Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

ci(GitHub): bump gradle/actions from 3 to 4 #70

Closed
wants to merge 1 commit into from

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Sep 1, 2024

Bumps gradle/actions from 3 to 4.

Release notes

Sourced from gradle/actions's releases.

v4.0.0

Final release of v4.0.0 of the setup-gradle, dependency-submission and wrapper-validation actions provided under gradle/actions. This release is available under the v4 tag.

Major changes from the v3 release

The arguments parameter has been removed

Using the action to execute Gradle via the arguments parameter was deprecated in v3 and this parameter has been removed. See here for more details.

Cache cleanup enabled by default

After a number of fixes and improvements, this release enables cache-cleanup by default for all Jobs using the setup-gradle and dependency-submission actions.

Improvements and bugfixes related cache cleanup:

  • By default, cache cleanup is not run if any Gradle build fails (#71)
  • Cache cleanup is not run after configuration-cache reuse (#19)

This feature should help to minimize the size of entries written to the GitHub Actions cache, speeding up builds and reducing cache usage.

Wrapper validation enabled by default

In v3, the setup-gradle action was enhanced to support Gradle wrapper validation, removing the need to use a separate workflow file with the gradle/actions/wrapper-validation action.

With this release, wrapper validation has been significantly improved, and is now enabled by default (#12):

  • The allow-snapshot-wrappers makes it possible to validate snapshot wrapper jars using setup-gradle.
  • Checksums for nightly and snapshot Gradle versions are now validated (#281).
  • Valid wrapper checksums are cached in Gradle User Home, reducing the need to retrieve checksum values remotely (#172).
  • Reduce network calls in wrapper-validation for new Gradle versions: By only fetching wrapper checksums for Gradle versions that were not known when this action was released, this release reduces the likelihood that a network failure could cause failure in wrapper validation (#171)
  • Improved error message when wrapper-validation finds no wrapper jars (#284)

Wrapper validation is important for supply-chain integrity. Enabling this feature by default will increase the coverage of wrapper validation on projects using GitHub Actions.

New input parameters for Dependency Graph generation

Some dependency-graph inputs that could previously only be configured via environment variables now have dedicated action inputs:

Other improvements

  • In Job summary, the action now provides an explanation when cache is set to read-only or disabled (#255)
  • When setup-gradle requests a specific Gradle version, the action will no longer download and install that version if it is already available on the PATH of the runner (#270)
  • To attempt to speed up builds, the setup-gradle and dependency-submission actions now attempt to use the D: drive for Gradle User Home if it is available (#290)

Deprecations and breaking changes

... (truncated)

Commits
  • 16bf8bc Rework docs for Develocity support
  • faf4eea [bot] Update dist directory
  • 4b7cc6e Differentiate Gradle 8.1 from 8.10 when checking version (#358)
  • 0873530 Increase Gradle version coverage for init-scripts
  • f67327f [bot] Update dist directory
  • d32a10b Dependency updates (#356)
  • e598a32 Quote version 8.10 in integ test
  • d6c8cf8 Bump unzip-stream from 0.3.1 to 0.3.4 in /sources
  • 79ea5b8 Bump org.junit.jupiter:junit-jupiter
  • d77a030 Bump com.google.guava:guava in /.github/workflow-samples/kotlin-dsl
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Summary by CodeRabbit

  • New Features

    • Upgraded the Gradle setup action in the build, PR baseline, and release workflows to enhance performance and compatibility.
    • Updated the Android Gradle Plugin version in the lint baseline to provide better dependency management and awareness of newer versions.
  • Bug Fixes

    • Improved build process reliability by utilizing the latest version of the Gradle setup action.

@dependabot dependabot bot requested a review from amal as a code owner September 1, 2024 04:54
@dependabot dependabot bot added dependencies Dependencies update request gh-action GitHub actions-releated labels Sep 1, 2024
Copy link

coderabbitai bot commented Sep 1, 2024

Walkthrough

Walkthrough

The changes involve updating the Gradle setup action version in multiple GitHub Actions workflow files from version 3 to version 4. This update is consistent across the build.yml, pr-baseline.yml, and release.yml files, ensuring that the workflows utilize the latest features and improvements of the Gradle action while maintaining existing configurations. Additionally, the lint-baseline.xml file has been updated to reflect a newer version of the Android Gradle Plugin.

Changes

Files Change Summary
.github/workflows/build.yml Updated Gradle setup action from v3 to v4.
.github/workflows/pr-baseline.yml Updated Gradle setup action from v3 to v4.
.github/workflows/release.yml Updated Gradle setup action from v3 to v4.
fluxo-kmp-conf/lint-baseline.xml Updated Android Gradle Plugin version from 8.6.0-alpha05 to 8.6.0-alpha08 and added new version availability issues.

Poem

🐰 In the meadow, a change did bloom,
With Gradle's new version, there's more room!
Hopping along, we build with glee,
Faster and better, just wait and see!
A leap for the code, a dance in the air,
With each little update, we show that we care! 🌼✨


Thank you for using CodeRabbit. We offer it for free to the OSS community and would appreciate your support in helping us grow. If you find it useful, would you consider giving us a shout-out on your favorite social media?

Share
Tips

Chat

There are 3 ways to chat with CodeRabbit:

  • Review comments: Directly reply to a review comment made by CodeRabbit. Example:
    • I pushed a fix in commit <commit_id>.
    • Generate unit testing code for this file.
    • Open a follow-up GitHub issue for this discussion.
  • Files and specific lines of code (under the "Files changed" tab): Tag @coderabbitai in a new review comment at the desired location with your query. Examples:
    • @coderabbitai generate unit testing code for this file.
    • @coderabbitai modularize this function.
  • PR comments: Tag @coderabbitai in a new PR comment to ask questions about the PR branch. For the best results, please provide a very specific query, as very limited context is provided in this mode. Examples:
    • @coderabbitai generate interesting stats about this repository and render them as a table.
    • @coderabbitai show all the console.log statements in this repository.
    • @coderabbitai read src/utils.ts and generate unit testing code.
    • @coderabbitai read the files in the src/scheduler package and generate a class diagram using mermaid and a README in the markdown format.
    • @coderabbitai help me debug CodeRabbit configuration file.

Note: Be mindful of the bot's finite context window. It's strongly recommended to break down tasks such as reading entire modules into smaller chunks. For a focused discussion, use review comments to chat about specific files and their changes, instead of using the PR comments.

CodeRabbit Commands (Invoked using PR comments)

  • @coderabbitai pause to pause the reviews on a PR.
  • @coderabbitai resume to resume the paused reviews.
  • @coderabbitai review to trigger an incremental review. This is useful when automatic reviews are disabled for the repository.
  • @coderabbitai full review to do a full review from scratch and review all the files again.
  • @coderabbitai summary to regenerate the summary of the PR.
  • @coderabbitai resolve resolve all the CodeRabbit review comments.
  • @coderabbitai configuration to show the current CodeRabbit configuration for the repository.
  • @coderabbitai help to get help.

Other keywords and placeholders

  • Add @coderabbitai ignore anywhere in the PR description to prevent this PR from being reviewed.
  • Add @coderabbitai summary to generate the high-level summary at a specific location in the PR description.
  • Add @coderabbitai or @coderabbitai title anywhere in the PR title to generate the title automatically.

CodeRabbit Configuration File (.coderabbit.yaml)

  • You can programmatically configure CodeRabbit by adding a .coderabbit.yaml file to the root of your repository.
  • Please see the configuration documentation for more information.
  • If your editor has YAML language server enabled, you can add the path at the top of this file to enable auto-completion and validation: # yaml-language-server: $schema=https://coderabbit.ai/integrations/schema.v2.json

Documentation and Community

  • Visit our Documentation for detailed information on how to use CodeRabbit.
  • Join our Discord Community to get help, request features, and share feedback.
  • Follow us on X/Twitter for updates and announcements.

Copy link

github-actions bot commented Sep 1, 2024

🔄 Baseline update started...

Copy link

@coderabbitai coderabbitai bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 0

Review details

Configuration used: CodeRabbit UI
Review profile: ASSERTIVE

Commits

Files that changed from the base of the PR and between c9efba1 and 4111499.

Files selected for processing (3)
  • .github/workflows/build.yml (1 hunks)
  • .github/workflows/pr-baseline.yml (1 hunks)
  • .github/workflows/release.yml (1 hunks)
Additional comments not posted (3)
.github/workflows/release.yml (1)

84-84: LGTM! But verify the impact of the Gradle setup action version update.

The code change is approved. However, ensure that the update to version 4 of the Gradle setup action does not introduce any breaking changes or compatibility issues in the workflow.

Run the following script to verify the impact of the version update:

Verification successful

No other instances of the Gradle setup action found.

The update to version 4 of the Gradle setup action appears to be isolated to the .github/workflows/release.yml file. No other workflow files in the repository use this action. Ensure that this update does not introduce any breaking changes or compatibility issues in the workflow.

Scripts executed

The following scripts were executed for the analysis:

Script:

#!/bin/bash
# Description: Verify the impact of the Gradle setup action version update.

# Test: Search for the usage of the Gradle setup action in other workflow files.
#       Expect: The version update is consistently applied across all workflow files.
rg --type yaml $'gradle/actions/setup-gradle@v\d'

Length of output: 50


Script:

#!/bin/bash
# Refined search for the usage of the Gradle setup action in all YAML files.
# This will help verify if the version update is consistently applied across all workflow files.
rg --type yaml 'gradle/actions/setup-gradle@v\d+' -A 2

Length of output: 56

.github/workflows/pr-baseline.yml (1)

66-66: LGTM!

