Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
9 changes: 7 additions & 2 deletions android/build.gradle.kts
Original file line number Diff line number Diff line change
Expand Up @@ -36,8 +36,9 @@ jacoco {

// Raise known-vulnerable transitive dependencies of the build toolchain to patched
// versions. None of these is a dependency of the SDK itself - they are pulled in by the
// Android Gradle Plugin's Unified Test Platform (netty, protobuf) and by Dokka's engine
// (jackson, jsoup), so the published AAR and its POM are unaffected.
// Android Gradle Plugin's Unified Test Platform (netty, protobuf), by Dokka's engine
// (jackson, jsoup, freemarker) and by the Kotlin plugin's signing helpers (Bouncy Castle),
// so the published AAR and its POM are unaffected.
//
// These are floors, not overrides: `useVersion` on its own would also drag a *newer*
// version back down, so anything at or above the floor is left alone and only older
Expand All @@ -54,6 +55,10 @@ run {
"com.fasterxml.jackson.dataformat" to libs.versions.jackson.get(),
"com.fasterxml.jackson.module" to libs.versions.jackson.get(),
"org.jsoup" to libs.versions.jsoup.get(),
"org.freemarker" to libs.versions.freemarker.get(),
// Kotlin 2.4's `kotlinBouncyCastleConfiguration` backs its PGP key and signing check
// tasks. This build never runs them, but the dependency graph still resolves it.
"org.bouncycastle" to libs.versions.bouncycastle.get(),
)

fun isBelowFloor(current: String?, floor: String): Boolean {
Expand Down
3 changes: 3 additions & 0 deletions build.gradle.kts
Original file line number Diff line number Diff line change
Expand Up @@ -20,6 +20,9 @@ buildscript {
add("classpath", "org.bitbucket.b_c:jose4j:${libs.versions.jose4j.get()}")
add("classpath", "org.jdom:jdom2:${libs.versions.jdom2.get()}")
add("classpath", "org.apache.commons:commons-compress:${libs.versions.commonsCompress.get()}")
// Not from AGP directly: commons-compress 1.26+ depends on it, so the floor above
// brings it onto this classpath.
add("classpath", "org.apache.commons:commons-lang3:${libs.versions.commonsLang3.get()}")
}
}
}
Expand Down
13 changes: 9 additions & 4 deletions gradle/libs.versions.toml
Original file line number Diff line number Diff line change
Expand Up @@ -33,14 +33,17 @@ dokka = "2.2.0"
# resolved independently:
#
# - build.gradle.kts (root buildscript) - AGP's own plugin classpath. gRPC/Netty, Bouncy
# Castle, commons-compress, jose4j and JDOM live here. This is the classpath Dependabot
# reports against, attributed to settings.gradle.kts.
# Castle, commons-compress (and its commons-lang3), jose4j and JDOM live here.
# - android/build.gradle.kts (resolutionStrategy) - the :android project's configurations,
# including AGP's Unified Test Platform, plus Dokka's engine (jackson, jsoup).
# including AGP's Unified Test Platform, Dokka's engine (jackson, jsoup, freemarker) and
# the Kotlin plugin's signing helpers (Bouncy Castle again).
#
# Dependabot reports both, attributing every alert to settings.gradle.kts - check which
# classpath a version is on before adding a floor.
#
# Dependabot does not track these: its Gradle parser only reaches [versions] through a
# `version.ref` in [libraries]/[plugins], and nothing references them. Re-check them by
# hand when `agp` or `dokka` is upgraded - because they are floors, one at or below what the
# hand when `agp`, `kotlin` or `dokka` is upgraded - because they are floors, one at or below what the
# tool already ships is a no-op, so a stale entry is inert rather than harmful.
netty = "4.1.138.Final"
protobuf = "3.25.9"
Expand All @@ -50,6 +53,8 @@ bouncycastle = "1.85"
jose4j = "0.9.6"
jdom2 = "2.0.6.1"
commonsCompress = "1.27.1"
commonsLang3 = "3.21.0"
freemarker = "2.3.35"

[libraries]
androidx-core-ktx = { group = "androidx.core", name = "core-ktx", version.ref = "coreKtx" }
Expand Down
Loading