Repository navigation
Move the Maven wrapper to 3.10.0 - #236
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Moves the Maven wrapper to 3.10.0 and completes the toolchain checklist from #233, superseding #235. Dependabot's PR failed only because
check-wrapper.pyasserts the exact Maven version. It also re-committedmvnw.cmdwith CRLF in the index, a whole-file line-ending change with no content difference, which this PR leaves out..mvn/wrapper/maven-wrapper.properties: 3.10.0 URL and SHA-256, the same values as Bump org.apache.maven:apache-maven from 3.9.16 to 3.10.0 #235. Wrapper scripts stay at 3.3.4 andmvnw.cmdis untouched.pom.xml: the signing profile now requires exactly[3.10.0]. The ordinary[3.9.16,)minimum stays, so a contributor's local 3.9.x still builds.check-wrapper.py,check-reproducible.py, BUILDING.md, README.md and RELEASING.md now name 3.10.0..github/DEPENDENCY_DECISIONS.mdandreleases/maven-3.10.0-validation.md.Verification
KEYS../mvnw -B -ntp clean verifyon 3.10.0: 2,280 unit tests and 7 integration tests pass, along with the API/Java 8 signature, coverage and packaged JSP engine checks.check-wrapper.pypasses locally, and all 35 policy tests pass.-DperformRelease=true, differ only in unused Super POM entries (assembly and release plugin management, and a redundantinheritedflag from the removedrelease-profile).check-reproducible.pywith reference Temurin 17.0.20.1+1: two clean 3.10.0 builds produce identical copies of all 13 payloads. All nine JARs and three module POMs are byte-identical to a 3.9.16 build ofmain. The parent POM differs only in the enforcer line.For the next release
3.10.0 scopes repository credentials to their origins. Signing and Central staging weren't exercised here. The first signed
clean deployshould confirm that thecentralserver entry still authenticates.After merge
Dependabot should close #235 once
mainis on 3.10.0. If it doesn't, close it as superseded.