Update dependency gradle to v7.6.3
This MR contains the following updates:
Package | Update | Change |
---|---|---|
gradle (source) | patch |
7.6 -> 7.6.3
|
Release Notes
gradle/gradle (gradle)
v7.6.3
: 7.6.3
This is a patch release for 7.6. We recommend using 7.6.3 instead of 7.6.
This release addresses two security vulnerabilities:
- Incorrect permission assignment for symlinked files used in copy or archiving operations
- Possible local text file exfiltration by XML External entity injection
It also fixes the following issues:
Upgrade Instructions
Switch your build to use Gradle 7.6.3 by updating your wrapper:
./gradlew wrapper --gradle-version=7.6.3
See the Gradle 7.x upgrade guide to learn about deprecations, breaking changes and other considerations when upgrading to Gradle 7.6.3.
Reporting Problems
If you find a problem with this release, please file a bug on GitHub Issues adhering to our issue guidelines. If you're not sure you're encountering a bug, please use the forum.
v7.6.2
: 7.6.2
This is a patch release for 7.6. We recommend using 7.6.2 instead of 7.6.
This release addresses two security vulnerabilities:
It also fixes the following issues:
- #23201 Backport dependency upgrades to 7.x
- #23202 Backport Scala incremental compilation fixes
- #23325 Backport JSoup update to resolve CVE-2022-36033
- #23458 Backport JUnit5 dynamic test logging bug fix
- #23681 Dependency graph resolution: Equivalent excludes can cause un-necessary graph mutations [backport 7.x]
- #23922 Backport "Use Compiler API data for incremental compilation after a failure" to 7.x
- #23951 Exclude rule merging: missing optimization [Backport 7.x]
- #24132 Extending an already resolved configuration no longer works correctly [backport 7.x]
- #24234 7.6.1 breaks gradle-consistent-versions
- #24390 Gradle 7.4 fails on multi release jar's with JDK 19 code
- #24439 Gradle complains about invalid tool chain - picking up the source package location - it should just ignore them [Backport]
- #24443 Maven artifact referenced only in dependency constraints raises IllegalStateException: Corrupt serialized resolution result [backport]
- #24901 Backport fix for test exception that cannot be deserialized to 7.x
Upgrade Instructions
Switch your build to use Gradle 7.6.2 by updating your wrapper:
./gradlew wrapper --gradle-version=7.6.2
See the Gradle 7.x upgrade guide to learn about deprecations, breaking changes and other considerations when upgrading to Gradle 7.6.2.
Reporting Problems
If you find a problem with this release, please file a bug on GitHub Issues adhering to our issue guidelines. If you're not sure you're encountering a bug, please use the forum.
v7.6.1
: 7.6.1
This is a patch release for 7.6. We recommend using 7.6.1 instead of 7.6.
It fixes the following issues:
- #19065 Platform dependencies not possible in dependency block of test suite plugin
- #22688 Increased memory usage (with -p option)
-
#22796 Building gradle itself fails during toolchain download: permission denied copying a file within
.gradle/jdks
- #22875 Regression with 7.6: @pom artifact in JVM library project is no longer found
- #22937 Remove safe credentials reference
- #22973 Kotlin MPP plugin broken with Gradle 7.6 due to signature change in TestResultProcessor
- #23016 toolchainManagement.jvm.javaRepositories should not expose the full surface of NamedDomainObjectList
- #23025 Back-port toolchain related fixes to 7.6.1
- #23053 Auto-provisioning/auto-detection of IBM Semeru toolchains is broken with Gradle 7.6
- #23074 Docs: Build Lifecycle starts halfway through a point
- #23096 Classifiers of version catalog are discarded while copied to anothor dependency
- #23111 Ant closures are broken with Gradle 7.6
- #23178 Mention the Foojay Toolchain Resolver plugin in the Gradle manual
- #23215 Gradle 7.6: high memory usage (android project)
- #23224 Backport to 7.6.1 "Fix for Incremental compilation with modules"
- #23294 "Unable to make progress running work" together with --continue and failing tasks (Backport to 7.6.1)
- #23555 Improve Toolchain related deprecation nagging in 7.6
- #23894 Update EOL policy
- #23910 Backport trusting only full GPG keys in dependency verification [Backport 7.6.1]
- #23941 Typo in v7.6 docs about disabling_the_daemon
- #23985 Resolving of manually created configuration creates a ResolveException
Upgrade Instructions
Switch your build to use Gradle 7.6.1 by updating your wrapper:
./gradlew wrapper --gradle-version=7.6.1
See the Gradle 7.x upgrade guide to learn about deprecations, breaking changes and other considerations when upgrading to Gradle 7.6.1.
Reporting Problems
If you find a problem with this release, please file a bug on GitHub Issues adhering to our issue guidelines. If you're not sure you're encountering a bug, please use the forum.
Configuration
-
If you want to rebase/retry this MR, check this box
This MR has been generated by Renovate Bot.