Skip to content

build: drop jcenter (sunset 2021), use mavenCentral + gradlePluginPortal - #8

Merged
Tagar merged 1 commit into
masterfrom
fix-build-drop-jcenter
May 21, 2026
Merged

Tagar merged 1 commit into
masterfrom
fix-build-drop-jcenter

Conversation

@Tagar

@Tagar Tagar commented May 21, 2026

Copy link
Copy Markdown
Member

Root cause

py4j-java/build.gradle declared jcenter() as the sole repository for buildscript classpath resolution. JFrog sunset JCenter / Bintray in May 2021. The endpoint is now flaky — sometimes serves cached requests, sometimes 404s or times out.

This shows up in CI as a randomly-failing Windows cell (or any other fresh-cache runner):

Could not resolve com.diffplug.gradle.spotless:spotless:1.3.2.
> Could not get resource
  'https://jcenter.bintray.com/com/diffplug/gradle/spotless/spotless/1.3.2/spotless-1.3.2.pom'.

Observed on the master push CI for #7 — 1 of 56 cells failed (Python 3.9 / Java 17 / windows-latest). Pre-existing latent issue, surfaces whenever any cell starts with an empty ~/.gradle/caches. 55 of 56 passed because their gradle cache had the artifact from a prior run.

Fix

Replace jcenter() with mavenCentral() + gradlePluginPortal(). Both buildscript artifacts (com.diffplug.gradle.spotless:spotless:1.3.2 and org.standardout:bnd-platform:1.3.0) are mirrored on Maven Central; gradlePluginPortal() is added as a defensive fallback for any future plugin lookups.

Validation

Local clean-cache verification:

rm -rf ~/.gradle/caches/modules-2/files-2.1/com.diffplug.gradle.spotless
rm -rf ~/.gradle/caches/modules-2/files-2.1/org.standardout
./gradlew --refresh-dependencies classes testClasses
# → BUILD SUCCESSFUL

CI matrix on this PR is the final validation — should be 56/56 green now.

Scope

One-file change in py4j-java/build.gradle. Independent of any open PR. Should land before / alongside PRs #5 and #6 to stop the Windows flake masquerading as a CI failure on every push.

Co-authored-by: Isaac

The Gradle buildscript declared `jcenter()` as the sole repository
for buildscript classpath resolution (spotless 1.3.2 + bnd-platform
1.3.0). JFrog sunset JCenter / Bintray in May 2021; the endpoint is
now flaky — CI runners whose gradle cache happens to have the
artifacts cached pass; fresh runners (notably windows-latest)
intermittently fail dependency resolution:

    Could not resolve com.diffplug.gradle.spotless:spotless:1.3.2.
    > Could not get resource
      'https://jcenter.bintray.com/com/diffplug/gradle/spotless/spotless/1.3.2/spotless-1.3.2.pom'.

Observed on the master push CI for #7 (1 of 56 cells failed:
Python 3.9 / Java 17 / windows-latest), and intermittently on prior
runs.

Replace with mavenCentral() + gradlePluginPortal(). Both classpath
artifacts are mirrored on Maven Central; gradlePluginPortal() is
added as a defensive fallback for any future plugin lookups.

Verified locally: clean gradle cache (`rm -rf
~/.gradle/caches/modules-2/files-2.1/com.diffplug.gradle.spotless`
and bnd-platform) + `./gradlew --refresh-dependencies classes
testClasses` → BUILD SUCCESSFUL with the new repositories.

Co-authored-by: Isaac
@Tagar
Tagar merged commit 71bb28d into master May 21, 2026
56 checks passed
Tagar added a commit that referenced this pull request May 21, 2026
…03)"

This reverts commit 5026653 — removing FindBugs was overreach on
weak evidence:

* The 403 was on a SINGLE cell in PR #9's matrix (Python 3.9 /
  Java 8 / ubuntu-latest). Other cells in the SAME matrix run
  resolved `findbugs:3.0.+` successfully — proving the 403 is
  transient (likely Maven Central IP-throttling fresh runners),
  not a permanent policy change.
* Master CI on PRs #4 / #5 / #6 / #7 / #8 has been passing the
  same FindBugs resolution step reliably for months.
* Removing static analysis to "fix" a single flake degrades code
  quality on every future build.

The right defensive measures are already in this PR:
* shell-level retry around `./gradlew check && assemble`
* `shell: bash` for cross-platform consistency

If FindBugs ever does become permanently unavailable, that's the
moment to switch to SpotBugs — a real plugin migration, not a
panic delete.

Co-authored-by: Isaac
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant