)]}'
{
  "log": [
    {
      "commit": "449754dcbbd64c9f09544131f67b207a4c042cb7",
      "tree": "b2af890fce5c3d2e5e8a8e104ac86d8863ccc58b",
      "parents": [
        "ae4da88339cec0dccdddae99ddf22eedfa3fad94"
      ],
      "author": {
        "name": "mikhail-0330",
        "email": "145472039+mikhail-0330@users.noreply.github.com",
        "time": "Tue Aug 25 18:53:58 2026 +0300"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Aug 25 16:53:58 2026 +0100"
      },
      "message": "feat: expose kt_defs.bzl via public bzl_library for stardoc (#1626)"
    },
    {
      "commit": "ae4da88339cec0dccdddae99ddf22eedfa3fad94",
      "tree": "7a89f92aacfffa46a54431645d63185e8c65c11a",
      "parents": [
        "794bfda773284b2294bd0c9b5f4ecc5500523d8e"
      ],
      "author": {
        "name": "Simon Mavi Stewart",
        "email": "simon.m.stewart@gmail.com",
        "time": "Thu Aug 20 11:19:33 2026 +0100"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Aug 20 11:19:33 2026 +0100"
      },
      "message": "build: update rules_kotlin to 2.4.0 (#1621)"
    },
    {
      "commit": "794bfda773284b2294bd0c9b5f4ecc5500523d8e",
      "tree": "bfad287f8b80438f122f7865e73ebf2ae7a8da4c",
      "parents": [
        "6c20569dc37c4ab10b6628bbef1a68ea75b3f5f6"
      ],
      "author": {
        "name": "Simon Mavi Stewart",
        "email": "simon.m.stewart@gmail.com",
        "time": "Thu Aug 20 11:19:14 2026 +0100"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Aug 20 11:19:14 2026 +0100"
      },
      "message": "fix: Improve Gradle resolver console output (#1623)"
    },
    {
      "commit": "6c20569dc37c4ab10b6628bbef1a68ea75b3f5f6",
      "tree": "c83f83a3766d0b8c0b325e8ba40fad6829d36d18",
      "parents": [
        "e98a2bcebf3038243243941f458fefe940e980fb"
      ],
      "author": {
        "name": "Simon Mavi Stewart",
        "email": "simon.m.stewart@gmail.com",
        "time": "Thu Aug 20 11:19:01 2026 +0100"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Aug 20 11:19:01 2026 +0100"
      },
      "message": "perf: speed up java export exclusions (#1624)\n\nSigned-off-by: Simon Mavi Stewart \u003csimon.m.stewart@gmail.com\u003e"
    },
    {
      "commit": "e98a2bcebf3038243243941f458fefe940e980fb",
      "tree": "1e4dfe70cec8f319c1955af4cfb7995a8fb00481",
      "parents": [
        "63aa53ee091459e2eb2fc2b77daba95d0e8f0090"
      ],
      "author": {
        "name": "timothy",
        "email": "387270+timothyklim@users.noreply.github.com",
        "time": "Tue Aug 18 00:02:15 2026 +0700"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Aug 17 18:02:15 2026 +0100"
      },
      "message": "Remove -noverify (#1620)\n\n-noverify was removed in JDK 27 (deprecated since JDK 13) and now causes the launcher to fail with an unrecognized option error. It was only needed for proguarded coursier JARs from very old releases: https://github.com/coursier/coursier/pull/1245"
    },
    {
      "commit": "63aa53ee091459e2eb2fc2b77daba95d0e8f0090",
      "tree": "99db723a296e8d1f97524f1ac6996d4889fe9d65",
      "parents": [
        "b234733f7ce1ffc73ddc1be840893fb61bdae3b5"
      ],
      "author": {
        "name": "Keith Smiley",
        "email": "keithbsmiley@gmail.com",
        "time": "Fri Jul 31 14:32:09 2026 -0700"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jul 31 22:32:09 2026 +0100"
      },
      "message": "Return repo_metadata from repository rules (#1616)"
    },
    {
      "commit": "b234733f7ce1ffc73ddc1be840893fb61bdae3b5",
      "tree": "9d7494422e09a893ae88d403a0030295b6b18132",
      "parents": [
        "fd9185f5e6ed7b004b3ef6acac8fd3577ca72f4a"
      ],
      "author": {
        "name": "Simon Mavi Stewart",
        "email": "simon.m.stewart@gmail.com",
        "time": "Thu Jul 23 15:59:19 2026 +0100"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Jul 23 15:59:19 2026 +0100"
      },
      "message": "Prepare for 7.1 release (#1593)\n\nMaking the example build under Bazel 9 needed protobuf pinned back to\n33.4 (35.0 requires Bazel \u003e\u003d 8, which was breaking the 7.x cell), an\nexplicit `rules_java` bazel_dep, and `load` statements for `java_library`\nand `java_proto_library` since Bazel 9 no longer autoloads them."
    },
    {
      "commit": "fd9185f5e6ed7b004b3ef6acac8fd3577ca72f4a",
      "tree": "a20ea4a19fc98ea70d4d02d8dbcd632ccfa0cf7c",
      "parents": [
        "30e29da81fef13d0c55948bb8001be8e8d65521e"
      ],
      "author": {
        "name": "Simon Mavi Stewart",
        "email": "simon.m.stewart@gmail.com",
        "time": "Mon Jul 20 22:28:31 2026 +0100"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jul 20 22:28:31 2026 +0100"
      },
      "message": "fix: force a single version per Gradle module when pinning (#1608)\n\nGradle selects one version per group:artifact and ignores classifiers,\nso forcing each classified root separately (e.g. a main jar and its\ntest-fixtures jar at different versions) made resolution unsatisfiable.\nGroup roots by module and force only the defining version: the\nunclassified root, or the highest classified request.\n\nAlso stop the resolver plugin\u0027s detached-configuration retry from\nundermining pins: skip it when the main configuration fully resolved,\nand re-apply the forced modules when it runs, since detached\nconfigurations never see `configurations.all`.\n\nCo-Authored-By: Claude \u003cnoreply@anthropic.com\u003e"
    },
    {
      "commit": "30e29da81fef13d0c55948bb8001be8e8d65521e",
      "tree": "2fca97ff94a312b92f6fbf1df7b8abfaba3a0d5f",
      "parents": [
        "5eb595d7372a9a510a8c4a6ccdef7d4851d94eac"
      ],
      "author": {
        "name": "David Zbarsky",
        "email": "dzbarsky@gmail.com",
        "time": "Mon Jul 20 12:53:34 2026 -0400"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jul 20 17:53:34 2026 +0100"
      },
      "message": "Use a UTF-8 locale for jvm_import jar actions (#1610)"
    },
    {
      "commit": "5eb595d7372a9a510a8c4a6ccdef7d4851d94eac",
      "tree": "81d5a0fb27537761371913c113855320df98eeca",
      "parents": [
        "c1b3e5ea49d1504af2499a6bc5a0639cb9d5963b"
      ],
      "author": {
        "name": "mikhail-0330",
        "email": "145472039+mikhail-0330@users.noreply.github.com",
        "time": "Thu Jul 16 02:44:42 2026 +0300"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Jul 16 00:44:42 2026 +0100"
      },
      "message": "BOM/POM coordinates condition marked as `skipped` must not be turned into `http_file downloads (#1604)"
    },
    {
      "commit": "c1b3e5ea49d1504af2499a6bc5a0639cb9d5963b",
      "tree": "6cfaa3aba4aa7b4c125db9971cb12ec95c729061",
      "parents": [
        "60611a91a941dd79ab08c66d706b1a44610dfe1e"
      ],
      "author": {
        "name": "Simon Mavi Stewart",
        "email": "simon.m.stewart@gmail.com",
        "time": "Wed Jul 15 21:51:28 2026 +0100"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Jul 15 21:51:28 2026 +0100"
      },
      "message": "fix: honour pinned versions in external resolvers (#1606)"
    },
    {
      "commit": "60611a91a941dd79ab08c66d706b1a44610dfe1e",
      "tree": "bdadb3fa2180fc6c31de9259e77594618802a53e",
      "parents": [
        "2c8e8ac3d0d23294cd666c6eeaea7770a721768f"
      ],
      "author": {
        "name": "JonathanPerry651",
        "email": "jonathan.perry@gs.com",
        "time": "Fri Jul 10 12:14:03 2026 +0100"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jul 10 12:14:03 2026 +0100"
      },
      "message": "feat: Support pluggable dependency download and metadata caching SPIs (#1589)\n\nProvides pluggable SPIs for rules_jvm_external\u0027s dependency resolution, allowing custom download/caching and authentication implementations (such as integrating with Bazel\u0027s remote fetcher/downloader APIs) to be registered via classpath plugins.\n\nKey Changes:\n1. Public API Targets \u0026 SPIs:\n   - Created public interfaces for MetadataService, DependencyMetadata, and DownloadService.\n   - Added a generic SpiLoader utility to load classpath SPI service implementations (ensuring at most one implementation is loaded per SPI).\n   - Exposed custom classpath library loading via the new resolver_extra_dependencies attribute.\n   - Decomposed the API targets into fine-grained libraries: :api_core, :download_service, :metadata_service, and :spi_loader.\n   - Relocated the build definition closer to the sources in //resolver/src/main/java/com/github/bazelbuild/rules_jvm_external/resolver/BUILD.\n   - Flattened public SPI classes into a single package (com.github.bazelbuild.rules_jvm_external.resolver) to prevent split-package issues and avoid spanning multiple packages.\n\n2. Aether \u0026 Downloader SPI Integration:\n   - Replaced Aether\u0027s default HTTP transport with a custom HttpDownloaderTransporterFactory, routing all POM, BOM, and metadata lookups through the pluggable DownloadService SPI.\n   - Extracted HttpDownloaderTransporter into its own top-level package-private class.\n   - Renamed DownloadService.download to get to match HTTP verb naming conventions and align with head.\n   - Implemented null-safe defensive copying of collections in DependencyMetadata constructor using Set.copyOf/Map.copyOf.\n\n3. Inline URL Credentials Handling:\n   - Aether downloads are now routed through the pluggable DownloadService SPI backed by HttpDownloader without inline credentials support (making both resolution and downloading fail consistently). Users must configure credentials via .netrc instead.\n   - Deleted the shouldDownloadOverHttpWithAuthenticationPassedInOnRepoUrl test from ResolverTestBase.java since that flow does not work and is explicitly unsupported.\n\n4. Cleanup \u0026 Optimization:\n   - Removed final modifier from SpiLoader class and refactored joining logic to use Guava Joiner.\n   - Removed redundant metadata caches and unused resolver binaries."
    },
    {
      "commit": "2c8e8ac3d0d23294cd666c6eeaea7770a721768f",
      "tree": "8ca4d14c2d319b2123df4cc38a8050d25b5602ab",
      "parents": [
        "97d4d4f79022fcc82a926227a19e32146b63e43e"
      ],
      "author": {
        "name": "Simon Mavi Stewart",
        "email": "simon.m.stewart@gmail.com",
        "time": "Wed Jul 08 20:31:04 2026 +0100"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Jul 08 20:31:04 2026 +0100"
      },
      "message": "Preserve Gradle variant identity in the lock graph (#1576)\n\nThe Gradle resolver was flattening multiple selected variants of the same\nmodule into a single dependency node. When a module was resolved both as its\nmain jar and as test fixtures, we merged their outgoing dependencies and then\nstamped that merged child set onto both output coordinates. That can create\nself loops and main-to-test-fixtures back-edges in the generated lockfile,\nwhich Bazel cannot repair downstream.\n\nFix this by keeping variant identity through resolution so each selected\nvariant keeps its own dependency set. Variants are classified and artifacts\nare attached to them using Gradle capabilities, the canonical identity for\nfeature variants, so any capability-based variant is handled, not just test\nfixtures. Requested test-fixtures classifiers resolve through Gradle\u0027s\ntestFixtures(...) notation instead of being treated like an ad hoc classifier\nfetch."
    },
    {
      "commit": "97d4d4f79022fcc82a926227a19e32146b63e43e",
      "tree": "dc4e3cd1da7484d8f6f1942674abe992614aa4cb",
      "parents": [
        "06db7d7d6f695a0b1df3a75e88773709bb10f031"
      ],
      "author": {
        "name": "Simon Mavi Stewart",
        "email": "simon.m.stewart@gmail.com",
        "time": "Mon Jul 06 18:49:42 2026 +0100"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jul 06 18:49:42 2026 +0100"
      },
      "message": "fix: make :outdated work when runfiles trees are disabled (#1602)\n\n`bazel run @maven//:outdated` failed with \"Unable to access jarfile\"\nunder --noenable_runfiles (the default on Windows) because the\ngenerated sh_binary passed cwd-relative rootpaths, which only resolve\ninside a materialised runfiles tree. Resolve the arguments with the\nBash runfiles library instead, as :pin already does.\n\nCo-authored-by: Claude \u003cnoreply@anthropic.com\u003e"
    },
    {
      "commit": "06db7d7d6f695a0b1df3a75e88773709bb10f031",
      "tree": "e1b8bb99823121cc81f17359bfa965e85cb298b0",
      "parents": [
        "b6dd5dca253055505fbd2b78ae4db9035f3e8882"
      ],
      "author": {
        "name": "Simon Mavi Stewart",
        "email": "simon.m.stewart@gmail.com",
        "time": "Fri Jul 03 15:26:21 2026 +0100"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jul 03 15:26:21 2026 +0100"
      },
      "message": "Enable RJE_UNSAFE_CACHE by default (#1584)\n\nThe shared cache is now used unless RJE_UNSAFE_CACHE is set to \"0\" or\n\"false\". The CLI flag --use_unsafe_shared_cache has been replaced by\n--use_unique_cache, which opts out of the shared cache.\n\nMaven and Gradle docs updated accordingly. Coursier behaviour is\nunchanged for now.\n\n---------\n\nCo-authored-by: Claude \u003cnoreply@anthropic.com\u003e"
    },
    {
      "commit": "b6dd5dca253055505fbd2b78ae4db9035f3e8882",
      "tree": "a4a8713a3888dd5154f955dcc5efdb45054e9443",
      "parents": [
        "38ac77b2511ec25a6b1624da37adcebaae6dec14"
      ],
      "author": {
        "name": "Nikolay M",
        "email": "dolphinn@bk.ru",
        "time": "Fri Jul 03 16:06:46 2026 +0300"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jul 03 14:06:46 2026 +0100"
      },
      "message": "Don\u0027t deduplicate additional_coursier_options (#1596)\n\nCo-authored-by: Nikolay \u003cn.matyushin@tawasal.ae\u003e"
    },
    {
      "commit": "38ac77b2511ec25a6b1624da37adcebaae6dec14",
      "tree": "9b93387288e49f9474ffba837aebc5554541b7fe",
      "parents": [
        "01a60c63f4d217d7de4b530cebdddbca54a97704"
      ],
      "author": {
        "name": "Simon Mavi Stewart",
        "email": "simon.m.stewart@gmail.com",
        "time": "Fri Jul 03 13:14:50 2026 +0100"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jul 03 13:14:50 2026 +0100"
      },
      "message": "Skip package-info.class when indexing jars (#1597)\n\n`package-info.class` files only hold package-level annotations and\ncannot be referenced from production code, so they should never\nappear in the indexed class set."
    },
    {
      "commit": "01a60c63f4d217d7de4b530cebdddbca54a97704",
      "tree": "d853b8fbbdb6e0c51aaa60442e074917c437cf3a",
      "parents": [
        "32fd66402bf7ef93dfc470909c09b5152da2bc39"
      ],
      "author": {
        "name": "Simon Mavi Stewart",
        "email": "simon.m.stewart@gmail.com",
        "time": "Wed Jul 01 16:40:55 2026 +0100"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Jul 01 16:40:55 2026 +0100"
      },
      "message": "Index top-level kotlin functions, properties and type aliases properly. (#1599)\n\nTop-level Kotlin functions, properties, and type aliases compile into a synthetic \u003cFile\u003eKt facade, so they were invisible to the class-name index and could not be attributed to an artifact in split packages.\n\nRead them from the @kotlin.Metadata annotation via kotlin-metadata-jvm and fold the public ones into the class index under their Kotlin source names."
    },
    {
      "commit": "32fd66402bf7ef93dfc470909c09b5152da2bc39",
      "tree": "190f5f2b447ddcd537fb09d8caace301da1f0bf1",
      "parents": [
        "c0ff7f62d380ebac995235d2ac5411e417245343"
      ],
      "author": {
        "name": "Simon Mavi Stewart",
        "email": "simon.m.stewart@gmail.com",
        "time": "Wed Jul 01 16:00:11 2026 +0100"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Jul 01 16:00:11 2026 +0100"
      },
      "message": "fix: stop Gradle daemons after dependency resolution (#1598)\n\nClosing the ProjectConnection alone leaves the Tooling API\u0027s daemon\nrunning for reuse. Call disconnect() on the connector so the daemon\nis shut down once pinning completes."
    },
    {
      "commit": "c0ff7f62d380ebac995235d2ac5411e417245343",
      "tree": "c4e66385fea976da60b102487f22a4fa25861c02",
      "parents": [
        "723d2033ec6967638859ffda55400450478eeaa2"
      ],
      "author": {
        "name": "Ben Lee",
        "email": "ben@ben.cm",
        "time": "Mon Jun 29 11:18:02 2026 -0700"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jun 29 19:18:02 2026 +0100"
      },
      "message": "Fix TOML AAR overrides using original artifact copy targets (#1600)"
    },
    {
      "commit": "723d2033ec6967638859ffda55400450478eeaa2",
      "tree": "b9617ddc3e612dc54c03ebce91ab825a0c7db623",
      "parents": [
        "8f8a17e0ce1a09f763ebea8bb6e867d9e949fdbc"
      ],
      "author": {
        "name": "Simon Mavi Stewart",
        "email": "simon.m.stewart@gmail.com",
        "time": "Wed Jun 17 20:25:58 2026 +0100"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Jun 17 20:25:58 2026 +0100"
      },
      "message": "Fix resolver NPE for no-binary artifacts (#1595)"
    },
    {
      "commit": "8f8a17e0ce1a09f763ebea8bb6e867d9e949fdbc",
      "tree": "ce8c387d60a3ce78124450e4360188fb5858fd07",
      "parents": [
        "87f44511325b139e99699a12c0c21be81151e11b"
      ],
      "author": {
        "name": "Simon Mavi Stewart",
        "email": "simon.m.stewart@gmail.com",
        "time": "Sun Jun 14 12:47:21 2026 +0100"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun Jun 14 12:47:21 2026 +0100"
      },
      "message": "Add `publish-to-bcr` automation (#1587)"
    },
    {
      "commit": "87f44511325b139e99699a12c0c21be81151e11b",
      "tree": "8242d1b07d895681240ee9690b6cabfd1991eee6",
      "parents": [
        "8378beb627e19a3c68f5d76408c0f72d5191da6a"
      ],
      "author": {
        "name": "Simon Mavi Stewart",
        "email": "simon.m.stewart@gmail.com",
        "time": "Sun Jun 14 12:46:42 2026 +0100"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun Jun 14 12:46:42 2026 +0100"
      },
      "message": "Preserve compound archive extensions when publishing (#1590)"
    },
    {
      "commit": "8378beb627e19a3c68f5d76408c0f72d5191da6a",
      "tree": "e9ec9a82fcbe802b90ca05599d93e58b26ee7ecc",
      "parents": [
        "9772dfacef0d67cf1371146a75f965bcbcdb78c2"
      ],
      "author": {
        "name": "Simon Mavi Stewart",
        "email": "simon.m.stewart@gmail.com",
        "time": "Sun Jun 14 12:46:32 2026 +0100"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun Jun 14 12:46:32 2026 +0100"
      },
      "message": "Fix null shasum artifacts in v3 locks (#1591)"
    },
    {
      "commit": "9772dfacef0d67cf1371146a75f965bcbcdb78c2",
      "tree": "187f345d3739fdca5dfe9f5f94c79805b5bc2692",
      "parents": [
        "7d65543abbd27efffc5210d6498b4f52ee6def78"
      ],
      "author": {
        "name": "Simon Mavi Stewart",
        "email": "simon.m.stewart@gmail.com",
        "time": "Sun Jun 14 12:46:21 2026 +0100"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun Jun 14 12:46:21 2026 +0100"
      },
      "message": "Fix BOM-only pinning (#1592)"
    },
    {
      "commit": "7d65543abbd27efffc5210d6498b4f52ee6def78",
      "tree": "12c5edb78732e9ee0ebccb6598e7daddb592a283",
      "parents": [
        "e37e63033151ef69a23a9c68332e0573e8490ab0"
      ],
      "author": {
        "name": "Simon Mavi Stewart",
        "email": "simon.m.stewart@gmail.com",
        "time": "Sun Jun 14 12:45:59 2026 +0100"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun Jun 14 12:45:59 2026 +0100"
      },
      "message": "Apply Maven exclusions to generated deps (#1594)"
    },
    {
      "commit": "e37e63033151ef69a23a9c68332e0573e8490ab0",
      "tree": "150973e8ef4b5635102b661f8a1e998ba04e05b7",
      "parents": [
        "ba6d3342e7c2ed4789d0b41b370052e10ae88d11"
      ],
      "author": {
        "name": "Simon Mavi Stewart",
        "email": "simon.m.stewart@gmail.com",
        "time": "Wed Jun 10 23:41:07 2026 +0100"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Jun 10 23:41:07 2026 +0100"
      },
      "message": "Allow boms to be defined in the gradle version catalogues (#1543)"
    },
    {
      "commit": "ba6d3342e7c2ed4789d0b41b370052e10ae88d11",
      "tree": "b4dc3638171338097bf723e47fa8700b45dbda0e",
      "parents": [
        "77128c98ca04e23f0a96d9f130726f9920e7f056"
      ],
      "author": {
        "name": "Simon Mavi Stewart",
        "email": "simon.m.stewart@gmail.com",
        "time": "Wed Jun 10 23:40:34 2026 +0100"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Jun 10 23:40:34 2026 +0100"
      },
      "message": "Make `amend_artifact` also match BOMs (#1586)\n\n`amend_artifact` previously searched only the `artifacts` list, so a BOM\n(declared via `install(boms \u003d ...)` or split out of a `from_toml`\n`libs.versions.toml` via `bom_modules`) could not be amended. The\namendment failed with \"No artifact found matching coordinates\" because\nBOMs are tracked in a separate list that the amendment never searched.\n\n`amend_artifact` now searches both the artifacts and boms lists, so a\nBOM\u0027s version and other properties can be adjusted through the same\nmechanism as a regular artifact (for example, force-pinning a BOM\nversion so transitive deps can\u0027t silently upgrade it).\n\nAdd unit tests covering amendment of artifacts, BOMs, and the\nno-match case.\n\nCo-authored-by: Claude Opus 4.7 \u003cnoreply@anthropic.com\u003e"
    },
    {
      "commit": "77128c98ca04e23f0a96d9f130726f9920e7f056",
      "tree": "d6bbfea9834ea0c389cd2ce2ae4c08ca6f3821af",
      "parents": [
        "a8de4f33484913a25b3b052966130849735e4fa0"
      ],
      "author": {
        "name": "Simon Mavi Stewart",
        "email": "simon.m.stewart@gmail.com",
        "time": "Wed Jun 10 23:39:59 2026 +0100"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Jun 10 23:39:59 2026 +0100"
      },
      "message": "Refactor: carry a `ResolvedArtifact` for every resolution node when resolving (#1585)\n\nReplace the `Map\u003cCoordinates, Path\u003e` side-channel on `ResolutionResult`\nwith a `Map\u003cCoordinates, ResolvedArtifact\u003e` that has an entry for every\nnode in the resolved graph. Each `ResolvedArtifact` holds its coordinates\nand an optional path, so \"this node has no known binary\" is represented\nexplicitly rather than inferred from an absent map entry.\n\nThis is a pure refactoring: the Maven and Gradle resolvers populate the\nnew shape from exactly the information they already had, the downloader\nstill receives the same set of known paths, and the lock file, its\nformat, and the resolved-artifact hashes are all unchanged.\n\nCo-Authored-By: Claude Opus 4.7 \u003cnoreply@anthropic.com\u003e"
    },
    {
      "commit": "a8de4f33484913a25b3b052966130849735e4fa0",
      "tree": "4c85fadc17a6d4a58aa1edacf90984525f18f514",
      "parents": [
        "af5ef5648fe5265921ca561428dc3a4f92751595"
      ],
      "author": {
        "name": "David Zbarsky",
        "email": "dzbarsky@gmail.com",
        "time": "Wed Jun 10 18:38:16 2026 -0400"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Jun 10 23:38:16 2026 +0100"
      },
      "message": "Run jvm_import jar tools with exec Java (#1583)\n\nInvoke AddJarManifestEntry_deploy.jar with current_java_runtime in the exec configuration instead of executing the AddJarManifestEntry java_binary launcher. This preserves --tool_java_runtime_version and selects Java for the execution platform when the target and execution platforms differ.\n\nTreat AddJarManifestEntry_deploy.jar and JavaRuntimeInfo.files as action tools.\n\nAdd jvm_import_uses_execution_platform_java_runtime_test with an Android s390x target platform. Android s390x has no Java runtime toolchain, so the test fails if StampJarManifest or CreateCompileJar resolves Java against the target platform. The test also verifies that both actions pass AddJarManifestEntry_deploy.jar to Java."
    },
    {
      "commit": "af5ef5648fe5265921ca561428dc3a4f92751595",
      "tree": "6c4a2ed75d142b1046d000c6fb34592020ef4926",
      "parents": [
        "b99243e596b921bba8771bf60f4d6b12cdae6070"
      ],
      "author": {
        "name": "Tharaka De Silva",
        "email": "tharaka.uo@gmail.com",
        "time": "Tue Jun 09 10:42:49 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Jun 09 09:42:49 2026 +0100"
      },
      "message": "fix: resolve concurrent NPE in ErrorReportingListener (#1152) (#1546)\n\nUse Collections.synchronizedList and synchronized block in\ngetExceptions() to prevent NullPointerException when multiple\nthreads add exceptions concurrently during Maven resolution.\n\nExtract common addExceptionIfPresent method with null-safe event check.\nAdd ErrorReportingListenerTest to verify thread safety.\n\nCloses #1152"
    },
    {
      "commit": "b99243e596b921bba8771bf60f4d6b12cdae6070",
      "tree": "9f59419f0245c749cb07d247199ac5674663bd3f",
      "parents": [
        "18abf9cd2837cffa510836a1191ff59b3a938a4e"
      ],
      "author": {
        "name": "Collin Funk",
        "email": "collin.funk1@gmail.com",
        "time": "Tue Jun 09 01:37:55 2026 -0700"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Jun 09 09:37:55 2026 +0100"
      },
      "message": "Fix GitHub search query in README (#1550)\n\nThe `filename:` query was a part of a legacy implementation of code\nsearch. The current equivalent is `path:` [1].\n\n[1] https://github.com/github/docs/issues/24666"
    },
    {
      "commit": "18abf9cd2837cffa510836a1191ff59b3a938a4e",
      "tree": "5d920a27e66f4bf685062352ee2b9cb417632496",
      "parents": [
        "79e1c370c170ed4f8582c8e197efeee6df66660d"
      ],
      "author": {
        "name": "Sergey Tyurin",
        "email": "sergey.v.tyurin@gmail.com",
        "time": "Tue Jun 09 01:36:44 2026 -0700"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Jun 09 09:36:44 2026 +0100"
      },
      "message": "Fix link to docs/bzlmod.md in README.md (#1564)"
    },
    {
      "commit": "79e1c370c170ed4f8582c8e197efeee6df66660d",
      "tree": "ebdb21d01d5eecb30a2fbde9021708711c657890",
      "parents": [
        "96b3926a359ff14300f20ead67244e9abe8e0505"
      ],
      "author": {
        "name": "Simon Mavi Stewart",
        "email": "simon.m.stewart@gmail.com",
        "time": "Tue Jun 09 09:36:04 2026 +0100"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Jun 09 09:36:04 2026 +0100"
      },
      "message": "Update Gradle to 9.5.0 (#1569)\n\nGradle 9.x requires JVM 17 to run, so this also bumps the project\u0027s\ndefault Java toolchain in .bazelrc from 11 to 17. Downstream projects\ncan continue targeting Java 11 with their own .bazelrc, though using\nthe Gradle resolver will require JVM 17+.\n\n---------\n\nCo-authored-by: Claude Opus 4.7 \u003cnoreply@anthropic.com\u003e"
    },
    {
      "commit": "96b3926a359ff14300f20ead67244e9abe8e0505",
      "tree": "8c455ebb4140c8cb42e9a00b81afc5fc71853f70",
      "parents": [
        "aa34b3f323f830e7b7a2132aa07d7b1de3500d1b"
      ],
      "author": {
        "name": "Simon Mavi Stewart",
        "email": "simon.m.stewart@gmail.com",
        "time": "Wed Jun 03 23:22:44 2026 +0100"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Jun 03 23:22:44 2026 +0100"
      },
      "message": "Update remaining examples (#1581)\n\nThis involves rewriting the Android Kotlin app to avoid AppCompat as otherwise\nthe `install` tag became a mess, and that\u0027s not what we\u0027re trying to demonstrate."
    },
    {
      "commit": "aa34b3f323f830e7b7a2132aa07d7b1de3500d1b",
      "tree": "e7e7ea4e597ea6e4a63c7e267a0bb17ea7a3f27c",
      "parents": [
        "bca547138bbae03f39d580f54c2bd899d88d5ab5"
      ],
      "author": {
        "name": "Simon Mavi Stewart",
        "email": "simon.m.stewart@gmail.com",
        "time": "Wed Jun 03 23:22:28 2026 +0100"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Jun 03 23:22:28 2026 +0100"
      },
      "message": "Bump the deps in the Spring Boot examples (#1580)"
    },
    {
      "commit": "bca547138bbae03f39d580f54c2bd899d88d5ab5",
      "tree": "f48611d08f9f29f1996a6ee000b411e07b16eb30",
      "parents": [
        "4476a218a753ef0318be4e5978a23341119c552b"
      ],
      "author": {
        "name": "Titus Fortner",
        "email": "titusfortner@users.noreply.github.com",
        "time": "Tue May 19 04:25:39 2026 -0500"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue May 19 11:25:39 2026 +0200"
      },
      "message": "Fix MavenPublisher to support POM-only publications (#1574)"
    },
    {
      "commit": "4476a218a753ef0318be4e5978a23341119c552b",
      "tree": "185d66c05fc4297cf63c757136c222fc0a2ea63f",
      "parents": [
        "4df0012a0cda10b5515883b40e02b1b56641f2d0"
      ],
      "author": {
        "name": "Titus Fortner",
        "email": "titusfortner@users.noreply.github.com",
        "time": "Mon May 18 03:26:46 2026 -0500"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon May 18 09:26:46 2026 +0100"
      },
      "message": "update environment variable handling for pinning (#1573)"
    },
    {
      "commit": "4df0012a0cda10b5515883b40e02b1b56641f2d0",
      "tree": "95a818bd7b645049c2e782c017787894627f4d94",
      "parents": [
        "548255817b4979bbf33152397eb4c745ccce2b9a"
      ],
      "author": {
        "name": "Andrius Bankauskas",
        "email": "and.bankauskas@gmail.com",
        "time": "Fri May 15 17:37:00 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri May 15 17:37:00 2026 +0200"
      },
      "message": "Prefer getenv to env.get (#1568)"
    },
    {
      "commit": "548255817b4979bbf33152397eb4c745ccce2b9a",
      "tree": "522fc39c3ad5d9c63783f67cac8c3b0421bfd5d0",
      "parents": [
        "170cafab638951b66ac74c0529acc089b95aab44"
      ],
      "author": {
        "name": "Ted Kaplan",
        "email": "tkaplan@roku.com",
        "time": "Tue Apr 21 11:24:08 2026 -0400"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Apr 21 16:24:08 2026 +0100"
      },
      "message": "Upload primary artifact before uploading hashes in MavenPublisher (#1548)"
    },
    {
      "commit": "170cafab638951b66ac74c0529acc089b95aab44",
      "tree": "1e1c8291fd6c74f8bcb29475ccf91322975e88bf",
      "parents": [
        "bc3fe5f772a3a57e478ad764f4ef1227989fc37f"
      ],
      "author": {
        "name": "Sitaktif",
        "email": "rchossart@apple.com",
        "time": "Mon Apr 20 17:10:01 2026 +0100"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Apr 20 17:10:01 2026 +0100"
      },
      "message": "Update deps before 7.0 release (#1561)"
    },
    {
      "commit": "bc3fe5f772a3a57e478ad764f4ef1227989fc37f",
      "tree": "7b510dc33ddec42f56cf654352ed44b9a258e43e",
      "parents": [
        "8d5cd8bcd65a1ba2b6a38c2d7256caea8b758ce6"
      ],
      "author": {
        "name": "Mikhail Filippov",
        "email": "mikhail@filippov.me",
        "time": "Thu Apr 16 13:38:36 2026 +0400"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Apr 16 10:38:36 2026 +0100"
      },
      "message": "fix: sort repositories in v3 lock file hash to match Java resolver order (#1557)"
    },
    {
      "commit": "8d5cd8bcd65a1ba2b6a38c2d7256caea8b758ce6",
      "tree": "2bce045f90c0e80c334f4db8094e7931198f9476",
      "parents": [
        "ff03b5759d01c22e16585f2acd1f063d871b9dad"
      ],
      "author": {
        "name": "Simon Mavi Stewart",
        "email": "simon.m.stewart@gmail.com",
        "time": "Wed Apr 15 22:57:34 2026 +0100"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Apr 15 22:57:34 2026 +0100"
      },
      "message": "Fix problems with Windows CI builds (#1566)"
    },
    {
      "commit": "ff03b5759d01c22e16585f2acd1f063d871b9dad",
      "tree": "f5109cc04683abb9bfd77e69f19f069d2164d8aa",
      "parents": [
        "78ba950a1fcf2c01c5aa2fc3b121528330351d7c"
      ],
      "author": {
        "name": "Ted Kaplan",
        "email": "tkaplan@roku.com",
        "time": "Thu Feb 12 06:21:18 2026 -0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Feb 12 14:21:18 2026 +0000"
      },
      "message": "Disable hash uploads for snapshot revisions (#1544)\n\n"
    },
    {
      "commit": "78ba950a1fcf2c01c5aa2fc3b121528330351d7c",
      "tree": "e7604e5094eb683d12072c3ff6a5cadfb6a02549",
      "parents": [
        "4f497f0bc104c8afb5f7ce12854dae9670ed4d8b"
      ],
      "author": {
        "name": "Simon Mavi Stewart",
        "email": "simon.m.stewart@gmail.com",
        "time": "Wed Feb 11 21:16:26 2026 +0000"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Feb 11 21:16:26 2026 +0000"
      },
      "message": "Switch to `toml.bzl` for TOML parsing (#1540)\n\n"
    },
    {
      "commit": "4f497f0bc104c8afb5f7ce12854dae9670ed4d8b",
      "tree": "e74c3f4f7697588440d9cfb8c630753e7f6ac76a",
      "parents": [
        "68cee9cfb6c0121a2c3e82be3940be1e313fba14"
      ],
      "author": {
        "name": "Kartikaya Gupta (kats)",
        "email": "staktrace@users.noreply.github.com",
        "time": "Wed Feb 11 16:01:39 2026 -0500"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Feb 11 21:01:39 2026 +0000"
      },
      "message": "Also handle the force_version field in the version catalog (#1542)\n\n"
    },
    {
      "commit": "68cee9cfb6c0121a2c3e82be3940be1e313fba14",
      "tree": "65eb35721cd51a36c0e5c83f5fb5e2060aea52c6",
      "parents": [
        "917e31dd0d11a6e2cf1064664b4a2a4d023d3139"
      ],
      "author": {
