chore: bring dependencies and CI up to date (24.7) - #25677
Conversation
@rollup/plugin-typescript resolves its TypeScript peer dependency freely, so the dev-server bundle now builds against TypeScript 7, where ts.ScriptTarget.ES2015 no longer exists and the vite build fails with "Cannot read properties of undefined (reading 'ES2015')". Pinning the same 5.x range the other branches use keeps the build working.
The branch had not been updated since January, so libraries, build plugins and frontend packages are behind the versions 24.10 ships. Everything stays within its current major, and Spring Boot stays on the 3.4 line the branch was released with.
Builds were only allowed for actors with write access, which fails for bots and outside contributors and left the branch without a way to run CI at all. Pull requests also ran through pull_request_target, which executes the base branch workflow with secrets against the pull request code. Also brings in the frontend dependency update script so the branch can be added to the weekly update workflow.
TestBench 9.6.3 ships a Selenium whose generated CDP package no longer matches the v136 classes this used, and the generated classes only work for the Chrome versions a Selenium release happens to bundle. Building the few Network and Target commands by hand, as 24.10 does, keeps the offline and cache tests working with any Chrome.
jsoup no longer breaks the line before a nested element when pretty printing, and the default dev dependency test states the glob version the frontend manifest now pins.
Type of change
How to test
Verified locally on JDK 17 with the same commands CI runs: full install API changesCompared to
No removals or signature changes. Why the build broke by itself
|
TestBench 9.5 and later need the license checker 2.x and 3.x APIs, which are a major step from the 1.x this branch ships, so every integration test failed to initialise with NoClassDefFoundError. 9.4.5 is the newest release that still runs against the 1.x checker, and its Selenium only has the single argument CDP connection factory.
Three separate breakages surfaced once the workflow could actually run: The bundled Vite plugin `react-function-location-plugin.js` imports `@babel/types`, which was only reachable transitively through `@babel/core`. pnpm does not hoist it to the project root reliably, so Vite failed to load `vite.config.ts` and every `vite-basics` test waited out its 300 second timeout until the shard hit the 30 minute cap. The package is now declared where the plugin expects it, as on 24.10. Guava 33.7.1 brings in jspecify 1.0.1 while flow-server and Selenium still depend on 1.0.0, which failed the releasability check on `flow-test-npm-performance-regression`. The two releases differ only in documentation, so the artifact is excluded from the convergence rule instead of being pinned - pinning flow-server to 1.0.1 only moves the conflict to the modules that pull Selenium in. `DnDIT` compares a drag image against the server rendered outer HTML, which jsoup no longer pads with spaces, the same pretty printing change `ElementTest` was already adjusted for.
Declaring `@babel/types` got Vite past loading its config, and the next unhoisted transitive took its place: `@preact/signals-react/runtime`, which the generated `index.tsx` and `Flow.tsx` import, could not be resolved either, so `vite-basics` still timed out shard after shard. `shamefully-hoist=true` is only a partial-hoist heuristic layered on pnpm's default isolated layout, and it does not expose every transitive at the project root. `node-linker=hoisted` installs flat, npm style, so resolution no longer depends on what pnpm chose to hoist. The flag is passed on the command line as well as written to the generated `.npmrc`, because the command line wins over a project or user level `.npmrc`. This is what 24.10 ships, and it covers the other transitives that would otherwise surface one integration test run at a time.
The postinstall command stripped a flag that is no longer added, and both .npmrc messages still pointed at shamefully-hoist. The hoisted node linker is a general pnpm option that `run` accepts, so nothing needs stripping, and a custom .npmrc no longer has to set anything itself because the command line wins over it.
…me test (24.7) `documentCssImport_externalUrlLoaded` checked `document.fonts.check` once, immediately after opening the view, so it failed whenever the Google Fonts request had not completed yet - which is what both custom frontend directory shards hit while the identical assertion in `test-themes` passed in the same job, because that copy already polls. Use the same `waitForFont` helper here.
`JarContentsManagerTest` asserted the copied file was older than a wall clock reading taken right after the copy, which only holds when a millisecond boundary falls in between; 24.8 and later record the file's own modification time and assert it is unchanged, which is what the test is about. This is the failure the unit test shard hit. `WebPushIT` now gives the notification the same generous timeout as the subscribe step, and `ThemeSwitchLiveReloadIT` waits for the server to finish restarting before each test, both as on the newer branches. `DEFAULT_NPM_VERSION` is the version shipped with the default Node, and Node v22.23.2 ships npm 10.9.8, so it follows the Node bump as it did on 24.9 and 24.10.
The single argument waitUntil only allows ten seconds, which is short for a server that is still redeploying, and swallowing the exception left a genuinely dead server reported as a bare Selenium timeout naming neither the URL nor the cause. Wait the same sixty seconds the Spring smoke test uses and rethrow the last connection failure instead. Backdate the copied file in JarContentsManagerTest before the second copy, so that an unwanted rewrite moves the modification time no matter how coarse the file system timestamps are, rather than only when the rewrite happens to land in a later tick.
Summary
Updates the managed libraries, build plugins and test dependencies on this branch to their current releases, bringing 24.7 in line with the 24.8–24.10 updates. It also fixes two CI problems that those updates uncovered.
What changed
No production code changes. This is a build, dependency and CI update only, so it is backward compatible for users of the library. The only runtime effect is the newer versions of the third-party libraries Flow depends on.
Libraries: Jackson 2.22.2, Jetty 12.0.39, Hibernate Validator 8.0.5, jsoup 1.23.2, Javassist 3.33.0, slf4j 2.0.19, JAXB 4.0.9, commons-io 2.22.0, commons-lang3 3.20.0, Mockito 5.23.0 with the matching Byte Buddy 1.17.7, ASM 9.10.1, JUnit Jupiter 5.14.4, Roaster 2.31.1, Nimbus JOSE+JWT 10.10 and the Eclipse runtime bundles. Spring Boot is already on the newest 3.4 release, and TestBench stays on the 9.4 line.
Build plugins: bnd 7.4.0, Surefire 3.6.0, Clean 3.5.0, WAR 3.5.1, Build Helper 3.6.2 and Properties 1.3.1.
Failsafe stays on 3.5.3. With 3.6.0 it picks up integration tests in modules whose web application the current shard has not built. Such a module starts a server that then holds the shared test port for the modules after it. The POM now explains this, since Surefire and Failsafe are no longer on the same version.
Surefire 3.6.0 fallout in
signals: the module now clears the inheritedtestListenerproperty. Surefire 3.6.0 resolves that JUnit 4 listener class before running the module's JUnit 5 tests, and the class is not on the module's classpath.CI: both the unit test job and the integration test job now write the TestBench license before their fallback compile. On a job re-run the saved workspace is gone, so the job builds the reactor itself, including the production bundle module, whose build validates a license. Both jobs also read
TB_LICENSEfrom the step environment instead of interpolating the secret into the shell script.Small cleanups: the two express build test modules take
slf4j-simplefrom${slf4j.version}instead of a hard-coded version, the Spring integration tests resolve components from 24.7.14, and.pnpm-store/is now ignored by git.