Repository navigation
Conversation
Accept exact X.Y.Z.N+B (and longer) JRE version pins, e.g. Liberica monthly security patch releases such as 21.0.12.1+1, in BP_JAVA_VERSION and JBP_CONFIG_*_JRE. Major versions and 21.+ / 21.* keep resolving to the newest version, now including patch releases. Use libbuildpack with JEP 322 version handling (cloudfoundry/libbuildpack#214) so that a single X.Y.Z.N+B manifest entry no longer breaks version resolution and installation of every version of that JRE. Fixes cloudfoundry#1461
Contributor
There was a problem hiding this comment.
🟡 Changes recommended
Version sorting is not a valid strict ordering, and the temporary contributor-fork dependency must be replaced before merge.
1 open finding
What changed in this PR
Adds JEP 322 version support for resolving and installing monthly JRE patch releases.
Changes:
- Supports exact multi-field JRE versions and numeric build metadata.
- Updates libbuildpack resolution, ordering, and lifecycle warnings.
- Adds resolution tests and documentation.
| File | Description |
|---|---|
go.mod |
Temporarily redirects libbuildpack to the feature fork. |
go.sum |
Adds checksums for the fork. |
vendor/modules.txt |
Records the vendored replacement. |
vendor/github.com/cloudfoundry/libbuildpack/versions.go |
Implements JEP 322 parsing, matching, and ordering. |
vendor/github.com/cloudfoundry/libbuildpack/installer.go |
Normalizes versions for patch and EOL warnings. |
src/java/jres/jre.go |
Accepts exact JEP 322 version pins. |
src/java/jres/jre_test.go |
Tests monthly-patch resolution scenarios. |
docs/design.md |
Documents exact JEP 322 selection. |
🧠 Review effort: Balanced
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp => go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp v1.32.0 | ||
| ) | ||
|
|
||
| replace github.com/cloudfoundry/libbuildpack => github.com/stokpop/libbuildpack v0.0.0-20261009130450-f1ccc70bd5b3 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Summary
Java-buildpack part of #1461: support JEP 322 version strings for JRE monthly security patch releases, e.g. Liberica
21.0.12.1+1. Follow-up to #1460.Depends on cloudfoundry/libbuildpack#214. This draft temporarily uses a
replacetostokpop/libbuildpack@80c7e71. Once #214 is merged, I'll swap it for a regular libbuildpack bump and mark this ready for review.Problem
With the current libbuildpack, a single
X.Y.Z.N+Bentry for a JRE inmanifest.ymlbreaks resolution of every version of that JRE, includingBP_JAVA_VERSION,JBP_CONFIG_*_JRE, the manifest default and installation (warnNewerPatch). Also,normalizeVersionPatterndid not accept exactX.Y.Z.N+Bpins:21.0.12.1+1was turned into the pattern21.0.12.1*1.Changes
src/java/jres/jre.go: replace the three exact-version regexes with one JEP 322 regex,^\d+\.\d+\.\d+(\.\d+)*(\+\d+)?$. It accepts17.0.13,17.0.19+11,21.0.12.1,21.0.12.1+1and21.0.10.0.1as exact pins.21,21.+and21.*keep resolving to the newest version.go.mod/vendor: libbuildpack with JEP 322 version handling (temporary replace, see above).docs/design.md: example of an exact JEP 322 pin.Resolution with libbuildpack#214
25.0.4+9,25.0.4.1+1,25.0.4.1+225,25.+,25.*25.0.4.1+225.0.4+925.0.4+925.0.4.125.0.4.1+225.0.4.1+125.0.4.1+125.0.4.1+3Compatibility with the SapMachine 4-part versions (#1460)
manifest.ymlfor cflinuxfs4 and cflinuxfs5: all default versions resolve, and SapMachine17.x,21.xand25.xresolve to17.0.20.1,21.0.12.1and25.0.4.1.Tests
jre_test.go: added Liberica-style25.0.4.1+Nopenjdk entries and a Zulu17.0.13.1entry, plus table tests for major/wildcard/exact/unknown-build requests and the manifest default. The existing Zulu17.+expectation is now17.0.13.1.GetJREVersionopenjdk tests fail once theX.Y.Z.N+Bfixture is present. With this PR,go vet ./...andgo test ./...insrc/javapass.