Skip to content

Add sk.ainet.maven-pins convention plugin - #1048

Merged
michalharakal merged 2 commits into
developfrom
fix/1046-high-severity-cve-transitive-deps
Aug 22, 2026
Merged

michalharakal merged 2 commits into
developfrom
fix/1046-high-severity-cve-transitive-deps

Conversation

@michalharakal

Copy link
Copy Markdown
Contributor

Summary

  • Adds sk.ainet.maven-pins, mirroring the existing sk.ainet.npm-pins mechanism for the JVM/Maven dependency graph: skainet { mavenPins { pin("group:artifact", version) } }, sourced from the version catalog, force-applied via resolutionStrategy across every subproject.
  • Adds verifyMavenPins (wired into check), registered per subproject, which walks the live resolved dependency graph and fails if a declared pin stops resolving to its pinned version.
  • No pins declared yet — see below.

Background

Investigated using this to close #1046's 22 high-severity Dependabot alerts. Turned out none of the 8 flagged packages are reachable through the app's own dependency graph: jose4j/jdom2 are transitive to the Android Gradle Plugin's own plugin classpath, jackson-core/jackson-databind to Dokka's, and Netty wasn't reproducible in the current graph at all. Gradle resolves plugin/buildscript classpaths before any project's configurations exist, so resolutionStrategy — and therefore this plugin — structurally cannot reach them.

Since none of those packages are present in anything SKaiNET publishes to Maven Central (build-time-only tooling dependencies, never shipped to consumers), all 22 alerts were dismissed with reason tolerable_risk rather than chasing an AGP/Dokka version bump for exposure that's effectively nil. Full writeup in #1046 (closed).

This PR keeps the sk.ainet.maven-pins infrastructure itself — it's real, tested, and ready for the next time a high-severity CVE is a genuine transitive dependency of the app's own dependency graph.

Refs #1046

Test plan

  • ./gradlew :build-logic:convention:compileKotlin passes
  • ./gradlew verifyMavenPins runs cleanly across all 46 subprojects with zero pins declared ("No maven pins declared; nothing to verify.")
  • Root project configures successfully with the plugin applied

🤖 Generated with Claude Code

Mirrors sk.ainet.npm-pins for the JVM/Maven dependency graph: force-pins an
exact "group:artifact" coordinate to an audited version via
`skainet { mavenPins { pin(...) } }`, sourced from the version catalog, and
verifies it with a per-subproject `verifyMavenPins` task (wired into `check`)
that walks the live resolved dependency graph rather than a lockfile.

No pins declared yet. Investigated using it to close issue #1046's 22
high-severity Dependabot alerts, but none of the 8 flagged packages are
reachable this way: jose4j/jdom2 are transitive to the Android Gradle
Plugin's own plugin classpath, jackson-core/jackson-databind to Dokka's, and
Netty isn't reproducible in the current graph at all (likely stale). Gradle
resolves plugin/buildscript classpaths before any project's `configurations`
exist, which `resolutionStrategy` — and so this plugin — cannot reach.
Details in the issue.

Fixing those needs an AGP/Dokka version bump instead, tracked as follow-up
in #1046.

Co-Authored-By: Claude <noreply@anthropic.com>
Adds a "Pinning Maven/JVM Dependencies" section to the build-from-source
guide, mirroring the existing npm-pins one, including what it structurally
cannot fix (a Gradle plugin's own classpath) — the reason issue #1046's 22
alerts were dismissed rather than pinned. Cross-references both mechanisms
from SECURITY.md's dependency-CVE-handling guidance.

Co-Authored-By: Claude <noreply@anthropic.com>
@github-actions

Copy link
Copy Markdown

📖 Documentation Preview

The documentation has been built successfully for this PR.

Generated Files:

  • Operator documentation: docs/modules/operators/_generated_/
  • JSON schema output: operators.json

Artifacts:

  • Download the documentation-preview-1048 artifact to view the complete documentation locally.

This comment will be updated automatically when the PR is updated.

@michalharakal
michalharakal merged commit 013856d into develop Aug 22, 2026
15 checks passed
@michalharakal
michalharakal deleted the fix/1046-high-severity-cve-transitive-deps branch August 22, 2026 18:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Dependabot alerts triage: 22 high-severity alerts dismissed (build-time-only), sk.ainet.maven-pins added

2 participants