Gradle dependencies are locked
kotlin/dependencies-locked@v1
The Gradle build commits the lock files that resolve its dependencies, so the same commit builds from the same versions.
| Id | kotlin/dependencies-locked |
| Version | v1 |
| Category | kotlin |
| Default severity | warning |
| Interpreter | python3 |
| Timeout | 30 seconds |
| Violations tolerated | 0 |
| Collects | gradle |
Collectors
This guardrail doesn't gather anything itself. It relies on the collectors below, which the CLI runs once per build before any check, and reads what they found from GUARDRAIL_FACTS. If a collector collects nothing, this guardrail is skipped, not failed.
| Collector | Gathers | Inputs it is given |
|---|---|---|
gradle | The Gradle build in the project directory: its settings and manifest, every included project, the wrapper and the distribution it pins, the version catalog, and every dependency the build files declare or the lock files resolve, with the versions its platforms supply. | projectDir |
The inputs above are this guardrail's own inputs, passed straight through to the collector. Setting one in buildnote.json changes what is collected, and two guardrails configured the same way share a single collection.
Configuration
{
"guardrails": {
"failOn": "error",
"checks": [
{
"use": "kotlin/dependencies-locked@v1",
"severity": "warning",
"with": {
"projectDir": ".",
"minLockfiles": "1"
},
"exemptions": []
}
]
}
}Inputs
| Input | Description | Default | Environment variable |
|---|---|---|---|
projectDir | Directory holding the project, relative to the directory the CLI runs in. | . | GUARDRAIL_INPUT_PROJECTDIR |
minLockfiles | Fewest lock files the build must commit. | 1 | GUARDRAIL_INPUT_MINLOCKFILES |
How to fix
Turn on locking for every configuration and write the lock files:
dependencyLocking {
lockAllConfigurations()
}./gradlew dependencies --write-locksCommit the gradle.lockfile files this writes. Without them, a dynamic version, or a transitive dependency whose own range moved, can resolve differently when the same commit is rebuilt, so the build that shipped is not the build that was reviewed.
More in kotlin
kotlin/build-manifest. The project declares a recognised build manifest, so the build is reproducible and tooling can find it.kotlin/gradle-wrapper. A Gradle project commitsgradlewand the wrapper properties that pin the Gradle version.kotlin/kotlin-version-pinned. The build declares the Kotlin compiler version, and it is no older than the configured floor.