From c270c91fb7bc417c23cdf86845dcebad210e9f2f Mon Sep 17 00:00:00 2001 From: robfrank Date: Wed, 29 Jul 2026 10:44:58 +0200 Subject: [PATCH] ci: stop Dependabot proposing Groovy majors that TinkerPop cannot take Groovy's version is set by TinkerPop, not by ArcadeDB. It appears only in gremlin/pom.xml (org.apache.groovy:groovy) and no other reactor module depends on it. gremlin-groovy 3.8.1 is built against the Groovy 4.0.x line, so Groovy 5 is a major break that cannot be adopted until TinkerPop moves. PR #4969 (4.0.32 -> 5.0.7) has been unmergeable since July for this reason. Ignores majors only. ArcadeDB deliberately runs 4.0.32, ahead of TinkerPop's own 4.0.25, so 4.0.x patch and minor updates keep flowing. ANTLR shares the same TinkerPop coupling but is deliberately left out. antlr4.version is declared per-module with two different intents: gremlin pins 4.9.1 because gremlin-language ships a parser generated by the ANTLR 4.9.1 tool and 4.10 changed the serialized ATN format, while engine independently tracks the latest 4.13.2 for its own grammar. Dependabot ignore rules match coordinates rather than modules, and gremlin's frozen 4.9.1 sits below the engine's current 4.13.2, so any range blocking the gremlin bump would silently freeze the engine too. --- .github/dependabot.yml | 23 +++++++++++++++++++++++ 1 file changed, 23 insertions(+) diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 03406eccb14..b3b21582b0b 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -18,6 +18,29 @@ updates: interval: weekly day: "sunday" open-pull-requests-limit: 20 + ignore: + # Groovy's version is dictated by TinkerPop, not by ArcadeDB. It appears + # only in gremlin/pom.xml and gremlin-it/pom.xml; no other module in the + # reactor uses it. gremlin-groovy 3.8.1 is built against the Groovy 4.0.x + # line (TinkerPop 3.8.1 declares groovy.version 4.0.25), so Groovy 5 is a + # major break that cannot be adopted until TinkerPop itself moves. + # + # Only majors are ignored. ArcadeDB deliberately runs 4.0.32, ahead of + # TinkerPop's own 4.0.25, so 4.0.x patch and minor updates must keep + # flowing. + # + # ANTLR is deliberately NOT listed here despite the same TinkerPop + # coupling. antlr4.version is declared per-module with two different + # intents: gremlin/pom.xml pins 4.9.1 because gremlin-language ships a + # parser generated by the ANTLR 4.9.1 tool, and ANTLR 4.10 changed the + # serialized ATN format, so a 4.13 runtime cannot read it. engine/pom.xml + # independently tracks the latest (4.13.2) for its own grammar. Dependabot + # ignore rules match dependency coordinates, not modules, and gremlin's + # frozen 4.9.1 sits below the engine's current 4.13.2, so any range that + # blocked the gremlin bump would silently freeze the engine too. The + # gremlin ANTLR PR is closed by hand instead. + - dependency-name: "org.apache.groovy:*" + update-types: ["version-update:semver-major"] - package-ecosystem: "github-actions" directory: "/"