Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
17 changes: 17 additions & 0 deletions .gitattributes
Original file line number Diff line number Diff line change
@@ -0,0 +1,17 @@
# Normalise line endings for every text file in the repository.
#
# java-parent 1.3.0 configures Spotless with <lineEndings>UNIX</lineEndings>, which makes the
# formatter's output independent of the developer's platform and Git configuration. That alone does
# not make the published sources jar LF-clean — Git still checks files out according to the local
# core.autocrlf — so the parent expects each child project to carry this file. Without it a build on
# Windows produces a sources jar with CRLF and the release stops being byte-reproducible.
* text=auto eol=lf

# Binary files Git must never touch.
*.jar binary
*.png binary
*.jpg binary
*.jpeg binary
*.gif binary
*.ico binary
*.pdf binary
11 changes: 8 additions & 3 deletions docs/TODO.md
Original file line number Diff line number Diff line change
Expand Up @@ -374,8 +374,11 @@ Micrometer into every consuming application now.
Spec 018 reads three files that no Open Elements build currently produces. The wiring is a
`java-parent` concern plus one line per application repository:

- `project.build.outputTimestamp` fixed in `java-parent` — **in progress separately**; without it
no Maven build in the org is byte-reproducible, independent of spec 018.
- ~~`project.build.outputTimestamp` fixed in `java-parent`~~ — **done**: shipped in
`java-parent` 1.3.0 as the literal `2026-09-10T00:00:00Z`, and this reactor is on it. Verified by
building the reactor twice and comparing artifact checksums: byte-identical. The parent's comment
states it explicitly — the value is *not* a build time, it identifies the `java-parent` release an
artifact was built against; `release.sh` rewrites it per release.
- `spring-boot-maven-plugin:build-info` in `java-parent`'s `pluginManagement`, with
`additionalProperties` carrying `commit`, activated per application.
- `cyclonedx-maven-plugin` output redirected to
Expand All @@ -390,4 +393,6 @@ sit in an application-level activation, never in a profile shared with library m
trap that already forced `generateGitPropertiesFile=false` in `java-parent`'s `full-build` profile.

**Context:** Surfaced during the `/grill-me` for spec 018; deferred because `java-parent` is a
separate repository and its `outputTimestamp` change is already being made in parallel.
separate repository. Its `outputTimestamp` part has since landed (1.3.0, 2026-09-10); the remaining
bullets — `build-info`, the SBOM output path and `ARG GIT_COMMIT` in the application Dockerfiles —
are still open, and they are what spec 018 actually needs in order to read anything.
2 changes: 1 addition & 1 deletion docs/specs/018-application-build-info/design.md
Original file line number Diff line number Diff line change
Expand Up @@ -340,7 +340,7 @@ the model to be populated. It belongs in `java-parent` and in the application re

| Requirement | Where |
|---|---|
| `project.build.outputTimestamp` set to a fixed value | `java-parent` (in progress, separately) |
| `project.build.outputTimestamp` set to a fixed value | `java-parent` — **shipped in 1.3.0** (`2026-09-10T00:00:00Z`) |
| `spring-boot-maven-plugin:build-info` in `pluginManagement`, with `additionalProperties` carrying `commit` | `java-parent`, activated per application |
| `cyclonedx-maven-plugin` output to `${project.build.outputDirectory}/META-INF/sbom/application.cdx.json` | `java-parent`, activated per application |
| `ARG GIT_COMMIT` in the Dockerfile, passed to Maven | each application repository |
Expand Down
11 changes: 6 additions & 5 deletions pom.xml
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,7 @@
<parent>
<groupId>com.open-elements</groupId>
<artifactId>java-parent</artifactId>
<version>1.2.1</version>
<version>1.3.0</version>
</parent>

<artifactId>spring-services</artifactId>
Expand Down Expand Up @@ -51,12 +51,13 @@
<module>spring-services-bom</module>
</modules>

<!-- Shared third-party versions for all modules (module-internal concern; not pushed to the org parent). -->
<!-- Third-party versions that java-parent does not manage (module-internal concern; not pushed
to the org parent). Anything the parent manages must NOT be redefined here: a property of the
same name shadows the parent's, so a stale value would silently pin the parent's BOM import
to an old version. jspecify and testcontainers were removed for exactly that reason — the
parent manages org.jspecify:jspecify and imports testcontainers-bom. -->
<properties>
<slack-api-client.version>1.45.3</slack-api-client.version>
<swagger-annotations-jakarta.version>2.2.29</swagger-annotations-jakarta.version>
<jspecify.version>1.0.0</jspecify.version>
<testcontainers.version>2.0.5</testcontainers.version>
<wiremock.version>3.10.0</wiremock.version>
<mcp-sdk.version>0.18.3</mcp-sdk.version>
</properties>
Expand Down
6 changes: 3 additions & 3 deletions spring-services-core/pom.xml
Original file line number Diff line number Diff line change
Expand Up @@ -36,15 +36,15 @@
<artifactId>spring-boot-starter-oauth2-resource-server</artifactId>
</dependency>
<dependency>
<!-- Version managed by java-parent's swagger-bom import: the OpenAPI stack must stay
version-uniform, because a split Swagger stack throws NoSuchMethodError at runtime. -->
<groupId>io.swagger.core.v3</groupId>
<artifactId>swagger-annotations-jakarta</artifactId>
<version>${swagger-annotations-jakarta.version}</version>
</dependency>
<!-- Version and scope managed by java-parent. -->
<dependency>
<groupId>org.jspecify</groupId>
<artifactId>jspecify</artifactId>
<version>${jspecify.version}</version>
<scope>compile</scope>
</dependency>
<!-- Test dependencies -->
<dependency>
Expand Down