Skip to content

chore(deps): bump io.insert-koin.compiler.plugin from 1.0.2 to 1.2.1 - #244

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/gradle/io.insert-koin.compiler.plugin-1.2.1
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/gradle/io.insert-koin.compiler.plugin-1.2.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor

Bumps io.insert-koin.compiler.plugin from 1.0.2 to 1.2.1.

Release notes

Sourced from io.insert-koin.compiler.plugin's releases.

1.2.1

Kotlin 2.4.20 support, plus two fixes found on real KMP apps.

✨ Added: Kotlin 2.4.20

On 1.2.0, any project on Kotlin 2.4.20 failed with a raw NoSuchMethodError during IR generation (#89, #99). Kotlin 2.4.20 removed or re-signed four compiler APIs the plugin used. All four are fixed in the plugin core, no new adapter needed.

🐛 Fixed

  • KLIB serialization failed on wasmJs, JS and Kotlin/Native with Different declarations with the same signatures were detected on componentscan_* hints. A @Configuration module relayed through a dependency could emit the same hint twice. Duplicates are now made distinct instead of dropped. JVM and Android were not affected.
  • Two @Named providers of one type collapsed into one when read across modules, giving a false KOIN-D001 (same class of bug as #94 in 1.2.0). If you turned compileSafety off because of false D001 errors, re-check with it on.

🔧 Changed: Kotlin version check is strict again

1.2.0 trusted a whole Kotlin minor line once one patch was verified. Kotlin 2.4.20 broke that assumption three weeks later, and the relax had silenced the only warning that would have hinted at it. A Kotlin version now counts as verified only when that exact version has been checked with tools/abi-check. Unverified versions warn and proceed, they never block.

✅ Compatibility

  • Koin 4.2.0+
  • Kotlin 2.3.20, 2.4.0, 2.4.10, 2.4.20

📦 Install

plugins {
    id("io.insert-koin.compiler.plugin") version "1.2.1"
}

Thanks

@​jamesarich measured all four API breaks with abi-check, validated a fix on a large KMP project and opened #100. This release is built on that analysis. Thanks also to @​nagatsuka-shuuya and @​annotation-engine for the reports (#89, #99), and to @​VladimirPupavaESET, @​dmitry-stakhov and @​Komdosh for confirming and triaging.

Your feedback is welcome 🙏

Cheers ✌️

Full changelog: InsertKoinIO/koin-compiler-plugin@1.2.0...1.2.1

1.2.0

Compile-time safety now covers the whole Koin DSL, and cross-module includes no longer hides definitions.

On Kotlin 2.4.20? Use 1.2.1. That Kotlin patch removed compiler APIs 1.2.0 depends on.

✨ Added

  • Constructor-shorthand DSL is validated: singleOf(::T), factoryOf(::T), scopedOf(::T), viewModelOf(::T) and Scope.new(::T) get the same missing-dependency and qualifier checks as single<T>(). Code that relied on an unchecked missing dependency here will now fail to compile. That is the gap closing, not a regression.
  • Two more entry points recognized: KoinApplication.withConfiguration<T>() and Ktor's install(Koin) { modules(...) }.
  • startKoin { modules(myList) } resolves plain list compositions (listOf, +, .toList(), a function returning List<Module>). Runtime-branching lists (if/when, vararg) stay unresolved, and KOIN-W003 now points at the call.
  • fun myModule(): Module = module { ... } is tracked like a top-level val.

... (truncated)

Changelog

Sourced from io.insert-koin.compiler.plugin's changelog.

A compile-safety architecture release: per-module validation is removed entirely in favor of a single, authoritative full-graph check at each Koin entry point. This closes a real, measured false-positive class, at the cost of leaf modules with no entry point of their own now getting no compile-time safety diagnostics until something assembles a real graph around them. Also ships incremental-compilation freshness hardening, allWarningsAsErrors compatibility, and a collision-safe hint-file-naming scheme.

⚠️ Behavior change — per-module validation removed, full-graph validation only (#32, #51)

Why. A module validated in isolation cannot know how it will be wired into a larger app. This stopped being theoretical: :core:notifications in a real playground app genuinely false-positived on a dependency (PeerService) that a peer module provides — with no Gradle edge between the two, the two are only unified downstream at the app's entry point. Per-module validation — checking a module against its own definitions, its includes = [...], and its @Configuration siblings — cannot see that far, and reported a hard KOIN-D001 for a dependency that resolves correctly once the real app assembles both modules together. Rather than keep tuning the per-module oracle around each new false-positive shape, per-module validation (and its "defer iff a provider exists somewhere" oracle) is deleted outright. Full-graph validation — the check that runs at startKoin/koinApplication/@KoinApplication — is now the sole compile-safety verifier.

What this means for you:

  • Rooted compiles (an app module with a real startKoin/koinApplication/@KoinApplication): more accurate. Genuine cross-module false positives like the peer-provider case above disappear; KOIN-D001 now always shows the real, assembled graph.
  • Leaf/library modules with no Koin entry point in their own compilation: KOIN-D001 (missing dependency), KOIN-D004 (circular dependency), KOIN-D005/KOIN-D006 (parametersOf shape mismatches resolved via the graph), and KOIN-P001 (missing @PropertyValue) are now silent in that compilation — not because the module is safe, but because compile-time cannot know how it will be assembled downstream. The graph is still checked, correctly, at the real entry point once one exists in the compilation. This is disclosed via a default-visible (INFO-severity) message rather than failing silently; see logSeverity below to control its visibility.
  • KOIN-W002 (the old "deferred, no provider hint found anywhere" warning) is deleted — there is no more deferral machinery to warn about.
  • Circular-dependency detection (KOIN-D004) going silent for a leaf module is intentional, not a regression: detecting a cycle requires seeing the whole graph, and a same-module-only check was never a complete cycle detector even under the old per-module validation (it only ever saw local/sibling visibility).

Full account, including the design docs this reverses: docs/COMPILE_SAFETY_A3_PLAN.md (superseded-banner) and docs/COMPILE_TIME_SAFETY.md.

🐛 Fixes

Orphaned @Module classes were silently treated as reachable (found during this release's own verification)

A plain @Module @ComponentScan(...) class with no @Configuration and not referenced by anyone's includes = [...] was silently treated as part of the graph anyway, as long as the entry point used a bare/default-labeled @KoinApplication/startKoin — the overwhelmingly common case. Its @ComponentScan-discovered definitions (including cross-module ones) were folded into the resolved graph and validated as satisfied, when the actual generated module tree never wired them in at all:

... (truncated)

Commits
  • fae817f fix: per-occurrence dup markers so a third identical hint no longer collides ...
  • 2ad3185 fix: Kotlin 2.4.20 support, KLIB duplicate hints, qualifier-blind relay dedup...
  • 0cdde34 docs: add missing compile-time perf entry to 1.2.0 release notes
  • 51395d5 chore: release 1.2.0
  • 0b9d696 feat(a3): recognize KoinApplication.withConfiguration<T>() and Ktor's install...
  • f4ec8ea fix(a3): @​Module(includes=[...]) definition dedup ignored qualifier, dropping...
  • 0278639 chore(playground): pin app-annotations and app-dsl to koin-plugin 1.2.0-Beta10
  • c6212cb 1.2.0-Beta10
  • 03ae05b fix(a3): route two invariant hint lookups through the cache; keep funcreqs_/a...
  • e488a95 docs: catch up docs with constructor-shorthand DSL, W007 removal, and version...
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [io.insert-koin.compiler.plugin](https://github.com/InsertKoinIO/koin-compiler-plugin) from 1.0.2 to 1.2.1.
- [Release notes](https://github.com/InsertKoinIO/koin-compiler-plugin/releases)
- [Changelog](https://github.com/InsertKoinIO/koin-compiler-plugin/blob/main/RELEASE_NOTES_1.1.0.md)
- [Commits](InsertKoinIO/koin-compiler-plugin@1.0.2...1.2.1)

---
updated-dependencies:
- dependency-name: io.insert-koin.compiler.plugin
  dependency-version: 1.2.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update java code labels Oct 1, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants