Repository navigation
build(deps): bump gradle/actions/setup-gradle from 5.0.2 to 6.3.0 - #932
Conversation
Castiron custom code✅ No new custom-code files detected. 87 mixed files remain; 0 existing customizations changed. Compared 87 existing customizations unchanged
47 more in the full report. A changed generated baseline means this report cannot reliably identify which handwritten lines changed. Inspect the custom-code diffDownload the exact patch produced by this run (requires repository access): gh run download 35931582759 --repo openai/openai-java \
--name castiron-custom-code-35931582759-1 --dir /tmp/castiron-custom-code-35931582759-1
git apply --stat /tmp/castiron-custom-code-35931582759-1/custom-code.patch
cat /tmp/castiron-custom-code-35931582759-1/custom-code.patchOr reproduce it from an SDK checkout containing the vendored reporter: git fetch --no-tags origin 82440c9c05a0e2983c47d55dbcd9f4cf889bd9ec ffe9b8fee23e1607064ec76d51f7f09cdbbe32c4
python3 scripts/castiron/custom_code_report.py report \
--base 82440c9c05a0e2983c47d55dbcd9f4cf889bd9ec \
--head ffe9b8fee23e1607064ec76d51f7f09cdbbe32c4 --fetch --require-head-hash --public \
--out /tmp/castiron-custom-code-ffe9b8fee23e
cat /tmp/castiron-custom-code-ffe9b8fee23e/custom-code.patchThis is the current full custom patch for mixed files, not an attribution of only the handwritten lines changed by this PR. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: b00d638427
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
jbeckwith-oai
left a comment
There was a problem hiding this comment.
This major setup-gradle upgrade cannot merge as submitted. Exact-head CI fails the release-security regression test publishing rejects unreviewed action capabilities and cache-enabled inputs because its malicious-fixture mutation still targets the old pinned action SHA, so the release trust-policy coverage no longer validates the changed workflow. Update that regression fixture to derive or match the currently reviewed pinned revision, then rerun the full build, API/runtime compatibility, and release-security checks. Separately, setup-gradle v6 changes its default cache-provider to enhanced, which upstream documents as a closed-source proprietary caching component under separate terms. The current diff silently enables that provider across CI and runtime workflows; explicitly choose cache-provider: basic or obtain a focused review of the new cache trust boundary, data handling, and licensing. Keep publishing cache-disabled: true and preserve the read-only pull-request cache policy.
b00d638 to
35ef602
Compare
35ef602 to
6b58877
Compare
Bumps [gradle/actions/setup-gradle](https://github.com/gradle/actions) from 5.0.2 to 6.3.0. - [Release notes](https://github.com/gradle/actions/releases) - [Commits](gradle/actions@0723195...9c97196) --- updated-dependencies: - dependency-name: gradle/actions/setup-gradle dependency-version: 6.3.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
6b58877 to
c436af8
Compare
|
Addressed the requested cache and regression changes in 3dce554, and merged current main (head ffe9b8f). Every updated setup-gradle invocation explicitly selects cache-provider: basic. Publishing and X.509 jobs retain cache-disabled: true and isolated Gradle homes; CI retains read-only cross-run caches for PRs. The regression mutation now matches the current pinned revision. Local build-logic tests passed (50 passed, 1 skipped) and Kotlin lint passed. Two fresh, independent security-focused review rounds found no in-scope blockers. Remote CI is now running; human re-review is still needed. |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
jbeckwith-oai
left a comment
There was a problem hiding this comment.
Re-reviewed at ffe9b8f. Both prior blockers are fixed; no remaining blocking findings.
All 12 setup-gradle invocations explicitly select cache-provider: basic. The pinned commit matches upstream's verified v6.3.0 tag. I checked the upstream provider-selection/basic-cache code: disabled caching returns before loading a provider, basic does not load the proprietary provider, and read-only cache saves remain disabled. Publishing and X.509 retain their isolated Gradle homes and cache-disabled: true; PR/merge-group CI retains its read-only cache rules.
The release-security fixture now actually replaces the current SHA pin with a mutable tag, while retaining the mutation and policy-rejection assertions. Parsed base/head comparisons across all five workflows confirm that only the action pin and explicit basic-provider selection changed; events, permissions, secret handling, and other steps are preserved.
Verified CI run 35931547286 passed on this exact head, including build, lint, tests, Jackson/API compatibility, and Java 8/25 runtime compatibility. The build log confirms :buildSrc:test executed successfully and basic caching was selected. I independently checked the workflow structure and malicious-fixture mutation, but did not rerun Gradle or privileged/live release jobs locally.
This approval supersedes my earlier changes-requested review.
| "actions/checkout" to setOf("persist-credentials", "ref"), | ||
| "actions/setup-java" to setOf("distribution", "java-version"), | ||
| "gradle/actions/setup-gradle" to setOf("cache-disabled"), | ||
| "gradle/actions/setup-gradle" to setOf("cache-disabled", "cache-provider"), |
There was a problem hiding this comment.
[Medium] Keep the provider choice inside the trust boundary
This allowlist accepts the new cache-provider key but never constrains its value. A later change from basic to enhanced would still pass the publishing policy (which only asserts cache-disabled) and the pull-request policy (which only asserts read-only behavior), silently reintroducing the separately reviewed provider this PR deliberately avoids.
Suggested fix: assert that every setup-gradle action uses cache-provider: basic, and add an enhanced mutation to the poisoned-workflow regression.
markstuart-oai
left a comment
There was a problem hiding this comment.
Reviewed the complete change at ffe9b8f. All 12 setup-gradle invocations explicitly select the basic provider; the pinned upstream implementation preserves disabled caching and read-only saves. The protected release/X.509 workflows retain their isolated Gradle homes, and the release-policy mutation now targets the current pin without becoming vacuous. No actionable findings.
Verified 11 successful exact-head hosted checks and both Castiron statuses. Source review only; no local Gradle, release or live X.509 jobs were run.
Automated Release PR --- ## [4.69.2](openai/openai-java@v4.69.1...v4.69.2) (2026-09-24) ### Bug Fixes * buffer completion text with linear accumulation ([openai#1051](openai#1051)) ([0971c87](openai@0971c87)) ### Build System * **deps:** bump com.fasterxml.jackson.core:jackson-databind in / ([openai#905](openai#905)) ([fc18819](openai@fc18819)) * **deps:** bump gradle/actions/setup-gradle from 5.0.2 to 6.3.0 ([openai#932](openai#932)) ([3f00bce](openai@3f00bce)) --- This PR was generated with [Release Please](https://github.com/googleapis/release-please). See [documentation](https://github.com/googleapis/release-please#release-please). Co-authored-by: openai-sdks[bot] <284451331+openai-sdks[bot]@users.noreply.github.com>
Bumps gradle/actions/setup-gradle from 5.0.2 to 6.3.0.
Release notes
Sourced from gradle/actions/setup-gradle's releases.
... (truncated)
Commits
9c97196Bump the github-actions group across 2 directories with 9 updates (#1024)760e4a4Bump the npm-dependencies group across 1 directory with 2 updates (#1037)73e4c42Update gradle-actions-caching library to v1.0.0 (#1029)a9d1438Add dependabot ignore rules for TypeScript 7.x and@types/node25.x/26.x68f3700[bot] Update dist directory5971332Bump Gradle Wrapper to 9.6.1, wrapper checksums, and Develocity plugin to 4.5...b5bc804[bot] Update dist directorydcbab4eBump npm-dependencies group with TypeScript 6.0.3,@types/node24.x, and secu...ca8d957Move non-smoke restore-gradle-home tests back to the integ-test suite (#1032)4318659[bot] Update dist directory