Java toolchain is declared
java/toolchain-declared@v1
The build chooses the JDK it compiles with through a Java toolchain, rather than inheriting whichever JDK started it.
| Id | java/toolchain-declared |
| Version | v1 |
| Category | java |
| Default severity | warning |
| Interpreter | python3 |
| Timeout | 30 seconds |
| Violations tolerated | 0 |
| Collects | java |
Collectors
This guardrail gathers nothing itself. It depends on the collectors below, which the CLI runs once per build before any check, and reads what they found out of GUARDRAIL_FACTS. A collector that collects nothing skips this guardrail rather than failing it.
| Collector | Gathers | Inputs it is given |
|---|---|---|
java | The Java version the Gradle or Maven build declares, how it declares it, and whether that mechanism makes the build reproducible, for the project and for every Gradle project it includes. | projectDir |
The inputs above are this guardrail's own, passed straight through. Configuring one in buildnote.json changes what is collected, and two guardrails configured the same way share the one collection.
Configuration
{
"guardrails": {
"failOn": "error",
"comment": true,
"checks": [
{
"use": "java/toolchain-declared@v1",
"severity": "warning",
"with": {
"projectDir": "."
},
"exemptions": []
}
]
}
}Inputs
| Input | Description | Default | Environment variable |
|---|---|---|---|
projectDir | Directory holding the project, relative to the directory the CLI runs in. | . | GUARDRAIL_INPUT_PROJECTDIR |
How to fix
Let the build choose its own JDK instead of accepting the one that launched it:
java {
toolchain {
languageVersion.set(JavaLanguageVersion.of(21))
}
}A toolchain provisions the JDK it names and fails the build when it cannot find one. Without it the JDK the build compiles against is whichever one the runner happens to start it with, so the same commit produces different bytecode on a machine with a different JDK installed.
More in java
java/version-declared. The build declares the Java release it compiles for, and that release is no older than the configured floor.java/version-reproducible. The Java release is declared by a mechanism that provisions the JDK, rather than one that asks whichever JDK is running to target an older release.