Conversation
Bumps com.gradleup.shadow from 8.3.8 to 9.6.1. --- updated-dependencies: - dependency-name: com.gradleup.shadow dependency-version: 9.6.1 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: abda53b330
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
jbeckwith-oai
left a comment
There was a problem hiding this comment.
Overview
This changes the ProGuard/R8 test fixture from Shadow 8.3.8 to 9.6.1. The fat JAR produced by this plugin is a required input to both shrinker compatibility tests, so plugin configuration and archive semantics must remain compatible with the repository Gradle wrapper.
Confirmed Findings
- [High] Shadow 9.6.1 is incompatible with Gradle 8.12
- Location: openai-java-proguard-test/build.gradle.kts:3; wrapper remains
gradle/wrapper/gradle-wrapper.properties:3. - Why: Shadow 9.5+ requires Gradle 9.2+, but this repository is pinned to Gradle 8.12. Exact-head CI fails during configuration with the missing
AdhocComponentWithVariants.addVariantsFromConfiguration(Provider, Action)API, so build, test, API, and runtime jobs cannot run. Failed CI - Suggested fix: Keep 8.3.8 or choose a release compatible with Gradle 8.12. Treat 9.6.1 as part of a separately reviewed Gradle 9.2+ migration, including a fat-JAR output comparison for Shadow 9 breaking changes.
- Location: openai-java-proguard-test/build.gradle.kts:3; wrapper remains
Rejected Findings
None.
Residual Risks
None beyond the confirmed build blocker. Requesting changes; this PR must not merge in its current form.
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
Castiron custom code✅ No new custom-code files detected. 87 mixed files remain; 0 existing customizations changed. Compared 87 existing customizations unchanged
47 more in the full report. A changed generated baseline means this report cannot reliably identify which handwritten lines changed. Inspect the custom-code diffDownload the exact patch produced by this run (requires repository access): gh run download 36026630514 --repo openai/openai-java \
--name castiron-custom-code-36026630514-1 --dir /tmp/castiron-custom-code-36026630514-1
git apply --stat /tmp/castiron-custom-code-36026630514-1/custom-code.patch
cat /tmp/castiron-custom-code-36026630514-1/custom-code.patchOr reproduce it from an SDK checkout containing the vendored reporter: git fetch --no-tags origin fc188194e7e016dfd8dd327d6f855dfe48c08b1c 5484e643b38df1d7f9167b608daa5e46265a31a5
python3 scripts/castiron/custom_code_report.py report \
--base fc188194e7e016dfd8dd327d6f855dfe48c08b1c \
--head 5484e643b38df1d7f9167b608daa5e46265a31a5 --fetch --require-head-hash --public \
--out /tmp/castiron-custom-code-5484e643b38d
cat /tmp/castiron-custom-code-5484e643b38d/custom-code.patchThis is the current full custom patch for mixed files, not an attribution of only the handwritten lines changed by this PR. |
markstuart-oai
left a comment
There was a problem hiding this comment.
Reviewed 5484e643b38df1d7f9167b608daa5e46265a31a5; no remaining actionable findings.
Shadow 9.2.2 supports the existing Gradle 8.12/JDK 21 build. The documented addMultiReleaseAttribute = false option preserves the shrinker fixture’s prior manifest behavior without changing SDK toolchains, published artifacts, or the ProGuard/R8 task wiring. This is a small, direct fix to the earlier compatibility feedback.
Source review included the surrounding Gradle conventions, fixture tests, and Shadow 9.2.2’s implementation. Current CI checks pass; the hosted test log confirms both testProGuard and testR8 executed successfully. I did not run builds or tests locally or independently repeat the reported fat-JAR comparison.
Re-reviewed current head 5484e64. My original Gradle compatibility finding is fixed: Shadow 9.2.2 supports the unchanged Gradle 8.12 / JDK 21 build. The fixture opts out of automatic Multi-Release manifest inheritance while retaining both shrinker smoke tests. Reviewed the complete one-file change and versioned upstream implementation; 11 static base/head and wiring checks passed. Exact-head CI36026576009 is green, and logs confirm both testProGuard and testR8 executed successfully. No remaining actionable findings; local Gradle/archive comparison was not rerun. Mark and Dan already approved this exact head, so I am withdrawing only my outdated change request instead of duplicating their approvals.
Automated Release PR --- ## [4.69.3](openai/openai-java@v4.69.2...v4.69.3) (2026-09-25) ### Chores * **api:** document files and uploads error responses ([openai#1081](openai#1081)) ([69a4e21](openai@69a4e21)) * **api:** document Responses not-found errors ([openai#1080](openai#1080)) ([e8cbf5d](openai@e8cbf5d)) ### Build System * **deps:** bump Maven Publish to 0.34.0 ([openai#910](openai#910)) ([2cbf22c](openai@2cbf22c)) * **deps:** bump Shadow to 9.2.2 ([openai#904](openai#904)) ([09b8c60](openai@09b8c60)) * **deps:** upgrade Kotlin declarations together to 2.2.21 ([openai#1079](openai#1079)) ([465742d](openai@465742d)) --- This PR was generated with [Release Please](https://github.com/googleapis/release-please). See [documentation](https://github.com/googleapis/release-please#release-please). Co-authored-by: openai-sdks[bot] <284451331+openai-sdks[bot]@users.noreply.github.com>
Reviewed upgrade
Updates Shadow from 8.3.8 to 9.2.2. This supersedes the original Dependabot 9.6.1 target: 9.2.2 supports the existing Gradle 8.12 / JDK 21 build.
Validation: buildSrc tests, Kotlin lint, ProGuard and R8 smoke tests. Compared Shadow 8.3.8 and 9.2.2 fat JAR entries; the upgrade removes module-info and adds the manifest flag, and disabling the latter restores both smoke tests.
Original Dependabot proposal (superseded target)
Bumps com.gradleup.shadow from 8.3.8 to 9.6.1.
You can trigger a rebase of this PR by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)