Skip to content

[Backport 2.19] Bump com.diffplug.spotless to 8.10.1 - #22880

Open
andrross wants to merge 2 commits into
opensearch-project:2.19from
andrross:bump-spotless-2.19
Open

[Backport 2.19] Bump com.diffplug.spotless to 8.10.1#22880
andrross wants to merge 2 commits into
opensearch-project:2.19from
andrross:bump-spotless-2.19

Conversation

@andrross

Copy link
Copy Markdown
Member

Check List

  • Functionality includes testing.

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.
For more information on following Developer Certificate of Origin and signing off your commits, please check here.

Signed-off-by: Andrew Ross <andrross@amazon.com>
@andrross
andrross requested a review from a team as a code owner August 29, 2026 20:33
@andrross andrross changed the title Bump com.diffplug.spotless to 8.10.1 [Backport 2.19] Bump com.diffplug.spotless to 8.10.1 Aug 29, 2026
@andrross andrross added the skip-diff-analyzer Maintainer to skip code-diff-analyzer check, after reviewing issues in AI analysis. label Aug 29, 2026
@github-actions

Copy link
Copy Markdown
Contributor

PR Code Analyzer ❗

AI-powered 'Code-Diff-Analyzer' found issues on commit 8649a7d.

Hard block: Issues at Medium severity or above will block this PR from merging.

PathLineSeverityDescription
build.gradle57highBuild plugin version change: com.diffplug.spotless bumped from 6.25.0 to 8.10.1 (major version jump). Per mandatory supply chain policy, build plugin changes must be flagged regardless of apparent legitimacy — maintainers should verify the artifact at the new version is authentic and not a namespace-hijacked or typosquatted package.

The table above displays the top 10 most important findings.

Total: 1 | Critical: 0 | High: 1 | Medium: 0 | Low: 0


Pull Requests Author(s): Please update your Pull Request according to the report above.

Repository Maintainer(s): You can bypass diff analyzer by adding label skip-diff-analyzer after reviewing the changes carefully, then re-run failed actions. To re-enable the analyzer, remove the label, then re-run all actions.


⚠️ Note: The Code-Diff-Analyzer helps protect against potentially harmful code patterns. Please ensure you have thoroughly reviewed the changes beforehand.

Thanks.

@github-actions

Copy link
Copy Markdown
Contributor

❌ Gradle check result for 8649a7d: FAILURE

Please examine the workflow log, locate, and copy-paste the failure(s) below, then iterate to green. Is the failure a flaky test unrelated to your change?

Signed-off-by: Andrew Ross <andrross@amazon.com>
@github-actions

Copy link
Copy Markdown
Contributor

PR Reviewer Guide 🔍

Here are some key observations to aid the review process:

🧪 No relevant tests
🔒 No security concerns identified
✅ No TODO sections
🔀 No multiple PR themes
⚡ No major issues detected

@github-actions

Copy link
Copy Markdown
Contributor

✅ Gradle check result for 30a1550: SUCCESS

@codecov

codecov Bot commented Aug 29, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 72.07%. Comparing base (aff3489) to head (30a1550).
⚠️ Report is 27 commits behind head on 2.19.

Additional details and impacted files
@@             Coverage Diff              @@
##               2.19   #22880      +/-   ##
============================================
+ Coverage     71.92%   72.07%   +0.14%     
+ Complexity    66009    64490    -1519     
============================================
  Files          5342     5103     -239     
  Lines        307392   299843    -7549     
  Branches      44862    44077     -785     
============================================
- Hits         221105   216121    -4984     
+ Misses        67823    65576    -2247     
+ Partials      18464    18146     -318     

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

skip-changelog skip-diff-analyzer Maintainer to skip code-diff-analyzer check, after reviewing issues in AI analysis.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant