Skip to content

Remove Gradle dependency verification - #498

Merged
benjaminkomen merged 3 commits into
masterfrom
chore/remove-dependency-verification
Sep 29, 2026
Merged

benjaminkomen merged 3 commits into
masterfrom
chore/remove-dependency-verification

Conversation

@benjaminkomen

@benjaminkomen benjaminkomen commented Sep 29, 2026 •

Copy link
Copy Markdown
Owner

Summary

Gradle dependency verification (gradle/verification-metadata.xml) made every Dependabot Gradle bump fail CI (Build, Docker boot, API regression, and Cloud Build) until someone regenerated checksums by hand (#486–#490, now #493/#494). Per Benjamin (2026-09-29), remove it:

  • Delete gradle/verification-metadata.xml (no gradle.properties / settings.gradle.kts settings referenced it).
  • Remove the refresh-command comment from build.gradle.kts and the "Dependabot / dependency bumps" section added to AGENTS.md in Document Dependabot verification-metadata refresh #492.
  • Ignore SonarCloud rule kotlin:S6474 via sonar.issue.ignore.multicriteria in build.gradle.kts (covers the in-file disableDependencyVerification variant).

Known: one project-level S6474 issue

SonarCloud still raises one project-level kotlin:S6474 ("verification-metadata.xml is missing"). It isn't tied to a file, so the file-pattern ignore can't match it. sonar-kotlin's KotlinGradleSensor raises it whenever sonar.kotlin.gradleProjectRoot equals the base dir, and the Sonar Gradle plugin overwrites any user value for that property (tried and reverted). This fails the Sonar quality gate (new security rating B) on the Build job only. To clear it, Accept the issue once in SonarCloud (Issues → kotlin:S6474 → Accept). Per Benjamin, accepting it is fine.

Test plan

  • ./gradlew ktlintCheck jacocoTestReport bootJar green locally with no metadata file
  • CI: Docker boot, API regression, and Cloud Build green. Build is red only on the Sonar gate for the project-level S6474 above

Benjamin Komen added 3 commits September 29, 2026 09:15
verification-metadata.xml made every Dependabot version bump fail CI until
checksums were regenerated by hand. Drop the file, the refresh-command
comments, and the AGENTS.md section from #492, and ignore Sonar rule
kotlin:S6474 (dependency verification) project-wide.
@benjaminkomen
benjaminkomen merged commit 329958e into master Sep 29, 2026
3 of 4 checks passed
@benjaminkomen
benjaminkomen deleted the chore/remove-dependency-verification branch September 29, 2026 16:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant