Skip to content

Complete 1.5.0 post-release cleanup - #230

Merged
jmanico merged 2 commits into
mainfrom
chore/post-release-1.5.0
Sep 28, 2026
Merged

jmanico merged 2 commits into
mainfrom
chore/post-release-1.5.0

Conversation

@jmanico

@jmanico jmanico commented Sep 28, 2026 •

Copy link
Copy Markdown
Member

Summary

  • Record verified 1.5.0 publication and replace stale pending-release notices in the README, security policy, release notes and usage/context guides.
  • Resume development at 1.5.1-SNAPSHOT with SCM HEAD; keep consumer examples on published 1.5.0.
  • Advance japicmp to the immutable 1.5.0 artifacts and their matching support APIs. The minimum-consumer fixtures and production dependency graph are unchanged.
  • Discover release tags independently of commit ancestry, with isolated Git regressions for squash merges, future releases, non-release tags and missing tags.
  • Fix newly surfaced Jackson alerts #587/#588/#589 in the unpublished fixture's Spring Boot Maven plugin: pin its separate core/databind dependencies to 3.1.6. The actual plugin graph now resolves both fixed versions; the application graph has no Jackson databind dependency. Alert #589 (GHSA-gx83-3vf8-gh7j) appeared after the follow-up was pushed and has the same fixed version, so no additional code change is needed.
  • Link the verified live 1.5.0 Javadoc pages for core, JSP and Jakarta.

The signed v1.5.0 tag, published artifacts and release signatures are unchanged. No production Java code changes. Website maintenance is separate from this PR.

Validation

  • Eclipse Temurin 17.0.20.1+1 and committed Maven 3.9.16 wrapper; private HOME, Java user.home/tmp, empty user/global settings and a private copy of the reviewed Maven cache. Resolve the newly published baseline first, then disable external networking for verification.
  • Complete offline clean verify: 2,287 tests, zero failures, errors or skips; Checkstyle, coverage, Animal Sniffer, dependency convergence/upper bounds, packaged JSP engines and all three japicmp comparisons passed.
  • Policy scripts: 34 tests passed, including the new release-tag and plugin-realm regressions.
  • Packaged-artifact guards: 17 tests passed.
  • Effective SCM metadata: parent and all three modules passed.
  • Original-JAR classpath, explicit/automatic JPMS and Felix R6/R8 consumers passed on Java 11, 17, 21 and 25.
  • Snapshot version policy and git diff --check passed.
  • Fixture compilation/convergence and before/after plugin resolution passed. Browser tests cannot run locally without Docker; the existing required CI exercises them and Boot repackaging.

The initial local policy run hit a test-only GPG socket denial; allowing sockets only in the private temporary directory resolved it. An artifact-guard run started before packaging finished and was repeated successfully after the clean reactor completed. No tests or assertions were disabled.

All 18 CI checks passed on final head c0fc1098ba1fae37640ccd5906e7bc882d64b51f, including Java 8, Windows and Docker/browser coverage unavailable in the local environment. The final clean reactor also passed Spring Boot repackaging and the packaged-WAR integration test. Results: Java CI, packaged consumers, CodeQL.

Ordinary review is still required before merging. No alerts were dismissed; after merge the normal dependency-submission workflow must report the corrected plugin graph.

@jmanico
jmanico requested a review from jeremylong as a code owner September 28, 2026 21:04
@jmanico
jmanico merged commit 454a07c into main Sep 28, 2026
18 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant