Repository navigation
Conversation
Each solrbot PR now creates its own changelog entry via the renovate-changelog workflows, so the bulk step that built entries from git log only produced duplicates. Remove the step and the addDepsToChanges.py script it called. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Replace addDepsToChanges.py (which bulk-converted solrbot commits into changelog entries, duplicating the per-PR entries) with dependencyChanges.py. It diffs the jar checksum files in solr/licenses/ between the previous release tag and HEAD, groups jars that moved between the same versions, and prints a summary or writes one dependency_update changelog entry. The wizard step now runs it. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Obsolete now that dependencyChanges.py summarizes dependency changes at release time. Removes the renovate-changelog-prepare/push workflows and generate-renovate-changelog.py. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Dependency changes from releases/solr/9.10.1 to apache/branch_9_11: |
Print one line per category, with changes separated by semicolons, and with --write produce one changelog entry per category. Removals are included again, limited to jars that had a LICENSE file. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Drop the --author option (defaulting to git user.name); the entries summarize many people's changes. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…, removed Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
🤖 A thought for a follow-up, based on generating the 9.11 dependency entries by hand. Comparing the jars actually inside the binary distribution is more accurate than comparing For 9.10.1 → 9.11, I compared the output against the jars in the official 9.10.1 tarball and in a fresh 9.11 build (
Net effect: upgraded went from 87 to 74 entries and removed from 43 to 48. That's what I committed for 9.11. Proposal: take the jar list from each distribution instead.
This could go in this PR or a follow-up. The current sha1-based version is still a big improvement over the old per-PR entries. Note: looking at JARs is less than perfect as well, as it doesn't include non-JAR dependencies such as jQuery. Finally... what we really want is likely a Cyclone DX SBOM to do comparisons. CC @epugh 🤖 Generated with Claude Code and reviewed/edited by Smiley |
Agreed. The WIP is this file: https://github.com/apache/solr-site/blob/main/plugins/vex/solr-dependency-versions.json, it's only listing mappings for jars that have a vex file, so it doesn't cover everything. What I learned was that you have to look at the dist, not the source, or get you get a lot of noise. Do you think starting to publish SBOM now, even though it won't exist for previous Solrs would be useful? @ppkarwasz has #4690 which adds SBOM. Maybe worth a discussion at Glasgow? |
|
Again, the sha1 file approach should become stable/reliable on the 10x line, and it's efficient to do the processing that way instead of comparing JARs in multiple distributions. Nonetheless I could switch this to the latter; Claude did so locally for my 9.11 analysis.
Sounds like a non-starter? |
The licenses are also there, although in “raw” form (i.e. as declared in the POM) and a script would be necessary to add a “concluded” license. For example I imagine that Jetty inside Solr is relicensed under |

🤖 Replaces
addDepsToChanges.py, which bulk-converted solrbot commits into changelog entries (duplicating the entries solrbot PRs already create), withdev-tools/scripts/dependencyChanges.py. Context: dev@ thread "changelog and dependencies".The new script diffs the jar checksum files in
solr/licenses/between the previous release tag and HEAD (git only; no build needed):jetty-* (23 jars) 12.0.27 → 12.1.12), since they're typically one project.--writewrites onedependency_updateentry per category tochangelog/unreleased/dependency-changes-{1-added,2-upgraded,3-removed}.yml(numbered to order them), attributed to "various contributors". Re-running overwrites them.The release wizard step now runs it with
--write. Try it:python3 dev-tools/scripts/dependencyChanges.py(on main, compares to 10.0.0: 11 added, 83 upgraded, 49 removed).Also removes the workflows (and script) that generated a changelog entry for each solrbot (Renovate) PR; they're obsolete. Removing the existing solrbot entries is separate: #4944.
🤖 Generated with Claude Code