Skip to content

Catch stale entries in the Java SDK dependency trust list - #71869

Merged
jason810496 merged 1 commit into
apache:mainfrom
FrankYang0529:java-sdk-verification-metadata-ci-check
Sep 27, 2026
Merged

jason810496 merged 1 commit into
apache:mainfrom
FrankYang0529:java-sdk-verification-metadata-ci-check

Conversation

@FrankYang0529

@FrankYang0529 FrankYang0529 commented Aug 20, 2026 •

Copy link
Copy Markdown
Member

Why

  • java-sdk/gradle/verification-metadata.xml is a trust list. Gradle's strict mode fails on a checksum mismatch and on an artifact with no entry, but not on an entry nothing resolves any more.
  • Regeneration only appends, so every version bump leaves the superseded checksums behind.

How

  • Add scripts/ci/prek/regenerate_java_sdk_verification_metadata.py. It clears the component list first, so superseded entries disappear instead of accumulating. Regenerate metadata based on -PgitRef=HEAD. It also puts back the ASF header Gradle strips. It retries three times because Maven Central and the Gradle Plugin Portal fail often enough to matter.
  • Add a regenerate-java-sdk-verification-metadata prek hook.

Verification

  • prek run regenerate-java-sdk-verification-metadata --all-files

Was generative AI tooling used to co-author this PR?
  • Yes - Claude Code

  • Read the Pull Request Guidelines for more information. Note: commit author/co-author name and email in commits become permanently public when merged.
  • For fundamental code changes, an Airflow Improvement Proposal (AIP) is needed.
  • When adding dependency, check compliance with the ASF 3rd Party License Policy.
  • For significant user-facing changes create newsfragment: {pr_number}.significant.rst, in airflow-core/newsfragments. You can add this file in a follow-up commit after the PR is created so you know the PR number.

@uranusjr

uranusjr commented Aug 23, 2026 •

Copy link
Copy Markdown
Member

I feel we don’t need --check; generally our approach is to simply regenerate, and let prek’s file changed detection do the checking (prek fails when files are changed by the hook). There should be a way to work around the license header.

Otherwise I think this is on the right track.

@FrankYang0529

Copy link
Copy Markdown
Member Author

@uranusjr Thanks for the suggestion. I changed to use prek hook.

@jason810496 jason810496 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for the update.

Comment thread .pre-commit-config.yaml Outdated
Comment thread java-sdk/scripts/ci/regenerate-verification-metadata.sh Outdated
Comment thread java-sdk/scripts/ci/regenerate-verification-metadata.sh Outdated
@FrankYang0529
FrankYang0529 force-pushed the java-sdk-verification-metadata-ci-check branch from 5b7d205 to 14ed122 Compare August 28, 2026 07:43

@jason810496 jason810496 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for the follow-up.

Comment thread java-sdk/scripts/ci/regenerate-verification-metadata.sh Outdated
@FrankYang0529
FrankYang0529 force-pushed the java-sdk-verification-metadata-ci-check branch 4 times, most recently from f08432a to e0099f2 Compare September 8, 2026 13:16
Signed-off-by: PoAn Yang <payang@apache.org>
@FrankYang0529
FrankYang0529 force-pushed the java-sdk-verification-metadata-ci-check branch from e0099f2 to 901aa4e Compare September 9, 2026 04:56
This was referenced Sep 25, 2026
@jason810496
jason810496 merged commit 3e47fc3 into apache:main Sep 27, 2026
159 checks passed
@github-actions

Copy link
Copy Markdown
Contributor

Backport failed to create: v3-3-test. View the failure log Run details

Note: As of Merging PRs targeted for Airflow 3.X
the committer who merges the PR is responsible for backporting the PRs that are bug fixes (generally speaking) to the maintenance branches.

In matter of doubt please ask in #release-management Slack channel.

Status Branch Result
❌ v3-3-test Commit Link

You can attempt to backport this manually by running:

cherry_picker 3e47fc3 v3-3-test

This should apply the commit to the v3-3-test branch and leave the commit in conflict state marking
the files that need manual conflict resolution.

After you have resolved the conflicts, you can continue the backport process by running:

cherry_picker --continue

If you don't have cherry-picker installed, see the installation guide.

@FrankYang0529
FrankYang0529 deleted the java-sdk-verification-metadata-ci-check branch September 27, 2026 10:57
potiuk added a commit that referenced this pull request Sep 27, 2026
The regenerate-java-sdk-verification-metadata hook added in #71869 drops
checksums that no Java SDK build task resolves any more, but the trust
list on main still carried entries for versions superseded by earlier
dependency bumps. The hook therefore rewrites the file in every run, and
static checks fail on every PR regardless of what it touches.

Generated-by: Claude Opus 5
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants