Skip to content

Move the Maven wrapper to 3.10.0 - #236

Merged
jmanico merged 3 commits into
mainfrom
chore/maven-3.10.0
Oct 11, 2026
Merged

jmanico merged 3 commits into
mainfrom
chore/maven-3.10.0

Conversation

@jmanico

@jmanico jmanico commented Oct 11, 2026

Copy link
Copy Markdown
Member

Moves the Maven wrapper to 3.10.0 and completes the toolchain checklist from #233, superseding #235. Dependabot's PR failed only because check-wrapper.py asserts the exact Maven version. It also re-committed mvnw.cmd with CRLF in the index, a whole-file line-ending change with no content difference, which this PR leaves out.

  • .mvn/wrapper/maven-wrapper.properties: 3.10.0 URL and SHA-256, the same values as Bump org.apache.maven:apache-maven from 3.9.16 to 3.10.0 #235. Wrapper scripts stay at 3.3.4 and mvnw.cmd is untouched.
  • pom.xml: the signing profile now requires exactly [3.10.0]. The ordinary [3.9.16,) minimum stays, so a contributor's local 3.9.x still builds.
  • check-wrapper.py, check-reproducible.py, BUILDING.md, README.md and RELEASING.md now name 3.10.0.
  • The decision and evidence are recorded in .github/DEPENDENCY_DECISIONS.md and releases/maven-3.10.0-validation.md.

Verification

  • The ZIP is byte-identical on downloads.apache.org and Central. It matches Apache's SHA-512 and the wrapper SHA-256, and its signature is good from a key in Apache Maven's KEYS.
  • ./mvnw -B -ntp clean verify on 3.10.0: 2,280 unit tests and 7 integration tests pass, along with the API/Java 8 signature, coverage and packaged JSP engine checks. check-wrapper.py passes locally, and all 35 policy tests pass.
  • Effective POMs from 3.9.16 and 3.10.0, both default and with -DperformRelease=true, differ only in unused Super POM entries (assembly and release plugin management, and a redundant inherited flag from the removed release-profile).
  • check-reproducible.py with reference Temurin 17.0.20.1+1: two clean 3.10.0 builds produce identical copies of all 13 payloads. All nine JARs and three module POMs are byte-identical to a 3.9.16 build of main. The parent POM differs only in the enforcer line.

For the next release

3.10.0 scopes repository credentials to their origins. Signing and Central staging weren't exercised here. The first signed clean deploy should confirm that the central server entry still authenticates.

After merge

Dependabot should close #235 once main is on 3.10.0. If it doesn't, close it as superseded.

@jmanico
jmanico requested a review from jeremylong as a code owner October 11, 2026 12:58
@jmanico
jmanico merged commit f200fae into main Oct 11, 2026
18 checks passed
@jmanico
jmanico deleted the chore/maven-3.10.0 branch October 11, 2026 13:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant