Skip to content

chore: bring dependencies and CI up to date (24.7) - #25677

Merged
Artur- merged 12 commits into
24.7from
chore/update-dependencies-24.7
Sep 17, 2026
Merged

Artur- merged 12 commits into
24.7from
chore/update-dependencies-24.7

Conversation

@totally-not-ai

@totally-not-ai totally-not-ai Bot commented Sep 11, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Updates the managed libraries, build plugins and test dependencies on this branch to their current releases, bringing 24.7 in line with the 24.8–24.10 updates. It also fixes two CI problems that those updates uncovered.

What changed

No production code changes. This is a build, dependency and CI update only, so it is backward compatible for users of the library. The only runtime effect is the newer versions of the third-party libraries Flow depends on.

Libraries: Jackson 2.22.2, Jetty 12.0.39, Hibernate Validator 8.0.5, jsoup 1.23.2, Javassist 3.33.0, slf4j 2.0.19, JAXB 4.0.9, commons-io 2.22.0, commons-lang3 3.20.0, Mockito 5.23.0 with the matching Byte Buddy 1.17.7, ASM 9.10.1, JUnit Jupiter 5.14.4, Roaster 2.31.1, Nimbus JOSE+JWT 10.10 and the Eclipse runtime bundles. Spring Boot is already on the newest 3.4 release, and TestBench stays on the 9.4 line.

Build plugins: bnd 7.4.0, Surefire 3.6.0, Clean 3.5.0, WAR 3.5.1, Build Helper 3.6.2 and Properties 1.3.1.

Failsafe stays on 3.5.3. With 3.6.0 it picks up integration tests in modules whose web application the current shard has not built. Such a module starts a server that then holds the shared test port for the modules after it. The POM now explains this, since Surefire and Failsafe are no longer on the same version.

Surefire 3.6.0 fallout in signals: the module now clears the inherited testListener property. Surefire 3.6.0 resolves that JUnit 4 listener class before running the module's JUnit 5 tests, and the class is not on the module's classpath.

CI: both the unit test job and the integration test job now write the TestBench license before their fallback compile. On a job re-run the saved workspace is gone, so the job builds the reactor itself, including the production bundle module, whose build validates a license. Both jobs also read TB_LICENSE from the step environment instead of interpolating the secret into the shell script.

Small cleanups: the two express build test modules take slf4j-simple from ${slf4j.version} instead of a hard-coded version, the Spring integration tests resolve components from 24.7.14, and .pnpm-store/ is now ignored by git.

@rollup/plugin-typescript resolves its TypeScript peer dependency freely,
so the dev-server bundle now builds against TypeScript 7, where
ts.ScriptTarget.ES2015 no longer exists and the vite build fails with
"Cannot read properties of undefined (reading 'ES2015')". Pinning the
same 5.x range the other branches use keeps the build working.
The branch had not been updated since January, so libraries, build
plugins and frontend packages are behind the versions 24.10 ships.
Everything stays within its current major, and Spring Boot stays on the
3.4 line the branch was released with.
Builds were only allowed for actors with write access, which fails for
bots and outside contributors and left the branch without a way to run
CI at all. Pull requests also ran through pull_request_target, which
executes the base branch workflow with secrets against the pull request
code.

Also brings in the frontend dependency update script so the branch can
be added to the weekly update workflow.
TestBench 9.6.3 ships a Selenium whose generated CDP package no longer
matches the v136 classes this used, and the generated classes only work
for the Chrome versions a Selenium release happens to bundle. Building
the few Network and Target commands by hand, as 24.10 does, keeps the
offline and cache tests working with any Chrome.
jsoup no longer breaks the line before a nested element when pretty
printing, and the default dev dependency test states the glob version
the frontend manifest now pins.
@totally-not-ai

Copy link
Copy Markdown
Contributor Author

Type of change

  • Internal change

How to test

  1. ./scripts/computeMatrix.js set-version --version=999.99-SNAPSHOT
  2. mvn install -B -ntp -DskipTests -pl '!flow-plugins/flow-gradle-plugin' — fails on master/this branch's base in the vaadin-dev-server npm build with TypeError: Cannot read properties of undefined (reading 'ES2015'), passes with this branch.
  3. mvn verify -B -ntp -fae -Dmaven.javadoc.skip=false for the unit test modules — all 24 modules pass.

Verified locally on JDK 17 with the same commands CI runs: full install
build green, and the unit test modules from both CI shards green (4010
tests in flow-server, no failures). The integration tests were not
run locally — they need the TestBench license, so the offline/cache tests
that use the rewritten DevToolsWrapper are only covered once CI runs
them here.

API changes

Compared to origin/24.7:

  • Added public void DevToolsWrapper.close() (flow-test-util)
  • FrontendTools.DEFAULT_NODE_VERSION value v22.17.0 → v22.23.2
  • FrontendTools.DEFAULT_PNPM_VERSION value 8.6.11 → 8.15.9

No removals or signature changes.

Why the build broke by itself

@rollup/plugin-typescript declares TypeScript as a peer dependency, and
vaadin-dev-server never pinned it, so every npm install picks the
newest release. TypeScript 7 dropped ts.ScriptTarget.ES2015, which the
plugin reads at load time, so the vite config fails to load. 24.10 hit the
same thing in July and pinned ^5.9.3 in #24959.

@github-actions

github-actions Bot commented Sep 11, 2026 •

Copy link
Copy Markdown
Contributor

Test Results

1 117 files   -  79  1 117 suites   - 79   1h 10m 4s ⏱️ - 4m 14s
7 844 tests ±  0  7 788 ✅ +40  56 💤 ±0  0 ❌ ±0 
8 145 runs   - 101  8 084 ✅  - 53  61 💤  - 4  0 ❌ ±0 

Results for commit 68a7473. ± Comparison against base commit cffb87c.

♻️ This comment has been updated with latest results.

TestBench 9.5 and later need the license checker 2.x and 3.x APIs, which
are a major step from the 1.x this branch ships, so every integration
test failed to initialise with NoClassDefFoundError. 9.4.5 is the newest
release that still runs against the 1.x checker, and its Selenium only
has the single argument CDP connection factory.
Artur-
Artur- previously approved these changes Sep 14, 2026
Three separate breakages surfaced once the workflow could actually run:

The bundled Vite plugin `react-function-location-plugin.js` imports
`@babel/types`, which was only reachable transitively through
`@babel/core`. pnpm does not hoist it to the project root reliably, so
Vite failed to load `vite.config.ts` and every `vite-basics` test waited
out its 300 second timeout until the shard hit the 30 minute cap. The
package is now declared where the plugin expects it, as on 24.10.

Guava 33.7.1 brings in jspecify 1.0.1 while flow-server and Selenium
still depend on 1.0.0, which failed the releasability check on
`flow-test-npm-performance-regression`. The two releases differ only in
documentation, so the artifact is excluded from the convergence rule
instead of being pinned - pinning flow-server to 1.0.1 only moves the
conflict to the modules that pull Selenium in.

`DnDIT` compares a drag image against the server rendered outer HTML,
which jsoup no longer pads with spaces, the same pretty printing change
`ElementTest` was already adjusted for.
Declaring `@babel/types` got Vite past loading its config, and the next
unhoisted transitive took its place: `@preact/signals-react/runtime`,
which the generated `index.tsx` and `Flow.tsx` import, could not be
resolved either, so `vite-basics` still timed out shard after shard.

`shamefully-hoist=true` is only a partial-hoist heuristic layered on
pnpm's default isolated layout, and it does not expose every transitive
at the project root. `node-linker=hoisted` installs flat, npm style, so
resolution no longer depends on what pnpm chose to hoist. The flag is
passed on the command line as well as written to the generated `.npmrc`,
because the command line wins over a project or user level `.npmrc`.

This is what 24.10 ships, and it covers the other transitives that would
otherwise surface one integration test run at a time.
The postinstall command stripped a flag that is no longer added, and
both .npmrc messages still pointed at shamefully-hoist. The hoisted node
linker is a general pnpm option that `run` accepts, so nothing needs
stripping, and a custom .npmrc no longer has to set anything itself
because the command line wins over it.
…me test (24.7)

`documentCssImport_externalUrlLoaded` checked `document.fonts.check`
once, immediately after opening the view, so it failed whenever the
Google Fonts request had not completed yet - which is what both custom
frontend directory shards hit while the identical assertion in
`test-themes` passed in the same job, because that copy already polls.
Use the same `waitForFont` helper here.
`JarContentsManagerTest` asserted the copied file was older than a wall
clock reading taken right after the copy, which only holds when a
millisecond boundary falls in between; 24.8 and later record the file's
own modification time and assert it is unchanged, which is what the test
is about. This is the failure the unit test shard hit.

`WebPushIT` now gives the notification the same generous timeout as the
subscribe step, and `ThemeSwitchLiveReloadIT` waits for the server to
finish restarting before each test, both as on the newer branches.

`DEFAULT_NPM_VERSION` is the version shipped with the default Node, and
Node v22.23.2 ships npm 10.9.8, so it follows the Node bump as it did on
24.9 and 24.10.
The single argument waitUntil only allows ten seconds, which is short for
a server that is still redeploying, and swallowing the exception left a
genuinely dead server reported as a bare Selenium timeout naming neither
the URL nor the cause. Wait the same sixty seconds the Spring smoke test
uses and rethrow the last connection failure instead.

Backdate the copied file in JarContentsManagerTest before the second
copy, so that an unwanted rewrite moves the modification time no matter
how coarse the file system timestamps are, rather than only when the
rewrite happens to land in a later tick.
@Artur-
Artur- merged commit c8bc359 into 24.7 Sep 17, 2026
39 of 41 checks passed
@Artur-
Artur- deleted the chore/update-dependencies-24.7 branch September 17, 2026 16:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants