chore(deps): upgrade gRPC, Jackson, Logback, and SLF4J - #146
Open
halibobo1205 wants to merge 5 commits into
Open
chore(deps): upgrade gRPC, Jackson, Logback, and SLF4J#146halibobo1205 wants to merge 5 commits into
halibobo1205 wants to merge 5 commits into
Conversation
1. bump grpcVersion to 1.83.1 to pick up the upstream fix for grpc/grpc-java#12930 (PR grpc/grpc-java#12942), which enforces connection.remote().maxActiveStreams(maxStreams) at handler startup 2. drop GrpcNettyMaxConcurrentStreamsLimiter, the local protocol-negotiator shim that applied the same limit while 1.83.0 left the remote endpoint unbounded until the client acknowledged SETTINGS
🤖 CodeAnt AI — Review Status
|
Thanks for using CodeAnt! 🎉We're free for open-source projects. if you're enjoying it, help us grow by sharing. Share on X · |
bump jackson-databind from 2.18.6 to 2.18.10 to pick up cumulative fixes from the 2.18.x line
1. bump logback-classic from 1.2.13 to 1.3.16 and slf4j-api, jcl-over-slf4j, jul-to-slf4j from 1.7.36 to 2.0.17; logback 1.3 requires the slf4j 2.0 provider model, and 1.3.16 is the last 1.3.x release and the ceiling for the x86_64 JDK 8 build, since 1.5.x requires JDK 11 2. rename DelayingShutdownHook to DefaultShutdownHook in the toolkit logback.xml; logback 1.3 removed the old class and only auto-maps the legacy name with a startup warning 3. drop the CONSOLE appender from the toolkit logback.xml; no logger ever referenced it, so it never emitted output on 1.2 either, and logback 1.3 now flags it with an unreferenced-appender warning 4. accept one known 1.3.x behavior change: SizeAndTimeBasedRollingPolicy now throttles its maxFileSize comparison to once per 60s (SimpleInvocationGate) instead of the adaptive ~100-800ms gate of 1.2.13, so under sustained heavy logging a file can overshoot the 500MB cap by up to 60s of writes before the %i rollover fires; time-based rollover and totalSizeCap/maxHistory cleanup are ungated and unaffected 5. note for operators running a custom --log-config file: well-formed 1.2-era configs using standard elements keep working unchanged (jmxConfigurator degrades to an ignored-property warning, the legacy shutdown hook name is auto-mapped), and malformed XML still fails fast via TronError(LOG_LOAD) exactly as on 1.2; however, a config that references an uninstantiable class (e.g. a custom appender missing from the classpath) now aborts the whole appender-ref phase instead of losing just that one appender, so the node starts with no log output while the ERROR statuses are printed to stdout by LogService
1. bump commons-lang3 from 3.4 to 3.20.0; the runtime classpath already resolved 3.18.0 through libp2p 2.2.9's transitive requirement, so align the declaration with what actually ships and move past the CVE-2025-48924 range that the nominal 3.4 still sits in 2. bump commons-collections4 from 4.1 to 4.6.0 3. remove commons-math 2.2; no source file imports org.apache.commons.math and nothing else in the dependency graph requests it 4. update gradle/verification-metadata.xml: add the new jar and pom checksums with their commons-parent 92/103 and apache 39 parent poms, add the junit-bom 5.13.4/5.14.3 and mockito-bom 4.11.0 poms that the upgraded commons poms newly import in dependencyManagement, demote commons-lang3 3.18.0 to a pom-only entry, and drop the commons-lang3 3.4, commons-collections4 4.1 and commons-math 2.2 entries nothing resolves
1. drop the joda-time 2.3 dependency and its verification-metadata entries; no source file imports org.joda and nothing else in the dependency graph requests it 2. replace the six new DateTime(millis) log-formatting call sites in DynamicPropertiesStore, DposTask and DposService with the existing Time.getTimeString helper, converging on the Timestamp format that surrounding logs (BlockCapsule, Manager, StateManager) already use; the printed form changes from 2026-08-25T14:32:11.123+08:00 to 2026-08-25 14:32:11.123 3. replace DateTime.now() arithmetic in five test classes with System.currentTimeMillis() and fixed 86_400_000L day offsets, matching the millisecond style those tests already use elsewhere
halibobo1205
force-pushed
the
feature/upgrade_dependencies
branch
from
August 25, 2026 09:32
3801a50 to
f6373f1
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
User description
What does this PR do?
grpc-javafrom 1.83.0 to 1.83.1, removesGrpcNettyMaxConcurrentStreamsLimiter.jackson-databindfrom 2.18.6 to 2.18.9.logbackfrom 1.2.13 to 1.3.16.slf4jfrom 1.7.36 to 2.0.17.Why are these changes required?
The shim carried an explicit
// TODO: Remove this shim after https://github.com/grpc/grpc-java/issues/12930 is fixed.That issue is now fixed upstream by grpc/grpc-java#12933, backported in grpc/grpc-java#12942 and released in [v1.83.1](https://github.com/grpc/grpc-java/releases/tag/v1.83.1).The Jackson bump is a routine patch-level upgrade on the 2.18.x line.
The logback bump is a routine patch-level upgrade on the 1.3.x line.
This PR has been tested by:
Follow up
Extra details
CodeAnt-AI Description
Secure gRPC connection limits and refresh dependency support
What Changed
Impact
✅ Fewer excessive concurrent gRPC calls✅ Reduced HTTP/2 header-based denial-of-service risk✅ Cleaner toolkit log startup and shutdown💡 Usage Guide
Checking Your Pull Request
Every time you make a pull request, our system automatically looks through it. We check for security issues, mistakes in how you're setting up your infrastructure, and common code problems. We do this to make sure your changes are solid and won't cause any trouble later.
Talking to CodeAnt AI
Got a question or need a hand with something in your pull request? You can easily get in touch with CodeAnt AI right here. Just type the following in a comment on your pull request, and replace "Your question here" with whatever you want to ask:
This lets you have a chat with CodeAnt AI about your pull request, making it easier to understand and improve your code.
Example
Preserve Org Learnings with CodeAnt
You can record team preferences so CodeAnt AI applies them in future reviews. Reply directly to the specific CodeAnt AI suggestion (in the same thread) and replace "Your feedback here" with your input:
This helps CodeAnt AI learn and adapt to your team's coding style and standards.
Example
Retrigger review
Ask CodeAnt AI to review the PR again, by typing:
Check Your Repository Health
To analyze the health of your code repository, visit our dashboard at https://app.codeant.ai. This tool helps you identify potential issues and areas for improvement in your codebase, ensuring your repository maintains high standards of code health.