Skip to content

chore: take vaadin-cdi from Flow's version - #9457

Merged
ZheSun88 merged 1 commit into
mainfrom
chore/cdi-follows-flow-version
Sep 16, 2026
Merged

ZheSun88 merged 1 commit into
mainfrom
chore/cdi-follows-flow-version

Conversation

@totally-not-ai

@totally-not-ai totally-not-ai Bot commented Sep 16, 2026 •

Copy link
Copy Markdown
Contributor

Summary

From 25.4 on, vaadin-cdi is built and released as part of Flow, so it has no version of its own anymore. This change makes the platform take the CDI version from Flow, the same way it already does for the Spring add-on.

What changed

Behavior change (release tooling only): the generated artifacts now point CDI at Flow's version instead of a separate one. This affects anyone consuming the generated BOM or release notes; no application API changes.

  • versions.json: removed the core.flow-cdi entry (it was pinned at 16.1.2).
  • template-vaadin-bom.xml: vaadin-cdi now uses ${flow.version} instead of ${flow.cdi.version}. Since that was the last use, the generated flow.cdi.version property is gone from the BOM.
  • Both release-note templates (template-release-notes.md and template-release-notes-prerelease.md): the CDI add-on line now uses core.flow and links to Flow's releases. Before this, it printed a literal {{core.flow-cdi.javaVersion}} because the value no longer existed.
  • creator.js: dropped vaadin/cdi from the changelog module list, since it would look for release tags that will never be created.

Manual check with --platform=25.4.0-alpha1: the BOM resolves vaadin-cdi to 25.4-SNAPSHOT through flow.version, and the notes render the CDI line against Flow's releases.

Test summary

No tests were added or changed on this branch. The generator suite (creatorTest.js, jarVersionsTest.js, transformerTest.js) reports the same 18 passing and 5 failing as on an unmodified main, and the check-versions suite passes in full.

# Status What the test verifies Why it matters
1 ❗ gap Generated BOM resolves vaadin-cdi to Flow's version and contains no flow.cdi.version property A wrong or unresolved version here ships a broken BOM to every CDI user
2 ❗ gap Release notes render the CDI add-on line with Flow's version and a link to Flow's releases This was the actual bug: an undefined key printed as raw {{...}} text in published notes
3 ❗ gap Changelog generation no longer requests releases from vaadin/cdi Asking for tags that will never exist would break or pollute changelog output
  • No test methods added or changed.

Rows 1–3 were verified by hand (generating with --platform=25.4.0-alpha1) rather than by automated tests; the existing generator tests do not assert on CDI at all.

vaadin-cdi is built and released as part of Flow from 25.4 onwards, so it
no longer has a version line of its own. This gives it the same treatment
vaadin-spring already has, in the four places that named it:

- versions.json loses the flow-cdi entry, which was pinned at 16.1.2
- the BOM pins vaadin-cdi to ${flow.version}, so the generated
  flow.cdi.version property disappears with its last use
- both release-note templates take the version from core.flow and link to
  Flow's releases, matching the Spring add-on line directly above. Left
  alone they emitted a literal {{core.flow-cdi.javaVersion}}
- the changelog module list no longer looks for vaadin/cdi releases,
  which would have been tags that will never exist

Verified by generating with --platform=25.4.0-alpha1: the BOM resolves
vaadin-cdi to 25.4-SNAPSHOT via flow.version and the notes render the CDI
add-on line against Flow's releases. The generator suite reports the same
18 passing and 5 failing as it does on an unmodified main, and the
check-versions suite passes in full.
@github-actions

Copy link
Copy Markdown
Contributor

Dependencies Report

  • 🚫 Vulnerabilities:

  • 🟠 Known Vulnerabilities:

    • Vulnerabilities in: pkg:maven/me.friwi/jcef-api@jcef-ca49ada%2Bcef-135.0.20%2Bge7de5c3%2Bchromium-135.0.7049.85 [CVE-2024-21639, CVE-2024-21640, CVE-2024-9410] (owasp)
      👌 Wait for the update from the jcefmaven community. Meanwhile the swing-kit is supposed to be used with fixed websites and not to browse the internet, we have a check for that, so the only possible attacker would be the same person that created the swing application, aka our customer devs. so this vulnerability is not classified by us as critical issue
      · cpe:2.3:a:chromiumembedded:chromium_embedded_framework::::::::
      · cpe:2.3:a:ada:ada::::::::
    • Vulnerabilities in: pkg:maven/com.vaadin/vaadin-swing-kit-flow@3.0.1 [CVE-2021-33604] (owasp)
      👌 false report: this CVE is targeting Vaadin version prior 20, swing-kit-flow is using vaadin 24+ version, the related issue has been fixed.
      · cpe:2.3:a:vaadin:flow-server::::::::
      · cpe:2.3:a:vaadin:vaadin::::::::
  • 📔 No Core License Issues

  • 📔 No License Issues

  • 🟠 Changes in 25.4-SNAPSHOT since V25.3.0-beta3

    • 1 packages removed (1 external, 0 vaadin)
    • 1 packages added (1 external, 0 vaadin)
    • 155 packages modified (33 external, 122 vaadin)
    • 492 packages same (372 external, 120 vaadin)

[Click for more Details]

@ZheSun88
ZheSun88 merged commit 8e55eef into main Sep 16, 2026
3 of 4 checks passed
@ZheSun88
ZheSun88 deleted the chore/cdi-follows-flow-version branch September 16, 2026 10:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant