Skip to content

build: add nebula.release versioning and dependency locking - #68

Merged
Cervator merged 4 commits into
masterfrom
feat/nebula-versioning-and-lockfile
Oct 1, 2026
Merged

Cervator merged 4 commits into
masterfrom
feat/nebula-versioning-and-lockfile

Conversation

@soloturn

Copy link
Copy Markdown
Contributor

Adds the same versioning/locking setup TerasologyLauncher already uses.

  • nebula.release 21.0.0 for git-tag-driven versioning. This project already tags releases as vX.Y.Z (v5.1.0 latest), matching the plugin's default tag convention, so no extra tagStrategy config is needed.
  • Buildscript-classpath dependency locking (activateDependencyLocking() on the buildscript classpath), producing buildscript-gradle.lockfile.
  • dependencyLocking { lockAllConfigurations() } on every subproject (cr-core, cr-destsol, cr-terasology), each with its own gradle.lockfile — locking is per-project, so a single shared lockfile isn't how Gradle does this for a multi-project build. The root project has no resolvable configurations of its own beyond buildscript, so it only gets the buildscript lockfile.
  • Same -PnoLock escape hatch as the launcher: passing it skips dependencyLocking{} entirely for that build, letting every range resolve fresh against whatever satisfies it right now — useful for trying an update locally before committing to it via --write-locks.

Test plan:

  • ./gradlew build -x test succeeds with locking active
  • Lockfiles generated via ./gradlew dependencies --write-locks (root) and ./gradlew :cr-core:dependencies :cr-destsol:dependencies :cr-terasology:dependencies --write-locks (subprojects)

@coderabbitai

coderabbitai Bot commented Aug 22, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: a510e6ed-e31c-4e1f-b456-4c913bdaeac9

📥 Commits

Reviewing files that changed from the base of the PR and between f970ad1 and 11f5ff3.

📒 Files selected for processing (6)
  • .gitattributes
  • build.gradle.kts
  • buildscript-gradle.lockfile
  • cr-core/gradle.lockfile
  • cr-destsol/gradle.lockfile
  • cr-terasology/gradle.lockfile

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Summary

Summary by CodeRabbit

  • Chores
    • Builds now use locked dependency versions across the project, helping keep dependency resolution consistent between environments.
    • Lockfile text uses consistent LF line endings, including when updated from Windows clones.

Walkthrough

The build now enables dependency locking for the buildscript classpath and conditionally for resolvable subproject configurations. New lockfiles record dependency versions and empty configurations. Lockfile files use LF line endings.

Changes

Dependency Locking

Layer / File(s) Summary
Enable dependency locking
build.gradle.kts, buildscript-gradle.lockfile
The build enables locking for the buildscript classpath. Unless noLock is set, it also enables locking for resolvable configurations in subprojects.
Record locked dependency states
cr-core/gradle.lockfile, cr-destsol/gradle.lockfile, cr-terasology/gradle.lockfile, .gitattributes
The project lockfiles record dependency versions and empty configurations. .gitattributes sets LF line endings for *.lockfile files.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~12 minutes

Change: Other

Merge Risk: ⚪ Minimal · up to 11f5f

No actionable merge-blocking behavior is established in the reviewed changes.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 11f5f

Default dependency locking constrains version drift without introducing a demonstrated increase in execution or publication privileges. No introduced security defect was established. Release-build enforcement and interrupted or concurrent lock refresh remain unverified, so the assessment retains limited uncertainty.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The affected security scope is dependency selection for build tooling and application artifacts across the three modules. A changed core dependency selection can propagate into both adapter modules through their existing project dependencies; lockfiles alone do not establish any new application caller or publication privilege.

Trust Boundaries and Controls

  • observed — Existing publication configuration selects an Artifactory destination using project properties or environment input and optionally uses mavenUser and mavenPass credentials. That shared publication configuration is unchanged in the inspected comparison; dependency locking does not introduce those authorities.
  • inferred — Default locking constrains dependency-version drift, but a build invoker can bypass the new subproject control by supplying noLock. This is an explicit opt-out from a newly added control, not an observed weakening of the previously unlocked baseline.

Hardening Proposals

  • proposed — As an optional operational safeguard, separate noLock experimentation from privileged publication builds and review coordinated lockfile refreshes before publication. This is a proposal, not evidence that current release workflows permit an unsafe bypass.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title identifies dependency locking, which is the main implemented change. It also mentions nebula.release versioning, which the objectives state was later dropped.
Description check ✅ Passed The description directly addresses dependency locking, lockfile generation, and the noLock escape hatch. It also contains stale information about nebula.release, but it remains related to the changese…
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 1…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.

Warning

Some tools did not complete. Review the errors below.

🔧 OSV Scanner (2.6.0)
buildscript-gradle.lockfile

OSV Scanner exited with code 128 without a usable report


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

A rabbit checks the locks at dawn,
Each version tucked where it belongs.
LF lines keep their steady track,
The build can find its way back.
Soft paws close the ledger tight.

Comment @coderabbitai help to get the list of available commands.

@soloturn
soloturn force-pushed the feat/nebula-versioning-and-lockfile branch from 4ae7c93 to c305ae6 Compare August 26, 2026 19:00
soloturn added a commit that referenced this pull request Aug 27, 2026
#68's lockfile predates #58's new deps (jackson, org.json). Full build green after.

Co-Authored-By: soloturn <soloturn@gmail.com>
@agent-refr

Copy link
Copy Markdown

Agent-authored comment — @Cervator via GDD.

#72 targets this branch and proposes keeping the dependency locking while dropping nebula.release, with the reasoning in its description: the community's Maven-published repos all version from a hand-edited SNAPSHOT that Jenkins publishes, and nebula would change what master publishes. If that lands here, this PR still needs a rebase onto master and --write-locks to pick up #70's Jackson dependencies; happy to do that part.

soloturn and others added 4 commits September 30, 2026 10:41
Terasology, gestalt and this repo all version from a hand-edited SNAPSHOT string that Jenkins publishes from long-lived branches. nebula.release would make CrashReporter the one Maven-published repo versioned from git tags, and a plain `publish` on master would ship `5.2.0-dev.N+sha` in place of today's `5.2.0-SNAPSHOT`. Locking stands on its own.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Jenkins PR-68 #7 failed lock verification on `jackson-bom`, `jackson-core`, `jackson-databind`, `jackson-annotations` once master carried #70. Rebased onto master, then `./gradlew dependencies --write-locks` per project.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Seen on a Windows clone with `core.autocrlf=true`: every `--write-locks` left `buildscript-gradle.lockfile` flagged modified with an empty diff, because Gradle emits LF and Git expected CRLF.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@Cervator
Cervator force-pushed the feat/nebula-versioning-and-lockfile branch from 84ef6e5 to 11f5ff3 Compare September 30, 2026 18:14
@Cervator
Cervator requested a balanced review from Copilot October 1, 2026 00:49

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The advertised nebula.release plugin is not applied, leaving tag-driven versioning unavailable.

Review effort: Balanced
Findings: None

What changed in this PR

Adds dependency locking and intends to introduce tag-driven release versioning.

Changes:

  • Enables dependency locking for buildscript and subprojects.
  • Adds generated lockfiles and a -PnoLock escape hatch.
  • Enforces LF endings for lockfiles.
File Description
build.gradle.kts Configures dependency locking.
buildscript-gradle.lockfile Locks buildscript dependencies.
cr-core/​gradle.lockfile Locks core dependencies.
cr-destsol/​gradle.lockfile Locks Destination Sol dependencies.
cr-terasology/​gradle.lockfile Locks Terasology dependencies.
.gitattributes Enforces LF lockfiles.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@Cervator Cervator left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Last copilot comment argues about the title of the PR after a pivot to just doing locking. Seems fine for that part.

@Cervator
Cervator merged commit 057e4d0 into master Oct 1, 2026
7 checks passed
@Cervator
Cervator deleted the feat/nebula-versioning-and-lockfile branch October 1, 2026 01:31
Cervator added a commit that referenced this pull request Oct 1, 2026
Master now locks dependencies (#68); this PR's `org.json:json` was not in the lock state, so the merged build would fail the same way PR-68 #7 did.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
soloturn pushed a commit that referenced this pull request Oct 7, 2026
Master now locks dependencies (#68); this PR's `org.json:json` was not in the lock state, so the merged build would fail the same way PR-68 #7 did.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants