Skip to content
BETAGuardrails are in beta. The library, the configuration format and the CLI command can still change.

Guardrails / java

Java toolchain is declared

java/toolchain-declared@v1

The build chooses the JDK it compiles with through a Java toolchain, rather than inheriting whichever JDK started it.

Idjava/toolchain-declared
Versionv1
Categoryjava
Default severitywarning
Interpreterpython3
Timeout30 seconds
Violations tolerated0
Collectsjava

Collectors

This guardrail gathers nothing itself. It depends on the collectors below, which the CLI runs once per build before any check, and reads what they found out of GUARDRAIL_FACTS. A collector that collects nothing skips this guardrail rather than failing it.

CollectorGathersInputs it is given
javaThe Java version the Gradle or Maven build declares, how it declares it, and whether that mechanism makes the build reproducible, for the project and for every Gradle project it includes.projectDir

The inputs above are this guardrail's own, passed straight through. Configuring one in buildnote.json changes what is collected, and two guardrails configured the same way share the one collection.

Configuration

json
{
  "guardrails": {
      "failOn": "error",
      "comment": true,
      "checks": [
          {
              "use": "java/toolchain-declared@v1",
              "severity": "warning",
              "with": {
                  "projectDir": "."
              },
              "exemptions": []
          }
      ]
  }
}

Inputs

InputDescriptionDefaultEnvironment variable
projectDirDirectory holding the project, relative to the directory the CLI runs in..GUARDRAIL_INPUT_PROJECTDIR

How to fix

Let the build choose its own JDK instead of accepting the one that launched it:

kotlin
java {
    toolchain {
        languageVersion.set(JavaLanguageVersion.of(21))
    }
}

A toolchain provisions the JDK it names and fails the build when it cannot find one. Without it the JDK the build compiles against is whichever one the runner happens to start it with, so the same commit produces different bytecode on a machine with a different JDK installed.

More in java

  • java/version-declared. The build declares the Java release it compiles for, and that release is no older than the configured floor.
  • java/version-reproducible. The Java release is declared by a mechanism that provisions the JDK, rather than one that asks whichever JDK is running to target an older release.

All 3 java guardrails

Buildnote Limited
Registered in England and Wales, Reg: 16140412