Skip to content

build(deps): bump gradle/actions/setup-gradle from 5.0.2 to 6.3.0 - #932

Merged
dpiet-oai merged 4 commits into
mainfrom
dependabot/github_actions/gradle/actions/setup-gradle-6.3.0
Sep 24, 2026
Merged

dpiet-oai merged 4 commits into
mainfrom
dependabot/github_actions/gradle/actions/setup-gradle-6.3.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 24, 2026 •

Copy link
Copy Markdown
Contributor

Bumps gradle/actions/setup-gradle from 5.0.2 to 6.3.0.

Release notes

Sourced from gradle/actions/setup-gradle's releases.

v6.3.0

Highlights

Enhanced Caching: Windows fixes and a cache-protocol bump

This release updates gradle-actions-caching to v1.0.0 (up from v0.7.0), which fixes two significant caching defects, both most visible on Windows:

  • Cache entries failed to store at all on Windows.. Every entry failed with Path Validation Error: Path(s) specified in the action for caching do(es) not exist, even though the Gradle User Home was fully intact. Nothing was stored, so every downstream job ran against an empty Gradle User Home. The cause was a nested, unpatched copy of @actions/glob combined with a silently swallowed require() in the bundle, which left Windows path separators unnormalized.

  • Cache cleanup deleted instrumented jars that were in use. A bug in key hashing for paths shorter than 64 characters made cleanup judge freshly created caches/jars-9 entries as unused and remove them, so the instrumented-jars entry was never saved and every job re-instrumented its classpaths.

    Also included: cache entry names are now consistent between the save and restore reports — restore previously fell back to showing the raw glob pattern (e.g. /home/runner/.gradle/caches/modules-*/files-*/*/*/*/*/) instead of dependencies.

[!IMPORTANT] Existing cache entries are invalidated by this release. The cache protocol version was bumped to v2, so the first run after upgrading will be a cache miss and will repopulate the cache. No configuration changes are required.

Basic caching warns instead of failing silently

The basic (open-source) caching provider now emits a warning and reports (Entry not saved: save failed) in the Job Summary when a cache save fails, rather than reporting success (#1028).

Dependency submission works with Isolated Projects

dependency-submission now disables Isolated Projects via a promoted property, so dependency graph generation works on builds that enable it (#1025). Thanks to @​reinsch82 for the contribution.

Updated defaults

  • Injected Develocity Gradle plugin: 4.4.2 → 4.5.0
  • 36 new known-good wrapper checksums added for wrapper-validation

What's Changed

... (truncated)

Commits
  • 9c97196 Bump the github-actions group across 2 directories with 9 updates (#1024)
  • 760e4a4 Bump the npm-dependencies group across 1 directory with 2 updates (#1037)
  • 73e4c42 Update gradle-actions-caching library to v1.0.0 (#1029)
  • a9d1438 Add dependabot ignore rules for TypeScript 7.x and @​types/node 25.x/26.x
  • 68f3700 [bot] Update dist directory
  • 5971332 Bump Gradle Wrapper to 9.6.1, wrapper checksums, and Develocity plugin to 4.5...
  • b5bc804 [bot] Update dist directory
  • dcbab4e Bump npm-dependencies group with TypeScript 6.0.3, @​types/node 24.x, and secu...
  • ca8d957 Move non-smoke restore-gradle-home tests back to the integ-test suite (#1032)
  • 4318659 [bot] Update dist directory
  • Additional commits viewable in compare view

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Aug 24, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner August 24, 2026 09:38
@dependabot dependabot Bot added the github_actions Pull requests that update GitHub Actions code label Aug 24, 2026
@openai-sdks

openai-sdks Bot commented Aug 24, 2026 •

Copy link
Copy Markdown
Contributor

OkTest Summary

✅ 236/236 SDK tests passed in 17.765s for Java SDK PR #932.

Test results — 42 files
Test Result Time
tests/chat-completions-complex-body.test.ts ✅ Passed 576ms
tests/chat-completions-create.test.ts ✅ Passed 655ms
tests/chat-completions-stream.test.ts ✅ Passed 698ms
tests/files-content-binary.test.ts ✅ Passed 276ms
tests/files-create-multipart.test.ts ✅ Passed 337ms
tests/files-list-pagination.test.ts ✅ Passed 305ms
tests/initialize-config.test.ts ✅ Passed 222ms
tests/instance-isolation.test.ts ✅ Passed 212ms
tests/models-list.test.ts ✅ Passed 237ms
tests/responses-background-lifecycle.test.ts ✅ Passed 852ms
tests/responses-body-method-errors.test.ts ✅ Passed 547ms
tests/responses-cancel-timeout.test.ts ✅ Passed 281ms
tests/responses-cancel.test.ts ✅ Passed 367ms
tests/responses-compact-retries.test.ts ✅ Passed 615ms
tests/responses-compact.test.ts ✅ Passed 315ms
tests/responses-create-advanced-stream.test.ts ✅ Passed 466ms
tests/responses-create-advanced.test.ts ✅ Passed 1.554s
tests/responses-create-disconnect.test.ts ✅ Passed 1.145s
tests/responses-create-errors.test.ts ✅ Passed 337ms
tests/responses-create-malformed-api-responses.test.ts ✅ Passed 226ms
tests/responses-create-retries.test.ts ✅ Passed 317ms
tests/responses-create-stream-failures.test.ts ✅ Passed 295ms
tests/responses-create-stream-timeout.test.ts ✅ Passed 282ms
tests/responses-create-stream-wire.test.ts ✅ Passed 6.575s
tests/responses-create-stream.test.ts ✅ Passed 586ms
tests/responses-create-terminal-states.test.ts ✅ Passed 430ms
tests/responses-create-timeout.test.ts ✅ Passed 313ms
tests/responses-create.test.ts ✅ Passed 280ms
tests/responses-delete.test.ts ✅ Passed 286ms
tests/responses-input-items-errors.test.ts ✅ Passed 281ms
tests/responses-input-items-list.test.ts ✅ Passed 299ms
tests/responses-input-items-options.test.ts ✅ Passed 517ms
tests/responses-input-tokens-count-timeout.test.ts ✅ Passed 223ms
tests/responses-input-tokens-count.test.ts ✅ Passed 376ms
tests/responses-malformed-inputs.test.ts ✅ Passed 5.418s
tests/responses-not-found-errors.test.ts ✅ Passed 530ms
tests/responses-parse.test.ts ✅ Passed 970ms
tests/responses-retrieve-retries.test.ts ✅ Passed 282ms
tests/responses-retrieve.test.ts ✅ Passed 275ms
tests/responses-stored-method-errors.test.ts ✅ Passed 989ms
tests/retry-behavior.test.ts ✅ Passed 3.354s
tests/sdk-error-shape.test.ts ✅ Passed 408ms

View OkTest run #35931550535

SDK merge (9e475d9232e8) · head (ffe9b8fee23e) · base (82440c9c05a0) · OkTest (a0be4375e02d)

@github-actions

github-actions Bot commented Aug 24, 2026 •

Copy link
Copy Markdown
Contributor

Castiron custom code

✅ No new custom-code files detected.

87 mixed files remain; 0 existing customizations changed.

Compared 82440c9c05a0 → ffe9b8fee23e. Generated baselines verified.

87 existing customizations unchanged
  • openai-java-core/src/main/kotlin/com/openai/models/audio/AudioResponseFormat.kt
  • openai-java-core/src/main/kotlin/com/openai/models/beta/agents/vaults/credentials/CredentialAuth.kt
  • openai-java-core/src/main/kotlin/com/openai/models/beta/agents/vaults/credentials/CredentialAuthCreateParam.kt
  • openai-java-core/src/main/kotlin/com/openai/models/beta/agents/vaults/credentials/CredentialAuthRotateParam.kt
  • openai-java-core/src/main/kotlin/com/openai/models/beta/responses/BetaResponseStreamEvent.kt
  • openai-java-core/src/main/kotlin/com/openai/models/beta/responses/BetaResponsesServerEvent.kt
  • openai-java-core/src/main/kotlin/com/openai/models/chat/completions/ChatCompletionCreateParams.kt
  • openai-java-core/src/main/kotlin/com/openai/models/chat/completions/ChatCompletionMessageFunctionToolCall.kt
  • openai-java-core/src/main/kotlin/com/openai/models/chat/completions/ChatCompletionToolMessageParam.kt
  • openai-java-core/src/main/kotlin/com/openai/models/embeddings/Embedding.kt
  • openai-java-core/src/main/kotlin/com/openai/models/embeddings/EmbeddingCreateParams.kt
  • openai-java-core/src/main/kotlin/com/openai/models/responses/ResponseCreateParams.kt
  • openai-java-core/src/main/kotlin/com/openai/models/responses/ResponseFunctionToolCall.kt
  • openai-java-core/src/main/kotlin/com/openai/models/responses/ResponseFunctionWebSearch.kt
  • openai-java-core/src/main/kotlin/com/openai/models/responses/ResponseInputItem.kt
  • openai-java-core/src/main/kotlin/com/openai/models/responses/ResponseStreamEvent.kt
  • openai-java-core/src/main/kotlin/com/openai/models/responses/ResponseTextConfig.kt
  • openai-java-core/src/main/kotlin/com/openai/models/responses/ResponsesServerEvent.kt
  • openai-java-core/src/main/kotlin/com/openai/models/videos/Video.kt
  • openai-java-core/src/main/kotlin/com/openai/models/webhooks/UnwrapWebhookEvent.kt
  • openai-java-core/src/main/kotlin/com/openai/models/webhooks/WebhookEndpointWithSecret.kt
  • openai-java-core/src/main/kotlin/com/openai/services/async/BetaServiceAsync.kt
  • openai-java-core/src/main/kotlin/com/openai/services/async/BetaServiceAsyncImpl.kt
  • openai-java-core/src/main/kotlin/com/openai/services/async/ImageServiceAsyncImpl.kt
  • openai-java-core/src/main/kotlin/com/openai/services/async/ResponseServiceAsync.kt
  • openai-java-core/src/main/kotlin/com/openai/services/async/ResponseServiceAsyncImpl.kt
  • openai-java-core/src/main/kotlin/com/openai/services/async/SkillServiceAsyncImpl.kt
  • openai-java-core/src/main/kotlin/com/openai/services/async/VideoServiceAsyncImpl.kt
  • openai-java-core/src/main/kotlin/com/openai/services/async/WebhookServiceAsync.kt
  • openai-java-core/src/main/kotlin/com/openai/services/async/WebhookServiceAsyncImpl.kt
  • openai-java-core/src/main/kotlin/com/openai/services/async/audio/TranscriptionServiceAsyncImpl.kt
  • openai-java-core/src/main/kotlin/com/openai/services/async/beta/agents/SessionServiceAsync.kt
  • openai-java-core/src/main/kotlin/com/openai/services/async/beta/agents/SessionServiceAsyncImpl.kt
  • openai-java-core/src/main/kotlin/com/openai/services/async/chat/ChatCompletionServiceAsync.kt
  • openai-java-core/src/main/kotlin/com/openai/services/async/finetuning/checkpoints/PermissionServiceAsyncImpl.kt
  • openai-java-core/src/main/kotlin/com/openai/services/async/skills/VersionServiceAsyncImpl.kt
  • openai-java-core/src/main/kotlin/com/openai/services/blocking/BetaService.kt
  • openai-java-core/src/main/kotlin/com/openai/services/blocking/BetaServiceImpl.kt
  • openai-java-core/src/main/kotlin/com/openai/services/blocking/ResponseService.kt
  • openai-java-core/src/main/kotlin/com/openai/services/blocking/ResponseServiceImpl.kt

47 more in the full report.

A changed generated baseline means this report cannot reliably identify which handwritten lines changed.

Inspect the custom-code diff

Download the exact patch produced by this run (requires repository access):

gh run download 35931582759 --repo openai/openai-java \
  --name castiron-custom-code-35931582759-1 --dir /tmp/castiron-custom-code-35931582759-1
git apply --stat /tmp/castiron-custom-code-35931582759-1/custom-code.patch
cat /tmp/castiron-custom-code-35931582759-1/custom-code.patch

Or reproduce it from an SDK checkout containing the vendored reporter:

git fetch --no-tags origin 82440c9c05a0e2983c47d55dbcd9f4cf889bd9ec ffe9b8fee23e1607064ec76d51f7f09cdbbe32c4
python3 scripts/castiron/custom_code_report.py report \
  --base 82440c9c05a0e2983c47d55dbcd9f4cf889bd9ec \
  --head ffe9b8fee23e1607064ec76d51f7f09cdbbe32c4 --fetch --require-head-hash --public \
  --out /tmp/castiron-custom-code-ffe9b8fee23e
cat /tmp/castiron-custom-code-ffe9b8fee23e/custom-code.patch

This is the current full custom patch for mixed files, not an attribution of only the handwritten lines changed by this PR.

Full report and patch

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: b00d638427

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment thread .github/workflows/create-releases.yml

@jbeckwith-oai jbeckwith-oai left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This major setup-gradle upgrade cannot merge as submitted. Exact-head CI fails the release-security regression test publishing rejects unreviewed action capabilities and cache-enabled inputs because its malicious-fixture mutation still targets the old pinned action SHA, so the release trust-policy coverage no longer validates the changed workflow. Update that regression fixture to derive or match the currently reviewed pinned revision, then rerun the full build, API/runtime compatibility, and release-security checks. Separately, setup-gradle v6 changes its default cache-provider to enhanced, which upstream documents as a closed-source proprietary caching component under separate terms. The current diff silently enables that provider across CI and runtime workflows; explicitly choose cache-provider: basic or obtain a focused review of the new cache trust boundary, data handling, and licensing. Keep publishing cache-disabled: true and preserve the read-only pull-request cache policy.

@dependabot
dependabot Bot force-pushed the dependabot/github_actions/gradle/actions/setup-gradle-6.3.0 branch from b00d638 to 35ef602 Compare August 28, 2026 20:01
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/gradle/actions/setup-gradle-6.3.0 branch from 35ef602 to 6b58877 Compare September 17, 2026 18:13
Bumps [gradle/actions/setup-gradle](https://github.com/gradle/actions) from 5.0.2 to 6.3.0.
- [Release notes](https://github.com/gradle/actions/releases)
- [Commits](gradle/actions@0723195...9c97196)

---
updated-dependencies:
- dependency-name: gradle/actions/setup-gradle
  dependency-version: 6.3.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/gradle/actions/setup-gradle-6.3.0 branch from 6b58877 to c436af8 Compare September 17, 2026 20:05

Copy link
Copy Markdown
Contributor

Addressed the requested cache and regression changes in 3dce554, and merged current main (head ffe9b8f). Every updated setup-gradle invocation explicitly selects cache-provider: basic. Publishing and X.509 jobs retain cache-disabled: true and isolated Gradle homes; CI retains read-only cross-run caches for PRs. The regression mutation now matches the current pinned revision. Local build-logic tests passed (50 passed, 1 skipped) and Kotlin lint passed. Two fresh, independent security-focused review rounds found no in-scope blockers. Remote CI is now running; human re-review is still needed.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 23, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-23T23:04:46.511659Z ffe9b8f New commits
🔒 Security Review ✅ Completed 2026-09-23T23:05:13.339233Z ffe9b8f New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@jbeckwith-oai jbeckwith-oai left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Re-reviewed at ffe9b8f. Both prior blockers are fixed; no remaining blocking findings.

All 12 setup-gradle invocations explicitly select cache-provider: basic. The pinned commit matches upstream's verified v6.3.0 tag. I checked the upstream provider-selection/basic-cache code: disabled caching returns before loading a provider, basic does not load the proprietary provider, and read-only cache saves remain disabled. Publishing and X.509 retain their isolated Gradle homes and cache-disabled: true; PR/merge-group CI retains its read-only cache rules.

The release-security fixture now actually replaces the current SHA pin with a mutable tag, while retaining the mutation and policy-rejection assertions. Parsed base/head comparisons across all five workflows confirm that only the action pin and explicit basic-provider selection changed; events, permissions, secret handling, and other steps are preserved.

Verified CI run 35931547286 passed on this exact head, including build, lint, tests, Jackson/API compatibility, and Java 8/25 runtime compatibility. The build log confirms :buildSrc:test executed successfully and basic caching was selected. I independently checked the workflow structure and malicious-fixture mutation, but did not rerun Gradle or privileged/live release jobs locally.

This approval supersedes my earlier changes-requested review.

"actions/checkout" to setOf("persist-credentials", "ref"),
"actions/setup-java" to setOf("distribution", "java-version"),
"gradle/actions/setup-gradle" to setOf("cache-disabled"),
"gradle/actions/setup-gradle" to setOf("cache-disabled", "cache-provider"),

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[Medium] Keep the provider choice inside the trust boundary

This allowlist accepts the new cache-provider key but never constrains its value. A later change from basic to enhanced would still pass the publishing policy (which only asserts cache-disabled) and the pull-request policy (which only asserts read-only behavior), silently reintroducing the separately reviewed provider this PR deliberately avoids.

Suggested fix: assert that every setup-gradle action uses cache-provider: basic, and add an enhanced mutation to the poisoned-workflow regression.

@markstuart-oai markstuart-oai left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed the complete change at ffe9b8f. All 12 setup-gradle invocations explicitly select the basic provider; the pinned upstream implementation preserves disabled caching and read-only saves. The protected release/X.509 workflows retain their isolated Gradle homes, and the release-policy mutation now targets the current pin without becoming vacuous. No actionable findings.

Verified 11 successful exact-head hosted checks and both Castiron statuses. Source review only; no local Gradle, release or live X.509 jobs were run.

@dpiet-oai
dpiet-oai added this pull request to the merge queue Sep 24, 2026
Merged via the queue into main with commit 3f00bce Sep 24, 2026
14 checks passed
@dependabot
dependabot Bot deleted the dependabot/github_actions/gradle/actions/setup-gradle-6.3.0 branch September 24, 2026 16:21
@openai-sdks openai-sdks Bot mentioned this pull request Sep 24, 2026
arimu1 pushed a commit to arimu1/openai-java that referenced this pull request Sep 27, 2026
Automated Release PR
---


##
[4.69.2](openai/openai-java@v4.69.1...v4.69.2)
(2026-09-24)


### Bug Fixes

* buffer completion text with linear accumulation
([openai#1051](openai#1051))
([0971c87](openai@0971c87))


### Build System

* **deps:** bump com.fasterxml.jackson.core:jackson-databind in /
([openai#905](openai#905))
([fc18819](openai@fc18819))
* **deps:** bump gradle/actions/setup-gradle from 5.0.2 to 6.3.0
([openai#932](openai#932))
([3f00bce](openai@3f00bce))

---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).

Co-authored-by: openai-sdks[bot] <284451331+openai-sdks[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants