Skip to content

Guardrails / build

The Gradle wrapper is no older than the floor ​

build/gradle-version-floor@v1

The Gradle version the wrapper pins is at or above the floor your team sets, so the build runs on a toolchain that is still supported.

Idbuild/gradle-version-floor
Versionv1
Categorybuild
Default severitywarning
Interpreterpython3
Timeout30 seconds
Violations tolerated0
Collectsgradle

Collectors ​

This guardrail doesn't gather anything itself. It relies on the collectors below, which the CLI runs once per build before any check, and reads what they found from GUARDRAIL_FACTS. If a collector collects nothing, this guardrail is skipped, not failed.

CollectorGathersInputs it is given
gradleThe Gradle build in the project directory: its settings and manifest, every included project, the wrapper and the distribution it pins, the version catalog, and every dependency the build files declare or the lock files resolve, with the versions its platforms supply.projectDir

The inputs above are this guardrail's own inputs, passed straight through to the collector. Setting one in buildnote.json changes what is collected, and two guardrails configured the same way share a single collection.

Configuration ​

json
{
  "guardrails": {
      "failOn": "error",
      "checks": [
          {
              "use": "build/gradle-version-floor@v1",
              "severity": "warning",
              "with": {
                  "projectDir": ".",
                  "minVersion": "8.0"
              },
              "exemptions": []
          }
      ]
  }
}

Inputs ​

InputDescriptionDefaultEnvironment variable
projectDirDirectory the Gradle build is read from, relative to the directory the CLI runs in..GUARDRAIL_INPUT_PROJECTDIR
minVersionOldest Gradle version the wrapper may pin.8.0GUARDRAIL_INPUT_MINVERSION

How to fix ​

Upgrade the wrapper, which updates the properties and the scripts together:

bash
./gradlew wrapper --gradle-version 9.0.0 --distribution-type bin
./gradlew wrapper --gradle-version 9.0.0 --distribution-type bin

Run it twice: the first run writes the new properties, and the second runs under the new wrapper and finishes the job.

A Gradle version far behind the floor doesn't just miss fixes. It also limits which JDK the build can run on, and every release it falls further behind turns the eventual upgrade from a version bump into a migration.

More in build ​

  • build/dependency-updates-configured. The repository configures a tool that opens dependency updates, so upgrades arrive as pull requests you can review instead of as a chore nobody has time for.
  • build/runs-on-hosted-ci. The artifact was built on a CI platform, not on someone's workstation, so the build is attributable and repeatable.
  • build/wrapper-distribution-verified. The Gradle wrapper pins the checksum of the distribution it downloads, so nobody can swap the toolchain underneath the build.

All 4 build guardrails

Buildnote Limited
Registered in England and Wales, Reg: 16140412