Update dependencies (#1065)

Rolls the outstanding dependency updates into a single change, along
with fixes for two breaking
changes they brought with them.

## Gradle Wrapper 9.6.1 → 9.7.1

Updated in all five wrapped projects: `sources/test/init-scripts` and
the `gradle-plugin`,
`groovy-dsl`, `java-toolchain` and `kotlin-dsl` workflow samples.

## GitHub Actions

- `actions/setup-java` v5.7.0 → v6.0.0
- `github/codeql-action/init` and `github/codeql-action/analyze`
re-pinned to a newer v3.29.5 commit

## npm dependencies

- `@typescript-eslint/eslint-plugin` 8.66.0 → 8.69.0
- `esbuild` 0.28.1 → 0.28.2
- `eslint` 10.8.0 → 10.9.1
- `globals` 17.9.0 → 17.11.0

`jest` stays at 30.4.2 and `@jest/globals` at 30.4.1 — see below.

## setup-java v6 needs signature verification disabled for EOL JDKs

v6 enables `verify-signature` by default. Temurin 16 and 20 are EOL and
publish no signatures, so
the toolchain-detection job could no longer install them:

```
Java setup process failed due to: Input 'verify-signature' is enabled,
but no signature URL was found for Temurin version 16.0.2+7.
```

Verification is disabled for those two steps only. The Java 17 and
matrix steps still verify.

## jest is held at 30.4.x because 30.5.0 breaks nock

jest 30.5.0 reworked the ESM module registry (ES modules keyed by full
URL, modules shared across
overlapping CommonJS/ESM graphs). nock ends up patching a different
module instance than the one
`@actions/http-client` reaches undici through, so it no longer
intercepts anything: all five mocked
tests in `short-lived-token.test.ts` silently hit the real network and
resolve `null`. Two further
tests in that file keep passing only vacuously — they assert `null`,
which is also what an
unintercepted request returns.

Bisected on node 24.18.0, changing only the jest version:

| jest | result |
| --- | --- |
| 30.5.0 | 5 failed, 38 passed |
| 30.4.2 | 43 passed |

nock 15.0.0 does not fix it, so this cannot be resolved by moving nock
forward. The node version
matters too: 24.3.0 masks the failure completely, which is why it
reproduced only in CI.

Because `jest` is an exactly-pinned direct devDependency, the pin by
itself holds the entire test
runtime at 30.4.x — `jest-cli`, `jest-runtime`, `jest-environment-node`,
`@jest/core`,
`@jest/transform`, `@jest/types`, `expect` and `jest-util` all resolve
to 30.4.x with no `overrides`
block. Nothing in the tree forces jest forward; only dependabot proposes
it. So the constraint is
expressed in `.github/dependabot.yml`, alongside the existing
`typescript` and `@types/node`
entries, ignoring `jest` and `@jest/globals` `>=30.5.0` with a comment
recording when it can be
lifted.

`pretty-format` is left to float to 30.5.1 via the types-only
`@types/jest`; it renders test output
and has no bearing on nock or module resolution.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Signed-off-by: bot-githubaction <bot-githubaction@gradle.com>
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: bot-githubaction <bot-githubaction@gradle.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
Daz DeBoer
2026-09-07 16:58:55 -06:00
committed by GitHub
co-authored by bot-githubaction dependabot[bot] Claude Opus 5
parent 0d208da058
commit 6b92be1905
17 changed files with 2419 additions and 987 deletions
+7
View File
@@ -20,6 +20,13 @@ updates:
versions: ["7.x"]
- dependency-name: "@types/node"
versions: ["25.x", "26.x"]
# jest 30.5.0 reworked the ESM module registry, and nock no longer intercepts requests
# made through @actions/http-client (undici): every mocked test silently hits the real
# network instead. nock 15 does not fix it. Drop these two once they interoperate again.
- dependency-name: "jest"
versions: [">=30.5.0"]
- dependency-name: "@jest/globals"
versions: [">=30.5.0"]
- package-ecosystem: "github-actions"
# github-actions with directory: "/" only monitors .github/workflows
# https://github.com/dependabot/dependabot-core/issues/6345
@@ -1,7 +1,7 @@
distributionBase=GRADLE_USER_HOME
distributionPath=wrapper/dists
distributionSha256Sum=9c0f7faeeb306cb14e4279a3e084ca6b596894089a0638e68a07c945a32c9e14
distributionUrl=https\://services.gradle.org/distributions/gradle-9.6.1-bin.zip
distributionSha256Sum=acd53f1edaf02f1a8ff99879f8a34b302661a057d9b063ae9e35b552f804d20a
distributionUrl=https\://services.gradle.org/distributions/gradle-9.7.1-bin.zip
networkTimeout=10000
retries=0
retryBackOffMs=500
@@ -1,7 +1,7 @@
distributionBase=GRADLE_USER_HOME
distributionPath=wrapper/dists
distributionSha256Sum=9c0f7faeeb306cb14e4279a3e084ca6b596894089a0638e68a07c945a32c9e14
distributionUrl=https\://services.gradle.org/distributions/gradle-9.6.1-bin.zip
distributionSha256Sum=acd53f1edaf02f1a8ff99879f8a34b302661a057d9b063ae9e35b552f804d20a
distributionUrl=https\://services.gradle.org/distributions/gradle-9.7.1-bin.zip
networkTimeout=10000
retries=0
retryBackOffMs=500
@@ -1,7 +1,7 @@
distributionBase=GRADLE_USER_HOME
distributionPath=wrapper/dists
distributionSha256Sum=9c0f7faeeb306cb14e4279a3e084ca6b596894089a0638e68a07c945a32c9e14
distributionUrl=https\://services.gradle.org/distributions/gradle-9.6.1-bin.zip
distributionSha256Sum=acd53f1edaf02f1a8ff99879f8a34b302661a057d9b063ae9e35b552f804d20a
distributionUrl=https\://services.gradle.org/distributions/gradle-9.7.1-bin.zip
networkTimeout=10000
retries=0
retryBackOffMs=500
@@ -1,7 +1,7 @@
distributionBase=GRADLE_USER_HOME
distributionPath=wrapper/dists
distributionSha256Sum=9c0f7faeeb306cb14e4279a3e084ca6b596894089a0638e68a07c945a32c9e14
distributionUrl=https\://services.gradle.org/distributions/gradle-9.6.1-bin.zip
distributionSha256Sum=acd53f1edaf02f1a8ff99879f8a34b302661a057d9b063ae9e35b552f804d20a
distributionUrl=https\://services.gradle.org/distributions/gradle-9.7.1-bin.zip
networkTimeout=10000
retries=0
retryBackOffMs=500
+2 -2
View File
@@ -35,7 +35,7 @@ jobs:
# Initializes the CodeQL tools for scanning.
- name: Initialize CodeQL
uses: github/codeql-action/init@d1ba80a13dd99fba24a470575428917156a28b43 # v3.29.5
uses: github/codeql-action/init@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v3.29.5
with:
languages: ${{ matrix.language }}
config: |
@@ -43,4 +43,4 @@ jobs:
- sources/src
- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@d1ba80a13dd99fba24a470575428917156a28b43 # v3.29.5
uses: github/codeql-action/analyze@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v3.29.5
+1 -1
View File
@@ -36,7 +36,7 @@ jobs:
sources/test/init-scripts/**
- name: Setup Java
if: steps.changes.outputs.any_changed == 'true' || github.event_name != 'pull_request'
uses: actions/setup-java@b6effb05e454b25005698d916606bdc6ffcbf961 # v5.7.0
uses: actions/setup-java@dd06d9cba3e5552c54d9f8ea23572deb30010f7c # v6.0.0
with:
distribution: temurin
java-version: 17
@@ -65,15 +65,19 @@ jobs:
uses: ./.github/actions/init-integ-test
- name: Setup Java 16
uses: actions/setup-java@b6effb05e454b25005698d916606bdc6ffcbf961 # v5.7.0
uses: actions/setup-java@dd06d9cba3e5552c54d9f8ea23572deb30010f7c # v6.0.0
with:
distribution: 'temurin'
java-version: 16
# Temurin 16 is EOL and publishes no signatures: setup-java v6 enables verify-signature by default
verify-signature: false
- name: Setup Java 20
uses: actions/setup-java@b6effb05e454b25005698d916606bdc6ffcbf961 # v5.7.0
uses: actions/setup-java@dd06d9cba3e5552c54d9f8ea23572deb30010f7c # v6.0.0
with:
distribution: 'temurin'
java-version: 20
# Temurin 20 is EOL and publishes no signatures: setup-java v6 enables verify-signature by default
verify-signature: false
- name: Setup Gradle
uses: ./setup-gradle
- name: List detected toolchains
@@ -56,7 +56,7 @@ jobs:
run: gradle help "-DgradleVersionCheck=7.1.1"
# Configure JDK 17 for Gradle 9 and later
- name: Setup Java
uses: actions/setup-java@b6effb05e454b25005698d916606bdc6ffcbf961 # v5.7.0
uses: actions/setup-java@dd06d9cba3e5552c54d9f8ea23572deb30010f7c # v6.0.0
with:
distribution: temurin
java-version: 17
@@ -110,7 +110,7 @@ jobs:
uses: ./.github/actions/init-integ-test
- name: Setup Java
uses: actions/setup-java@b6effb05e454b25005698d916606bdc6ffcbf961 # v5.7.0
uses: actions/setup-java@dd06d9cba3e5552c54d9f8ea23572deb30010f7c # v6.0.0
with:
distribution: temurin
java-version: ${{ matrix.java-version }}
+2387 -966
View File
File diff suppressed because it is too large Load Diff
+4 -4
View File
@@ -55,11 +55,11 @@
"@types/node": "24.13.3",
"@types/unzipper": "0.10.11",
"@types/which": "3.0.4",
"@typescript-eslint/eslint-plugin": "8.66.0",
"@typescript-eslint/eslint-plugin": "8.69.0",
"dedent": "1.7.2",
"esbuild": "0.28.1",
"eslint": "10.8.0",
"globals": "17.9.0",
"esbuild": "0.28.2",
"eslint": "10.9.1",
"globals": "17.11.0",
"jest": "30.4.2",
"nock": "14.0.17",
"npm-run-all": "4.1.5",
Binary file not shown.
@@ -1,7 +1,7 @@
distributionBase=GRADLE_USER_HOME
distributionPath=wrapper/dists
distributionSha256Sum=9c0f7faeeb306cb14e4279a3e084ca6b596894089a0638e68a07c945a32c9e14
distributionUrl=https\://services.gradle.org/distributions/gradle-9.6.1-bin.zip
distributionSha256Sum=acd53f1edaf02f1a8ff99879f8a34b302661a057d9b063ae9e35b552f804d20a
distributionUrl=https\://services.gradle.org/distributions/gradle-9.7.1-bin.zip
networkTimeout=10000
retries=0
retryBackOffMs=500