Skip to content

Guardrails / kotlin

Project has a build manifest ​

kotlin/build-manifest@v1

The project declares a recognised build manifest, so the build is reproducible and tooling can find it.

Idkotlin/build-manifest
Versionv1
Categorykotlin
Default severityerror
Interpreterpython3
Timeout30 seconds
Violations tolerated0
Collectsgradle, maven

Collectors ​

This guardrail doesn't gather anything itself. It relies on the collectors below, which the CLI runs once per build before any check, and reads what they found from GUARDRAIL_FACTS. If a collector collects nothing, this guardrail is skipped, not failed.

CollectorGathersInputs it is given
gradleThe Gradle build in the project directory: its settings and manifest, every included project, the wrapper and the distribution it pins, the version catalog, and every dependency the build files declare or the lock files resolve, with the versions its platforms supply.projectDir
mavenThe Maven build in the project directory: the root pom.xml coordinates, its modules, its properties and every dependency it and its modules declare, with the versions its imported BOMs supply.projectDir

The inputs above are this guardrail's own inputs, passed straight through to the collector. Setting one in buildnote.json changes what is collected, and two guardrails configured the same way share a single collection.

Configuration ​

json
{
  "guardrails": {
      "failOn": "error",
      "checks": [
          {
              "use": "kotlin/build-manifest@v1",
              "severity": "error",
              "with": {
                  "projectDir": "."
              },
              "exemptions": []
          }
      ]
  }
}

Inputs ​

InputDescriptionDefaultEnvironment variable
projectDirDirectory holding the project, relative to the directory the CLI runs in..GUARDRAIL_INPUT_PROJECTDIR

How to fix ​

Add a build manifest at the project root: build.gradle.kts (Gradle Kotlin DSL), build.gradle (Gradle Groovy DSL) or pom.xml (Maven). Without one, nobody but the author can build the checkout.

More in kotlin ​

  • kotlin/dependencies-locked. The Gradle build commits the lock files that resolve its dependencies, so the same commit builds from the same versions.
  • kotlin/gradle-wrapper. A Gradle project commits gradlew and the wrapper properties that pin the Gradle version.
  • kotlin/kotlin-version-pinned. The build declares the Kotlin compiler version, and it is no older than the configured floor.

All 4 kotlin guardrails

Buildnote Limited
Registered in England and Wales, Reg: 16140412