Skip to content

Support Android/Gradle dependencies and project toolchains - #33

Merged
owjs3901 merged 8 commits into
mainfrom
feat/android-gradle-toolchain-support
Oct 1, 2026
Merged

owjs3901 merged 8 commits into
mainfrom
feat/android-gradle-toolchain-support

Conversation

@owjs3901

@owjs3901 owjs3901 commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Integrate Android/Gradle dependencies, plugins, version catalogs, property references, SDK levels and wrapper distributions with the existing scanner, filters, targets, output and update pipeline.
  • Support project package managers and Node/Rust/mise/asdf toolchain declarations; provide explicit local installed-tool queries without changing installed tools.
  • Query declared Maven repositories and official tool metadata, update integrity sidecars, distinguish unsupported/failed entries from current versions, and preserve comments, formatting, channels, ranges and CRLF.
  • Add bounded, scoped AGP/Gradle/Kotlin/JDK/SDK compatibility guards and opt-in compatible selection; never automatically raise minSdk.
  • Add recoverable multi-file writes with locks, pending markers, receipts, rollback/finish recovery and filesystem metadata preservation.
  • Add structured JSON reports, strict/incomplete policies, bounded shared metadata caching, compatibility provenance, documentation and fixed-response Tauri monorepo regressions.
  • Gate changepacks on reusable Windows/macOS/Linux regressions, the existing suite and coverage; add real npm/wheel/crate packaging checks. Raise MSRV to Rust 1.88.
  • Include a changepacks minor-release record for all nine distribution packages (expected 0.3.0).

Local verification (Windows)

  • cargo test --locked --workspace --quiet: 1,058 tests passed.
  • cargo +1.88.0 test --locked --workspace --target-dir target/msrv-1.88 --quiet: 1,058 tests passed.
  • cargo +1.88.0 check --locked --workspace --all-targets --all-features --target-dir target/msrv-1.88 --quiet: passed.
  • cargo clippy --locked --workspace --all-targets --all-features -- -D warnings: passed.
  • cargo fmt --all -- --check and git diff --check: passed.
  • bun run --cwd bridge/node test: 3 tests passed, including npm pack and installation of the host native package.
  • Built and installed a Python wheel with bridge/python/test_wheel.py: passed, including both CLI aliases and fixed-response updates.
  • cargo package --locked --workspace --exclude dependency-check-updates-napi --exclude dependency-check-updates-python-bridge --allow-dirty: all seven publishable Rust crates rebuilt and verified.

Merge and release gates

Remote CI run 36806616204 passes on 7f8dc55: all 18 required validation jobs (three platforms, Rust 1.88, seven-crate packaging, coverage and the existing Python 3.11–3.14 × three-platform matrix) plus the changepacks gate succeeded. Publication jobs are correctly skipped on the feature PR. Release via the changepacks version PR after its own checks pass, then verify published packages and assets.

The existing 100% coverage policy is unchanged. Coverage passes at 100.00% (3,515/3,515 lines) on commit 7f8dc55, with no threshold change or new coverage exclusions. The intermediate coverage failures were addressed with deterministic tests. Added tests cover transaction failure outcomes, lock release, unsafe recovery inputs, registry failures, bounded compatibility search, static-parser boundaries, tool probes and updates across all existing ecosystems. Triple-quoted Gradle example text is now excluded from declarations.

The parser deliberately does not execute Gradle or act as a universal dependency solver. Unsupported dynamic expressions remain unchanged and are reported. Compatibility support and transaction boundaries are documented in README.

@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown

Changepacks

@dependency-check-updates/cli@0.2.0 → 0.3.0 - bridge/node/package.json

Minor

  • Add static Android/Gradle and project toolchain updates, explicit local tool queries, compatibility-aware selection, integrity checks, recoverable transactions, structured diagnostics, and deterministic cross-platform packaging regressions. Minimum supported Rust is now 1.88; legacy JSON output remains available with --json-legacy.

dependency-check-updates@0.2.0 → 0.3.0 - bridge/python/pyproject.toml

Minor

  • Add static Android/Gradle and project toolchain updates, explicit local tool queries, compatibility-aware selection, integrity checks, recoverable transactions, structured diagnostics, and deterministic cross-platform packaging regressions. Minimum supported Rust is now 1.88; legacy JSON output remains available with --json-legacy.

dependency-check-updates@0.2.0 → 0.3.0 - crates/cli/Cargo.toml

Minor

  • Add static Android/Gradle and project toolchain updates, explicit local tool queries, compatibility-aware selection, integrity checks, recoverable transactions, structured diagnostics, and deterministic cross-platform packaging regressions. Minimum supported Rust is now 1.88; legacy JSON output remains available with --json-legacy.

dependency-check-updates-core@0.2.0 → 0.3.0 - crates/core/Cargo.toml

Minor

  • Add static Android/Gradle and project toolchain updates, explicit local tool queries, compatibility-aware selection, integrity checks, recoverable transactions, structured diagnostics, and deterministic cross-platform packaging regressions. Minimum supported Rust is now 1.88; legacy JSON output remains available with --json-legacy.

dependency-check-updates-docker@0.2.0 → 0.3.0 - crates/docker/Cargo.toml

Minor

  • Add static Android/Gradle and project toolchain updates, explicit local tool queries, compatibility-aware selection, integrity checks, recoverable transactions, structured diagnostics, and deterministic cross-platform packaging regressions. Minimum supported Rust is now 1.88; legacy JSON output remains available with --json-legacy.

dependency-check-updates-github@0.2.0 → 0.3.0 - crates/github/Cargo.toml

Minor

  • Add static Android/Gradle and project toolchain updates, explicit local tool queries, compatibility-aware selection, integrity checks, recoverable transactions, structured diagnostics, and deterministic cross-platform packaging regressions. Minimum supported Rust is now 1.88; legacy JSON output remains available with --json-legacy.

dependency-check-updates-node@0.2.0 → 0.3.0 - crates/node/Cargo.toml

Minor

  • Add static Android/Gradle and project toolchain updates, explicit local tool queries, compatibility-aware selection, integrity checks, recoverable transactions, structured diagnostics, and deterministic cross-platform packaging regressions. Minimum supported Rust is now 1.88; legacy JSON output remains available with --json-legacy.

dependency-check-updates-python@0.2.0 → 0.3.0 - crates/python/Cargo.toml

Minor

  • Add static Android/Gradle and project toolchain updates, explicit local tool queries, compatibility-aware selection, integrity checks, recoverable transactions, structured diagnostics, and deterministic cross-platform packaging regressions. Minimum supported Rust is now 1.88; legacy JSON output remains available with --json-legacy.

dependency-check-updates-rust@0.2.0 → 0.3.0 - crates/rust/Cargo.toml

Minor

  • Add static Android/Gradle and project toolchain updates, explicit local tool queries, compatibility-aware selection, integrity checks, recoverable transactions, structured diagnostics, and deterministic cross-platform packaging regressions. Minimum supported Rust is now 1.88; legacy JSON output remains available with --json-legacy.

@owjs3901
owjs3901 merged commit e5fbcd9 into main Oct 1, 2026
25 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant