Add sk.ainet.maven-pins convention plugin - #1048
Merged
michalharakal merged 2 commits intoAug 22, 2026
Merged
Conversation
Mirrors sk.ainet.npm-pins for the JVM/Maven dependency graph: force-pins an
exact "group:artifact" coordinate to an audited version via
`skainet { mavenPins { pin(...) } }`, sourced from the version catalog, and
verifies it with a per-subproject `verifyMavenPins` task (wired into `check`)
that walks the live resolved dependency graph rather than a lockfile.
No pins declared yet. Investigated using it to close issue #1046's 22
high-severity Dependabot alerts, but none of the 8 flagged packages are
reachable this way: jose4j/jdom2 are transitive to the Android Gradle
Plugin's own plugin classpath, jackson-core/jackson-databind to Dokka's, and
Netty isn't reproducible in the current graph at all (likely stale). Gradle
resolves plugin/buildscript classpaths before any project's `configurations`
exist, which `resolutionStrategy` — and so this plugin — cannot reach.
Details in the issue.
Fixing those needs an AGP/Dokka version bump instead, tracked as follow-up
in #1046.
Co-Authored-By: Claude <noreply@anthropic.com>
Adds a "Pinning Maven/JVM Dependencies" section to the build-from-source guide, mirroring the existing npm-pins one, including what it structurally cannot fix (a Gradle plugin's own classpath) — the reason issue #1046's 22 alerts were dismissed rather than pinned. Cross-references both mechanisms from SECURITY.md's dependency-CVE-handling guidance. Co-Authored-By: Claude <noreply@anthropic.com>
|
📖 Documentation Preview The documentation has been built successfully for this PR. Generated Files:
Artifacts:
This comment will be updated automatically when the PR is updated. |
aharakal
approved these changes
Aug 22, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
sk.ainet.maven-pins, mirroring the existingsk.ainet.npm-pinsmechanism for the JVM/Maven dependency graph:skainet { mavenPins { pin("group:artifact", version) } }, sourced from the version catalog, force-applied viaresolutionStrategyacross every subproject.verifyMavenPins(wired intocheck), registered per subproject, which walks the live resolved dependency graph and fails if a declared pin stops resolving to its pinned version.Background
Investigated using this to close #1046's 22 high-severity Dependabot alerts. Turned out none of the 8 flagged packages are reachable through the app's own dependency graph:
jose4j/jdom2are transitive to the Android Gradle Plugin's own plugin classpath,jackson-core/jackson-databindto Dokka's, and Netty wasn't reproducible in the current graph at all. Gradle resolves plugin/buildscript classpaths before any project'sconfigurationsexist, soresolutionStrategy— and therefore this plugin — structurally cannot reach them.Since none of those packages are present in anything SKaiNET publishes to Maven Central (build-time-only tooling dependencies, never shipped to consumers), all 22 alerts were dismissed with reason
tolerable_riskrather than chasing an AGP/Dokka version bump for exposure that's effectively nil. Full writeup in #1046 (closed).This PR keeps the
sk.ainet.maven-pinsinfrastructure itself — it's real, tested, and ready for the next time a high-severity CVE is a genuine transitive dependency of the app's own dependency graph.Refs #1046
Test plan
./gradlew :build-logic:convention:compileKotlinpasses./gradlew verifyMavenPinsruns cleanly across all 46 subprojects with zero pins declared ("No maven pins declared; nothing to verify.")🤖 Generated with Claude Code