The code change is approved, as it is consistent with the Gradle setup action version update in the release.yml file.

.github/workflows/build.yml (1)

106-106: LGTM!

The code change is approved, as it is consistent with the Gradle setup action version updates in the other workflow files.

Bumps [gradle/actions](https://github.com/gradle/actions) from 3 to 4.
- [Release notes](https://github.com/gradle/actions/releases)
- [Commits](gradle/actions@v3...v4)

---
updated-dependencies:
- dependency-name: gradle/actions
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <[email protected]>
Copy link

github-actions bot commented Sep 1, 2024

✅ Baseline updated.

@github-actions github-actions bot force-pushed the dependabot/github_actions/gradle/actions-4 branch from 4111499 to 2ed23cb Compare September 1, 2024 05:01
Copy link

@coderabbitai coderabbitai bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

Review details

Configuration used: CodeRabbit UI
Review profile: ASSERTIVE

Commits

Files that changed from the base of the PR and between 4111499 and 2ed23cb.

Files selected for processing (4)
  • .github/workflows/build.yml (1 hunks)
  • .github/workflows/pr-baseline.yml (1 hunks)
  • .github/workflows/release.yml (1 hunks)
  • fluxo-kmp-conf/lint-baseline.xml (2 hunks)
Additional comments not posted (6)
fluxo-kmp-conf/lint-baseline.xml (3)

2-2: LGTM!

The changes update the Android Gradle Plugin (AGP) version from 8.6.0-alpha05 to 8.6.0-alpha08, indicating an upgrade to a newer alpha version. This upgrade may include bug fixes or new features.


22-29: Duplicate lint warning.

This <issue> entry appears to be a duplicate of the previous lint warning about the availability of a newer stable version (8.6.0) of the Android library compared to the alpha version (8.6.0-alpha08) currently in use.


40-47: Duplicate lint warning.

This <issue> entry appears to be a duplicate of the previous lint warning about the availability of a newer stable version (8.6.0) of the Android Gradle Plugin compared to the alpha version (8.6.0-alpha08) currently in use.

.github/workflows/release.yml (1)

84-84: LGTM!

The change upgrades the Gradle setup action from version 3 to version 4, potentially bringing enhancements, new features, or bug fixes. The caching strategy remains intact with the cache-disabled and cache-read-only parameters unchanged.

.github/workflows/pr-baseline.yml (1)

66-66: LGTM!

The change upgrades the Gradle setup action from version 3 to version 4, potentially bringing enhancements, new features, or bug fixes. The caching strategy remains intact with the cache-disabled and cache-read-only parameters unchanged.

.github/workflows/build.yml (1)

106-106: LGTM!

The update to version v4 of the Gradle setup action is a positive change that incorporates improvements, bug fixes, and new features to enhance the build process. The existing parameters remain unchanged, preserving the overall logic and control flow of the workflow while leveraging the benefits of the updated action. This update aims to optimize the workflow's performance and ensure better compatibility with newer Gradle versions.

Comment on lines +13 to +20
<issue
id="AndroidGradlePluginVersion"
message="A newer version of com.android.library than 8.6.0-alpha08 is available: 8.6.0">
<location
file="$HOME/work/fluxo-kmp-conf/fluxo-kmp-conf/gradle/libs.versions.toml"
line="102"
column="25"/>
</issue>
Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Lint warning about a newer Android library version.

The new <issue> entry with the ID AndroidGradlePluginVersion provides a lint warning indicating that a newer stable version (8.6.0) of the Android library is available compared to the alpha version (8.6.0-alpha08) currently in use.

Consider updating to the stable version of the Android library if feasible and compatible with the project requirements. This can be done by modifying the relevant version in the libs.versions.toml file.

Comment on lines +31 to +38
<issue
id="AndroidGradlePluginVersion"
message="A newer version of com.android.tools.build:gradle than 8.6.0-alpha08 is available: 8.6.0">
<location
file="$HOME/work/fluxo-kmp-conf/fluxo-kmp-conf/gradle/libs.versions.toml"
line="102"
column="25"/>
</issue>
Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Lint warning about a newer Android Gradle Plugin version.

The new <issue> entry with the ID AndroidGradlePluginVersion provides a lint warning indicating that a newer stable version (8.6.0) of the Android Gradle Plugin is available compared to the alpha version (8.6.0-alpha08) currently in use.

Consider updating to the stable version of the Android Gradle Plugin if feasible and compatible with the project requirements. This can be done by modifying the relevant version in the libs.versions.toml file.

@amal amal closed this Oct 10, 2024
Copy link
Contributor Author

dependabot bot commented on behalf of github Oct 10, 2024

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot dependabot bot deleted the dependabot/github_actions/gradle/actions-4 branch October 10, 2024 14:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Dependencies update request gh-action GitHub actions-releated
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant