19 Apr 2025 |
emily | it goes EOL like a month before the release goes out of support right? | 12:04:05 |
emily | I think knownVulnerabilities would be the thing to do, but it's possible the next round of advisories will come after it goes out of support anyway. | 12:04:38 |
emily | IMO we should just have a rolling openjdk_latest rather than per-version packages for non-LTS, but this has been discussed in here a bunch before and it seems some Java projects are both bleeding edge and incapable of keeping off EOL versions so there is some discontent about even not keeping around dead versions... | 12:05:56 |
emily | do we actually have latest versions of the LTSes? they were vulnerable last I checked | 12:06:18 |
emily | (and JFX?) | 12:06:28 |
emily | BTW, Bazel 5 is also already EOL… | 15:03:41 |
emily | (and there was the Gradle stuff right?) | 15:03:49 |
20 Apr 2025 |
Tomodachi94 (they/them) | Yep. As I understand it, it's very plausible that Gradle 7 goes EOL during the support period for 25.05 | 00:16:28 |
Tomodachi94 (they/them) | Based on what's currently in their issue tracker, I don't think Gradle 9 will be released before 25.05 | 00:17:54 |
Tomodachi94 (they/them) | (Nearly 200 entries on their release candidate milestone for Gradle 9.0) | 00:18:16 |
Tomodachi94 (they/them) | Oh and there's also Maven 4 which is getting released sometime, possibly this year? | 00:22:48 |
emily | right. well FWIW Bazel 5 is only used in the TensorFlow source build that we aren't using by default right now anyway (and which the open PRs to bump move past Bazel 5). | 00:24:40 |
emily | so it should be trivial to knownVulnerabilities | 00:24:51 |
emily | other than that I would suggest dropping OpenJDK 23 and ensuring OpenJDK/OpenJFX/Zulu/Temurin are on latest versions would be good | 00:25:21 |
Tomodachi94 (they/them) | Just posted on the tracking issue for release blockers, feel free to add a comment if something isn't accurate | 00:29:12 |
emily | LGTM | 00:30:44 |
emily | there's really not much using gradle_7; | 00:30:55 |
emily | Corretto and non-latest OpenJFX I guess | 00:31:07 |
23 Apr 2025 |
| @lorev:matrix.org joined the room. | 21:33:55 |
| @lorev:matrix.org left the room. | 21:38:11 |
24 Apr 2025 |
| ortolanbunting3002 joined the room. | 18:20:29 |
25 Apr 2025 |
Ami | openjdk has been stuck at the same patch for months, why is that? | 15:33:20 |
emily | I think we bumped it recently. there's not tons of JDK maintainerpower at present | 15:35:49 |
Ami | i see | 15:37:12 |
emily | do you mean in stable or unstable? | 15:37:54 |
Ami | unstable | 15:38:03 |
Ami | (i somehow manage to repeatedly forget that stable exists) | 15:41:21 |
emily | I also manage to forget that | 15:45:56 |
emily | looks like openjdk is on the latest OpenJDK 21? | 15:47:53 |
emily | 21.0.7 | 15:47:58 |