Skip to content

chore: bump com.vanniktech:gradle-maven-publish-plugin in / - #881

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/gradle/gradle-cc84e3a6d9
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/gradle/gradle-cc84e3a6d9

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Bumps com.vanniktech:gradle-maven-publish-plugin in / from 0.31.0 to 0.37.0.

Updates com.vanniktech:gradle-maven-publish-plugin from 0.31.0 to 0.37.0

Release notes

Sourced from com.vanniktech:gradle-maven-publish-plugin's releases.

0.37.0

  • When publishing to Maven Central, redundant checksum files are now excluded by default: checksums of .asc signature files (gradle/gradle#20232) and the sha256/sha512 checksums, which are never read by Gradle or Maven Central. The published checksums can be configured through checksums(...) in the DSL or the mavenCentralChecksums Gradle property (default md5,sha1). Signature checksum exclusion can be controlled through excludeSignatureChecksums() or the mavenCentralExcludeSignatureChecksums Gradle property.
  • Maven Central deployment id is being logged after upload.

Minimum supported versions

  • JDK 17
  • Gradle 9.0.0
  • Android Gradle Plugin 8.13.0
  • Kotlin Gradle Plugin 2.2.0

Compatibility tested up to

  • JDK 26
  • Gradle 9.6.0
  • Gradle 9.7.0-milestone-1
  • Android Gradle Plugin 9.2.1
  • Android Gradle Plugin 9.3.0-rc01
  • Android Gradle Plugin 9.4.0-alpha01
  • Kotlin Gradle Plugin 2.4.0

0.37.0-rc1

  • When publishing to Maven Central, redundant checksum files are now excluded by default: checksums of .asc signature files (gradle/gradle#20232) and the sha256/sha512 checksums, which are never read by Gradle or Maven Central. The published checksums can be configured through checksums(...) in the DSL or the mavenCentralChecksums Gradle property (default md5,sha1). Signature checksum exclusion can be controlled through excludeSignatureChecksums() or the mavenCentralExcludeSignatureChecksums Gradle property.
  • Maven Central deployment id is being logged after upload.

Minimum supported versions

  • JDK 17
  • Gradle 9.0.0
  • Android Gradle Plugin 8.13.0
  • Kotlin Gradle Plugin 2.2.0

Compatibility tested up to

  • JDK 26
  • Gradle 9.6.0
  • Gradle 9.7.0-milestone-1
  • Android Gradle Plugin 9.2.1
  • Android Gradle Plugin 9.3.0-rc01
  • Android Gradle Plugin 9.4.0-alpha01
  • Kotlin Gradle Plugin 2.4.0

0.36.0

BREAKING

... (truncated)

Changelog

Sourced from com.vanniktech:gradle-maven-publish-plugin's changelog.

0.37.0 (2026-06-21)

  • When publishing to Maven Central, redundant checksum files are now excluded by default: checksums of .asc signature files (gradle/gradle#20232) and the sha256/sha512 checksums, which are never read by Gradle or Maven Central. The published checksums can be configured through checksums(...) in the DSL or the mavenCentralChecksums Gradle property (default md5,sha1). Signature checksum exclusion can be controlled through excludeSignatureChecksums() or the mavenCentralExcludeSignatureChecksums Gradle property.
  • Maven Central deployment id is being logged after upload.

Minimum supported versions

  • JDK 17
  • Gradle 9.0.0
  • Android Gradle Plugin 8.13.0
  • Kotlin Gradle Plugin 2.2.0

Compatibility tested up to

  • JDK 26
  • Gradle 9.6.0
  • Gradle 9.7.0-milestone-1
  • Android Gradle Plugin 9.2.1
  • Android Gradle Plugin 9.3.0-rc01
  • Android Gradle Plugin 9.4.0-alpha01
  • Kotlin Gradle Plugin 2.4.0

0.36.0 (2026-01-13)

BREAKING

  • Updated minimum supported JDK, Gradle, Android Gradle Plugin and Kotlin versions.
  • Removed support for Dokka v1, it's now required to use Dokka in v2 mode.
  • Mark DirectorySignatureType internal.

Behavior changes

  • validateDeployment now has the DeploymentValidation enum as type instead of being a boolean. The default is now to just wait for the VALIDATED state. The previous behavior can be achieved by setting it to PUBLISHED. NONE can be used for disabling the validation completely.
  • When calling configure(...) manually to configure what to publish and not passing javadocJar explicity, the plugin now defaults to publishing an empty javadoc jar.

Features

  • Android projects now support using Dokka for javadoc creation, this will happen automatically when using the default options and the Dokka plugin is applied to the project.
  • Added consistent JavadocJar and SourcesJar options to configureBasedOnAppliedPlugins and to all applicable project types that can be passed to configure. The previous Boolean based versions have been deprecated.
  • When enabling Maven Central publishing through the DSL, the mavenCentralDeploymentValidation and mavenCentralAutomaticPublishing are used for the default values of the 2 parameters when they are not passed explicitly. This allows to more easily override them in certain environments.
  • When isolated projects is enabled the module/project specific gradle.properties files are now considered in

... (truncated)

Commits

@dependabot dependabot Bot added the dependabot label Oct 6, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner October 6, 2026 20:45
@dependabot dependabot Bot added the dependabot label Oct 6, 2026
@cursor

cursor Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

PR Summary

Low Risk
Low risk build dependency update with no impact on runtime application code.

Overview
Updates the com.vanniktech:gradle-maven-publish-plugin dependency in build-logic from version 0.31.0 to 0.37.0.

Reviewed by Cursor Bugbot for commit 98e7b96. Bugbot is set up for automated code reviews on this repo. Configure here.

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using default effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, have a team admin enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 8fc6e7e. Configure here.


dependencies {
implementation("com.vanniktech:gradle-maven-publish-plugin:0.31.0")
implementation("com.vanniktech:gradle-maven-publish-plugin:0.37.0")

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Plugin requires Gradle 9.0 but project uses 8.5

High Severity

Bumping gradle-maven-publish-plugin to 0.37.0 introduces incompatible minimum version requirements. The plugin now requires Gradle 9.0.0, Kotlin 2.2.0, and AGP 8.13.0, but the project uses Gradle 8.5 (gradle-wrapper.properties), Kotlin 2.1.20 (build.gradle), and AGP 8.3.2. This will break the build entirely since the included build-logic project cannot resolve or apply the plugin with these older toolchain versions.

Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit 8fc6e7e. Configure here.

@github-actions

github-actions Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

📦 SDK Size Impact Report

What the SDK adds to a minified release APK.

mParticle Core SDK

Measured against an empty baseline app. Unlike the Rokt kit, android-core ships no Compose and no resources, so there is nothing here that a host app would already provide.

Metric Target branch This PR Change
APK size 119.78 KB not measured not measured
Download size 117.60 KB not measured not measured
Dex bytes 213.75 KB not measured not measured

mParticle Core + Rokt kit

Measured against a Compose + Material3 reference app, so these are the costs on top of an app that already ships Compose. The reference app's dependencies are a documented convention, not a measured average: see size-report-rokt/README.md.

Metric Target branch This PR Change
APK size 1.26 MB not measured not measured
Download size 1.24 MB not measured not measured
Dex bytes 2.22 MB not measured not measured

Rokt SDK+ umbrella (adds the payment extension)

Metric Target branch This PR Change On top of mParticle Core + Rokt kit
APK size 6.53 MB not measured not measured not measured
Download size 6.43 MB not measured not measured not measured
Dex bytes 7.10 MB not measured not measured not measured

ℹ️ Size could not be measured on one or both branches.

Raw measurements

core, Target branch:

{"baseline_dex_bytes": 0, "baseline_download_bytes": 2511, "baseline_install_bytes": 7528, "core_dex_bytes": 218884, "core_download_bytes": 122937, "core_install_bytes": 130187}

core, This PR:

not measured

rokt, Target branch:

{"baseline_dex_bytes": 1829108, "baseline_download_bytes": 1240062, "baseline_install_bytes": 1300934, "kit_dex_bytes": 4156052, "kit_download_bytes": 2540333, "kit_install_bytes": 2623275, "sdkplus_dex_bytes": 9278708, "sdkplus_download_bytes": 7978466, "sdkplus_install_bytes": 8148975}

rokt, This PR:

not measured

Measured 9409f8f merged into 0cc27bc

@github-actions

github-actions Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

📦 SDK Size Impact Report

What the SDK adds to a minified release APK.

Measured against a Compose + Material3 reference app, so these are the costs on top of an app that already ships Compose. The reference app's dependencies are a documented convention, not a measured average: see size-report-rokt/README.md.

mParticle Core + Rokt kit

Metric Target branch This PR Change
APK size 1.26 MB not measured not measured
Download size 1.24 MB not measured not measured
Dex bytes 2.22 MB not measured not measured

Rokt SDK+ umbrella (adds the payment extension)

Metric Target branch This PR Change On top of mParticle Core + Rokt kit
APK size 6.53 MB not measured not measured not measured
Download size 6.43 MB not measured not measured not measured
Dex bytes 7.10 MB not measured not measured not measured

ℹ️ Size could not be measured on one or both branches.

Raw measurements

Target branch:

{"baseline_dex_bytes": 1829108, "baseline_download_bytes": 1240062, "baseline_install_bytes": 1300934, "kit_dex_bytes": 4156052, "kit_download_bytes": 2540334, "kit_install_bytes": 2623275, "sdkplus_dex_bytes": 9278708, "sdkplus_download_bytes": 7978466, "sdkplus_install_bytes": 8148975}

This PR:

not measured

Measured bc58a6f merged into a124f8b

@dependabot
dependabot Bot force-pushed the dependabot/gradle/gradle-cc84e3a6d9 branch 3 times, most recently from 98e7b96 to bc58a6f Compare October 7, 2026 19:57
@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown

Kotlin migration progress

No change to the Java left to convert.

Module Kotlin LOC Java LOC Java staying (facade) Java left to convert Kotlin share
android-core 3,238 22,515 9,636 12,879 12.6%
android-kit-base 557 5,380 1,651 3,729 9.4%
Total 3,795 27,895 11,287 16,608 12.0%

Conversion progress: 0.0% (16,608 of 16,550 baseline Java LOC left to convert). 132 Java files and 36 Kotlin files in scope.

@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown

Binary compatibility

⚠️ Could not complete the comparison: Command '['./gradlew', ':android-core:assembleRelease', ':android-kit-base:assembleRelease', '-PVERSION=6.1.5', '--console=plain', '-q']' returned non-zero exit status 1.. See the job log for details.

Bumps [com.vanniktech:gradle-maven-publish-plugin](https://github.com/vanniktech/gradle-maven-publish-plugin) in `/` from 0.31.0 to 0.37.0.


Updates `com.vanniktech:gradle-maven-publish-plugin` from 0.31.0 to 0.37.0
- [Release notes](https://github.com/vanniktech/gradle-maven-publish-plugin/releases)
- [Changelog](https://github.com/vanniktech/gradle-maven-publish-plugin/blob/main/CHANGELOG.md)
- [Commits](vanniktech/gradle-maven-publish-plugin@0.31.0...0.37.0)

---
updated-dependencies:
- dependency-name: com.vanniktech:gradle-maven-publish-plugin
  dependency-version: 0.37.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: shared-gradle-dependencies/com.vanniktech:gradle-maven-publish-plugin
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/gradle/gradle-cc84e3a6d9 branch from bc58a6f to 9409f8f Compare October 8, 2026 15:35
@thomson-t

Copy link
Copy Markdown
Collaborator

Not compatible

@thomson-t thomson-t closed this Oct 8, 2026
@dependabot @github

dependabot Bot commented on behalf of github Oct 8, 2026

Copy link
Copy Markdown
Contributor Author

This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.

To ignore these dependencies, configure ignore rules in dependabot.yml

@dependabot
dependabot Bot deleted the dependabot/gradle/gradle-cc84e3a6d9 branch October 8, 2026 18:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant