Skip to content

Conversation

@darvld
Copy link
Member

@darvld darvld commented Sep 21, 2025

Ready for review Powered by Pull Request Badge

Summary

Adds a missing test driver and correctly registers dynamic guest suites.

sgammon and others added 9 commits September 20, 2025 21:23
Signed-off-by: Sam Gammon <sam@elide.dev>
Signed-off-by: Sam Gammon <sam@elide.dev>
Signed-off-by: Sam Gammon <sam@elide.dev>
Signed-off-by: Sam Gammon <sam@elide.dev>
Signed-off-by: Sam Gammon <sam@elide.dev>
Signed-off-by: Sam Gammon <sam@elide.dev>
Signed-off-by: Sam Gammon <sam@elide.dev>
Signed-off-by: Dario Valdespino <dvaldespino00@gmail.com>
@darvld darvld self-assigned this Sep 21, 2025
@darvld darvld requested a review from sgammon as a code owner September 21, 2025 22:04
@darvld darvld added bug Something isn't working module:cli CLI module issues and features P0 tools:test-runner Stuff relating to Elide's test runner labels Sep 21, 2025
@socket-security
Copy link

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addedmaven/​org.junit.jupiter/​junit-jupiter-engine@​5.13.1361008910070
Addedmaven/​org.junit.platform/​junit-platform-launcher@​1.13.1361008910070
Addedmaven/​org.apache.commons/​commons-compress@​1.28.03610089100100
Addedmaven/​com.fasterxml.jackson.module/​jackson-module-kotlin@​2.20.0361009010080
Addedmaven/​org.jetbrains.kotlin/​kotlin-reflect@​2.2.203610090100100
Updatedmaven/​io.micronaut/​micronaut-http-server-netty@​4.9.7 ⏵ 4.9.103610090 +2100 +1100
Updatedmaven/​io.micronaut/​micronaut-http-client@​4.9.7 ⏵ 4.9.1036 -6410089100100
Updatedmaven/​com.fasterxml.jackson.datatype/​jackson-datatype-jsr310@​2.19.1 ⏵ 2.20.0361008910080
Updatedmaven/​org.yaml/​snakeyaml@​2.4 ⏵ 2.53610089 -1100100
Updatedmaven/​io.ktor/​ktor-client-core-jvm@​3.0.2 ⏵ 3.3.036 +1110090 -10100100
Updatedmaven/​io.micronaut/​micronaut-http-client-jdk@​4.9.7 ⏵ 4.9.1036 -6410090 +2100100
Addedmaven/​com.fasterxml.jackson.dataformat/​jackson-dataformat-xml@​2.20.0541008910080
Updatedmaven/​com.google.devtools.ksp/​symbol-processing-gradle-plugin@​2.2.0-2.0.2 ⏵ 2.2.20-2.0.354 +210090 +2100 +1100
Updatedmaven/​io.netty/​netty-codec-http2@​4.2.2.Final ⏵ 4.2.6.Final64100 +16100100100
Updatedmaven/​org.jetbrains.kotlin/​kotlin-serialization-compiler-plugin-embeddable@​2.2.0 ⏵ 2.2.207310090 +2100100
Updatedmaven/​io.micronaut.serde/​micronaut-serde-jackson@​2.15.0 ⏵ 2.15.176 -2410089100100
Updatedmaven/​org.jetbrains.kotlin/​kotlin-scripting-jvm-host@​2.2.0 ⏵ 2.2.2084 +210090 +2100100
Updatedmaven/​io.ktor/​ktor-server-sessions-jvm@​3.2.2 ⏵ 3.3.085 -1510090 +2100100
Updatedmaven/​com.akuleshov7/​ktoml-core-jvm@​0.7.0 ⏵ 0.7.189 -1110090 +2100100
Addedmaven/​com.aayushatharva.brotli4j/​native-linux-aarch64@​1.20.010010089100100
Addedmaven/​org.jetbrains/​annotations@​26.0.2-19910089100100
Addedmaven/​io.netty/​netty-codec@​4.2.6.Final10010089100100
Updatedmaven/​com.google.errorprone/​error_prone_annotations@​2.37.0 ⏵ 2.41.09910089100100
Updatedmaven/​com.squareup.okio/​okio@​3.15.0 ⏵ 3.16.010010089100100
Updatedmaven/​io.micronaut/​micronaut-runtime@​4.9.7 ⏵ 4.9.1010010089100 +1100
Updatedmaven/​com.google.j2objc/​j2objc-annotations@​3.0.0 ⏵ 3.19910089 -1100100
Updatedmaven/​io.netty/​netty-tcnative-boringssl-static@​2.0.72.Final ⏵ 2.0.73.Final10010089100100
Updatedmaven/​org.jetbrains.kotlin/​kotlin-scripting-dependencies-maven@​2.2.0 ⏵ 2.2.2089 +210090 +2100100
Addedmaven/​software.amazon.eventstream/​eventstream@​1.0.19510090100100
Addedmaven/​com.aayushatharva.brotli4j/​native-osx-x86_64@​1.20.010010090100100
Addedmaven/​dev.zacsweers.redacted/​redacted-compiler-plugin@​1.15.09810090100100
Addedmaven/​software.amazon.awssdk/​bom@​2.34.010010090100100
See 55 more rows in the dashboard

View full report

@socket-security
Copy link

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
maven/org.jetbrains.kotlin/kotlin-gradle-plugin@2.2.20 has Obfuscated code.

Confidence: 0.98

Location: Package overview

From: tools/elide-build/gradle.lockfilemaven/org.jetbrains.kotlin/compose-compiler-gradle-plugin@2.2.20maven/org.jetbrains.kotlin/kotlin-gradle-plugin@2.2.20

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore maven/org.jetbrains.kotlin/kotlin-gradle-plugin@2.2.20. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@sgammon
Copy link
Member

sgammon commented Sep 22, 2025

merging with #1657

@sgammon sgammon closed this Sep 22, 2025
@sgammon sgammon mentioned this pull request Oct 30, 2025
32 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working module:cli CLI module issues and features P0 tools:test-runner Stuff relating to Elide's test runner

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants