Java 8 execution and Windows wrapper evidence before merge.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant