Catch stale entries in the Java SDK dependency trust list - #71869
jason810496 merged 1 commit into
Conversation
b090bcc to
e80062f
Compare
|
I feel we don’t need Otherwise I think this is on the right track. |
e80062f to
5b7d205
Compare
|
@uranusjr Thanks for the suggestion. I changed to use prek hook. |
5b7d205 to
14ed122
Compare
jason810496
left a comment
There was a problem hiding this comment.
Thanks for the follow-up.
f08432a to
e0099f2
Compare
Signed-off-by: PoAn Yang <payang@apache.org>
e0099f2 to
901aa4e
Compare
Backport failed to create: v3-3-test. View the failure log Run detailsNote: As of Merging PRs targeted for Airflow 3.X In matter of doubt please ask in #release-management Slack channel.
You can attempt to backport this manually by running: cherry_picker 3e47fc3 v3-3-testThis should apply the commit to the v3-3-test branch and leave the commit in conflict state marking After you have resolved the conflicts, you can continue the backport process by running: cherry_picker --continueIf you don't have cherry-picker installed, see the installation guide. |
The regenerate-java-sdk-verification-metadata hook added in #71869 drops checksums that no Java SDK build task resolves any more, but the trust list on main still carried entries for versions superseded by earlier dependency bumps. The hook therefore rewrites the file in every run, and static checks fail on every PR regardless of what it touches. Generated-by: Claude Opus 5
Why
java-sdk/gradle/verification-metadata.xmlis a trust list. Gradle's strict mode fails on a checksum mismatch and on an artifact with no entry, but not on an entry nothing resolves any more.How
scripts/ci/prek/regenerate_java_sdk_verification_metadata.py. It clears the component list first, so superseded entries disappear instead of accumulating. Regenerate metadata based on-PgitRef=HEAD. It also puts back the ASF header Gradle strips. It retries three times because Maven Central and the Gradle Plugin Portal fail often enough to matter.regenerate-java-sdk-verification-metadataprek hook.Verification
prek run regenerate-java-sdk-verification-metadata --all-filesWas generative AI tooling used to co-author this PR?
{pr_number}.significant.rst, in airflow-core/newsfragments. You can add this file in a follow-up commit after the PR is created so you know the PR number.