-
Notifications
You must be signed in to change notification settings - Fork 105
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[JENKINS-41631] Lower Guava dep to 11, which is what Jenkins still uses #123
[JENKINS-41631] Lower Guava dep to 11, which is what Jenkins still uses #123
Conversation
This pull request originates from a CloudBees employee. At CloudBees, we require that all pull requests be reviewed by other CloudBees employees before we seek to have the change accepted. If you want to learn more about our process please see this explanation. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I am not sure it is safe in general. Stapler is being used in many libs embedded into Jenkins libs and plugins, and some of them may depend on Guava API available in newer versions. Same for non-Jenkins components like IDE plugins.
🐛 until somebody investigates Guava usage in transient dependencies. Maybe we could "just" update Jenkins instead.
Such as?
Clearly not if they were being used from Jenkins. If Stapler is being used from some non-Jenkins application, that application is free to depend on any newer version it likes.
Huh? IDE plugins do not depend on Stapler. Why would they?
That would be far, far riskier. Which is why I am doing the safe fix now. If you want to take on updating Guava in Jenkins core and analyzing the impact of that, go ahead. (And it is not mutually exclusive with this patch anyway.) |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🐝
@oleg-nenashev ping |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Clearly not if they were being used from Jenkins. If Stapler is being used from some non-Jenkins application, that application is free to depend on any newer version it likes.
Agreed, core would override that anyway. 🐝 just because I do not care about non-Jenkins usages
Was noted in jenkinsci/plugin-pom#67.
@reviewbybees