        "name": "Simon Mavi Stewart",
        "email": "simon.m.stewart@gmail.com",
        "time": "Wed Feb 11 20:43:20 2026 +0000"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Feb 11 20:43:20 2026 +0000"
      },
      "message": "Remove workspace-based dependencies and ensure RJE works with Bazel 9 (#1536)\n\n"
    },
    {
      "commit": "917e31dd0d11a6e2cf1064664b4a2a4d023d3139",
      "tree": "c940bb657a360d3723b6714550864495fd5ac0f9",
      "parents": [
        "7e89d206c2b77caf36aea3c8b44271f9f1c0f75a"
      ],
      "author": {
        "name": "Kartikaya Gupta (kats)",
        "email": "staktrace@users.noreply.github.com",
        "time": "Wed Feb 11 11:52:56 2026 -0500"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Feb 11 16:52:56 2026 +0000"
      },
      "message": "Add a test for the extra toml field handling (#1541)\n\nGoes with https://github.com/bazel-contrib/rules_jvm_external/pull/1539"
    },
    {
      "commit": "7e89d206c2b77caf36aea3c8b44271f9f1c0f75a",
      "tree": "564872775b4a57e548dba9b2412a8db2aa2d38cc",
      "parents": [
        "dbff0c47e7e36180a0fda66613fbb5cbfbe1cde8"
      ],
      "author": {
        "name": "vadikmironov",
        "email": "77026200+vadikmironov@users.noreply.github.com",
        "time": "Tue Feb 10 16:28:34 2026 +0000"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Feb 10 16:28:34 2026 +0000"
      },
      "message": "fix: Handle email-style usernames in Coursier cache path credential stripping (#1538)\n\nWhen a repository uses an email address as the username (e.g.,\nuser@domain.com), Coursier encodes the cache path as\n\"user%40domain.com%40host\". The existing credential stripping logic\nuses find(\"%40\") which locates the first %40 (the email\u0027s @), leaving\n\"domain.com%40host\" in the path instead of just \"host\".\n\nThis change:\n- Replaces find(\"%40\") with rfind(\"%40\") to locate the last %40,\n  which is always the user@host separator\n- Extracts the stripping logic into a public\n  strip_credentials_from_cache_path() function for testability\n- Adds unit tests covering: no credentials, simple username, and\n  email-style username cases\n\nCo-authored-by: Claude Opus 4.6 \u003cnoreply@anthropic.com\u003e"
    },
    {
      "commit": "dbff0c47e7e36180a0fda66613fbb5cbfbe1cde8",
      "tree": "f423901110156da7c00827f9de4d61579a98dc52",
      "parents": [
        "f23697ea7098330461558bedd742b8131acc7f88"
      ],
      "author": {
        "name": "Kartikaya Gupta (kats)",
        "email": "staktrace@users.noreply.github.com",
        "time": "Tue Feb 10 05:49:37 2026 -0500"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Feb 10 10:49:37 2026 +0000"
      },
      "message": "Add support for classifier and exclusions fields in toml files (#1539)\n\nThese are not supported by gradle but it makes life a lot easier when trying to use a common format for bazel and renovate."
    },
    {
      "commit": "f23697ea7098330461558bedd742b8131acc7f88",
      "tree": "41ecd505429426cd0520ee8bd47986b2ff3302dd",
      "parents": [
        "9b72b6ed99843fd50b22f6f6aba685ea3748b088"
      ],
      "author": {
        "name": "Simon Mavi Stewart",
        "email": "simon.m.stewart@gmail.com",
        "time": "Wed Feb 04 21:03:39 2026 +0000"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Feb 04 21:03:39 2026 +0000"
      },
      "message": "Prepare for 6.10 release (#1521)\n\nIncludes rebuilding the prebuilt jars."
    },
    {
      "commit": "9b72b6ed99843fd50b22f6f6aba685ea3748b088",
      "tree": "0fd839a3f27573da1b40039ae78767a95547336c",
      "parents": [
        "65eb4ad85a97be37bb0decfb06ac3fef996d82bf"
      ],
      "author": {
        "name": "Ted Kaplan",
        "email": "tkaplan@roku.com",
        "time": "Tue Feb 03 04:22:59 2026 -0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Feb 03 12:22:59 2026 +0000"
      },
      "message": "Add presubmit check for prebuilt jars (#1486)\n\n"
    },
    {
      "commit": "65eb4ad85a97be37bb0decfb06ac3fef996d82bf",
      "tree": "248395a720194fa2f837454159e35112cf362ae1",
      "parents": [
        "66e07e4c08799f1a42d0c4b7602be0438e00d444"
      ],
      "author": {
        "name": "Igor Perikov",
        "email": "IgorPerikov@users.noreply.github.com",
        "time": "Tue Feb 03 13:22:17 2026 +0100"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Feb 03 12:22:17 2026 +0000"
      },
      "message": "Upload artifacts in parallel (address artifactorys \"Maven Snapshot Version Behaviour\") (#1524)\n\n"
    },
    {
      "commit": "66e07e4c08799f1a42d0c4b7602be0438e00d444",
      "tree": "00cc386ecf106eb63e46c51075bb80840c0483d4",
      "parents": [
        "e43fffe6c33057f41935cd75f7cb44c3b6b61b7f"
      ],
      "author": {
        "name": "Alberto Cavalcante",
        "email": "alberto@cavalcante.uk",
        "time": "Tue Feb 03 04:20:40 2026 -0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Feb 03 12:20:40 2026 +0000"
      },
      "message": "feat: Support COURSIER_SHA256 environment variable (#1527)\n\nAllows users to specify a different Coursier version by overriding\nthe SHA256 checksum, complementing the existing COURSIER_URL env var.\n\nCloses bazel-contrib/rules_jvm_external#1526"
    },
    {
      "commit": "e43fffe6c33057f41935cd75f7cb44c3b6b61b7f",
      "tree": "3e7c38d31d3f18bb9ea8c6e7e6154de2720bcda6",
      "parents": [
        "bf2ecf4d6824e0e7e4e2facd413aa1ca3387b5af"
      ],
      "author": {
        "name": "Honnix",
        "email": "honnix@users.noreply.github.com",
        "time": "Tue Feb 03 13:19:19 2026 +0100"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Feb 03 12:19:19 2026 +0000"
      },
      "message": "fix: Do not add coursier opts when run other tools (#1531)\n\n"
    },
    {
      "commit": "bf2ecf4d6824e0e7e4e2facd413aa1ca3387b5af",
      "tree": "7ebf5fab64d89e63441adae6598a4b489f1470b1",
      "parents": [
        "2c50ea48e365dd47a20454a9f260cb7736f9435d"
      ],
      "author": {
        "name": "JonathanPerry651",
        "email": "jonathan.perry@gs.com",
        "time": "Tue Feb 03 12:04:57 2026 +0000"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Feb 03 12:04:57 2026 +0000"
      },
      "message": "fix: add string attributes to `amend_artifact` for explicit unset state (#1499)\n\n---------\n\nCo-authored-by: Jonathan Perry \u003cjonpez63@gmail.com\u003e\n"
    },
    {
      "commit": "2c50ea48e365dd47a20454a9f260cb7736f9435d",
      "tree": "fe564d989c0a21cea622ce6bc425bf8a10da88a5",
      "parents": [
        "82e529ab064dc583a61892c8fc92b8ff0f70ded6"
      ],
      "author": {
        "name": "Steve Barrau",
        "email": "98589981+stevebarrau@users.noreply.github.com",
        "time": "Thu Jan 22 11:11:41 2026 +0000"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Jan 22 11:11:41 2026 +0000"
      },
      "message": "fix: use forward slash separator in Maven purl format (#1530)\n\nUpdate the Maven package URL (purl) format to use forward slash (/)\ninstead of colon (:) as the separator between group and artifact,\nfollowing the correct purl specification for Maven packages.\n\nThe format now correctly generates:\n  pkg:maven/group/artifact@version\ninstead of:\n  pkg:maven/group:artifact@version\n\nhttps://github.com/package-url/purl-spec/blob/main/types-doc/maven-definition.md"
    },
    {
      "commit": "82e529ab064dc583a61892c8fc92b8ff0f70ded6",
      "tree": "c744b751c0caa3b1423bc4e9313d717363c6ebc2",
      "parents": [
        "50b20118912cc255a27465c5e23f354c592fc0b4"
      ],
      "author": {
        "name": "cheister",
        "email": "cheister@squareup.com",
        "time": "Wed Jan 21 19:39:52 2026 -0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Jan 21 19:39:52 2026 -0800"
      },
      "message": "Load rules from specific bzl files and add sh_test imports (#1529)\n\n* bazel run //scripts:format\n\n* Load rules from specific bzl files and add sh_test imports\n\n* Prefer BUILD to BUILD.bazel when we can"
    },
    {
      "commit": "50b20118912cc255a27465c5e23f354c592fc0b4",
      "tree": "f609767eb66a70d46278f0988d4d6b4a12d8c416",
      "parents": [
        "250946830a766a85b035f60d1d5da369cc80d785"
      ],
      "author": {
        "name": "MarconZet",
        "email": "25779550+MarconZet@users.noreply.github.com",
        "time": "Wed Jan 21 22:26:29 2026 +0100"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Jan 21 21:26:29 2026 +0000"
      },
      "message": "Added non-conflicting hash for install files (#1454)\n\n"
    },
    {
      "commit": "250946830a766a85b035f60d1d5da369cc80d785",
      "tree": "541c4f4641fb0397b2fb398f0445a3f4d67550c9",
      "parents": [
        "95935ff5551dc280bbc6ce96f02e6cad6adf6e7d"
      ],
      "author": {
        "name": "Jeff Mace",
        "email": "jeffmace@gmail.com",
        "time": "Mon Jan 19 07:41:18 2026 -0500"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jan 19 12:41:18 2026 +0000"
      },
      "message": "Update the maven and coursier resolver tests to create a class index file. (#1519)\n\nValidation of the index file for `coursier` is disabled until it works as expected.\n"
    },
    {
      "commit": "95935ff5551dc280bbc6ce96f02e6cad6adf6e7d",
      "tree": "75cc4ffde28c7b846e736dd474779e70c51180a8",
      "parents": [
        "9b17165e8f53563b6953a7cc81d53db6bc8a3b6b"
      ],
      "author": {
        "name": "Simon Mavi Stewart",
        "email": "simon.m.stewart@gmail.com",
        "time": "Mon Jan 19 12:05:42 2026 +0000"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jan 19 12:05:42 2026 +0000"
      },
      "message": "[ci] Drop Bazel 6 and ensure we run on Bazel 7 and 8 (#1525)\n\n[ci] Drop Bazel 6 and ensure we run on Bazel 7 and 8\n\nMinimal rules_kotlin bump to get tests passing with Bazel 8.5.1 on Windows. Also requires additional flag."
    },
    {
      "commit": "9b17165e8f53563b6953a7cc81d53db6bc8a3b6b",
      "tree": "203d4cb19bb34b3964a1dcd458cdcd925fffe73a",
      "parents": [
        "52d03179c58915bfe9ed81856487c0cf010efb41"
      ],
      "author": {
        "name": "cheister",
        "email": "cheister@squareup.com",
        "time": "Fri Jan 16 11:16:40 2026 -0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jan 16 11:16:40 2026 -0800"
      },
      "message": "Only allow modules specified in known_contributing_modules to contribute artifacts or boms to the root module (#1523)\n\n"
    },
    {
      "commit": "52d03179c58915bfe9ed81856487c0cf010efb41",
      "tree": "108719cdf79061b2d9cd44170e23393e95804bb8",
      "parents": [
        "777b42d5fdb230c6aff20b005ce8207aa31526c0"
      ],
      "author": {
        "name": "Simon Mavi Stewart",
        "email": "simon.m.stewart@gmail.com",
        "time": "Fri Jan 16 11:42:24 2026 +0000"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jan 16 11:42:24 2026 +0000"
      },
      "message": "[gradle] Fix false resolution failures when BOM upgrades dependency version (#1520)\n\nWhen a BOM or version conflict resolution upgrades a dependency to a\ndifferent version than originally requested, Gradle\u0027s internal resolution\nmay report the originally-requested version as \"unresolved\" in the\ndetached configuration. The resolver was incorrectly treating this as a\nfailure even though the artifact was successfully resolved at a different\nversion.\n\nFor example, if a user requests lib:1.0.0 but a BOM specifies lib:2.0.0,\nthe resolution succeeds with lib:2.0.0. However, lib:1.0.0 could appear\nin the unresolved dependencies list, causing a spurious\nGradleDependencyResolutionException.\n\nThe fix checks whether the same group:artifact was resolved at any version\nbefore reporting a dependency as failed. This is done by capturing the set\nof resolved group:artifact pairs before processing unresolved dependencies.\n\nAlso extracts the filtering logic into a testable method."
    },
    {
      "commit": "777b42d5fdb230c6aff20b005ce8207aa31526c0",
      "tree": "c64a1ba3b2a4b419e3c4554bf28d4de9609210e6",
      "parents": [
        "45ae779dc5fcad0140fac01776179882b3cd6b75"
      ],
      "author": {
        "name": "Simon Mavi Stewart",
        "email": "simon.m.stewart@gmail.com",
        "time": "Thu Jan 15 00:41:38 2026 +0000"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Jan 15 00:41:38 2026 +0000"
      },
      "message": "[gradle] Fix Gradle resolver to respect force_version and include runtime dependencies (#1516)\n\nThe Gradle resolver was incorrectly retaining aggregating dependencies (dependencies that exist solely to group platform-specific artifacts) in the graph. This occurred because the resolver checked the POM\u0027s `packaging` field; if it was `jar` (the default) or missing, the resolver assumed a main JAR artifact must exist, even if Gradle did not resolve one.\n\nThis change updates `GradleResolver` to:\n1. Remove the logic that infers artifact existence from POM packaging. Instead, it now checks strictly for the presence of non-POM files in the resolved artifacts list.\n2. Refine `collapseAggregatingDependencies` to explicitly ignore `javadoc` and `sources` classifiers when determining if a node is an aggregating parent. This ensures standard libraries with documentation or sources attached are not incorrectly identified as aggregating dependencies.\n\n* Avoid creating detached configurations which lead to incorrect versions being fetched\n\n* Use runtime resolution, not just api\n\n* Correctly identify aggregating dependencies by ignoring POM packaging\n"
    },
    {
      "commit": "45ae779dc5fcad0140fac01776179882b3cd6b75",
      "tree": "957b05c064a53c0c0b5a087cc9cb7ce73b8bf896",
      "parents": [
        "fdc5297d030d68108f8e575b6216c3cca48de67c"
      ],
      "author": {
        "name": "Simon Mavi Stewart",
        "email": "simon.m.stewart@gmail.com",
        "time": "Thu Jan 15 00:09:40 2026 +0000"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Jan 14 16:09:40 2026 -0800"
      },
      "message": "Correctly merge BOMs from non-root modules (#1518)\n\n* Correctly merge BOMs from non-root modules\n\nWhen merging BOMs from non-root modules, the code was incorrectly using\n`bazel_dep_to_non_root_artifacts` (the regular dependencies map) instead\nof `non_root_bazel_dep_to_boms` (the BOMs map). This caused all non-root\nmodule artifacts to be treated as BOMs\n\n* Repin lock files. `bazel test //...` now passes\n\n* Update more lock files"
    },
    {
      "commit": "fdc5297d030d68108f8e575b6216c3cca48de67c",
      "tree": "cb14f4b1f7fa77a6bb5601f8689d104f31bc6421",
      "parents": [
        "86c87b9a1483523fb1c2dd5c89ea6fc4d3924df5"
      ],
      "author": {
        "name": "Simon Mavi Stewart",
        "email": "simon.m.stewart@gmail.com",
        "time": "Wed Jan 14 22:23:54 2026 +0000"
      },
      "committer": {
        "name": "Simon Mavi Stewart",
        "email": "simon.m.stewart@gmail.com",
        "time": "Wed Jan 14 22:23:54 2026 +0000"
      },
      "message": "Update more lock files\n"
    },
    {
      "commit": "86c87b9a1483523fb1c2dd5c89ea6fc4d3924df5",
      "tree": "8e19d24beb6aac42161bd8143ce1173933c2f813",
      "parents": [
        "b7de21156e61a450cb10fa7e113023316e6cb2a2"
      ],
      "author": {
        "name": "cheister",
        "email": "cheister@squareup.com",
        "time": "Mon Jan 12 11:08:41 2026 -0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jan 12 11:08:41 2026 -0800"
      },
      "message": "Filter test_only artifacts out of artifacts merged into root repos and print a warning when a root artifact version is overridden by a non_root bazel_dep (#1511)\n\n"
    },
    {
      "commit": "b7de21156e61a450cb10fa7e113023316e6cb2a2",
      "tree": "5357aae366dc9d2c486876659d791f4bc5ea81ca",
      "parents": [
        "aed3a989e6b0300345c07b9e18d3298a0a56b377"
      ],
      "author": {
        "name": "Simon Mavi Stewart",
        "email": "simon.m.stewart@gmail.com",
        "time": "Sun Jan 11 11:42:35 2026 +0000"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun Jan 11 11:42:35 2026 +0000"
      },
      "message": "Fix SHA mismatch for conflicting dependency versions (#1513)\n\nWhen Gradle resolved version conflicts, the paths map included both the\nresolved version and the conflicting lower version. This caused the\nlockfile to record the SHA from the wrong version file, leading to\nchecksum validation failures.\n\nFor example, when resolving j2objc-annotations 2.8 → 3.0.0, the lockfile\nwould store version \"3.0.0\" but the SHA from the 2.8 JAR file.\n\nChanges:\n- Populate paths for all nodes in the final dependency graph, not just\n  root dependencies\n- Filter paths map to only include coordinates present in the final\n  resolved graph, automatically excluding conflicting versions,\n  relocated artifacts, and aggregating dependencies\n- Move test to GradleResolverTest since behavior differs between resolvers\n\nAmp-Thread-ID: https://ampcode.com/threads/T-019ba31f-0683-719f-9ce1-41dbd15e69f5\n\nCo-authored-by: Amp \u003camp@ampcode.com\u003e"
    },
    {
      "commit": "aed3a989e6b0300345c07b9e18d3298a0a56b377",
      "tree": "e99f782e62531f1a5861a22fc1c594137f74d800",
      "parents": [
        "b84160bc778783d6ae125ee501459fc9109ae6a0"
      ],
      "author": {
        "name": "Simon Mavi Stewart",
        "email": "simon.m.stewart@gmail.com",
        "time": "Sat Jan 10 10:57:51 2026 +0000"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sat Jan 10 10:57:51 2026 +0000"
      },
      "message": "[gradle] Plumb through the force_version attribute (#1515)\n\nAdds support for the force_version attribute in the Gradle resolver,\nallowing users to force specific dependency versions.\n\nChanges:\n- Add forceVersion field to Artifact class\n- Plumb through ConfigArtifact and ResolverConfig\n- Implement in both GradleResolver and MavenResolver\n- Add test for force version behavior"
    },
    {
      "commit": "b84160bc778783d6ae125ee501459fc9109ae6a0",
      "tree": "57574ac19d81cf145ea99cf47ebf3b9cedee6f50",
      "parents": [
        "858991323dab4ae7247a7da42759c6c4b3263203"
      ],
      "author": {
        "name": "Simon Mavi Stewart",
        "email": "simon.m.stewart@gmail.com",
        "time": "Sat Jan 10 10:57:36 2026 +0000"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sat Jan 10 10:57:36 2026 +0000"
      },
      "message": "[gradle] Add dep exclusions to only that dep (#1514)\n\nFixes exclusion handling so that exclusions apply only to the specific\ndependency they\u0027re declared on, not globally.\n\nThis ensures that when you exclude a transitive dependency from one\nartifact, it doesn\u0027t accidentally get excluded from other artifacts\nthat legitimately depend on it."
    },
    {
      "commit": "858991323dab4ae7247a7da42759c6c4b3263203",
      "tree": "531c81a1269dab76d330cf5e79cbbdd2f314b44f",
      "parents": [
        "125245ed274ca5fdb572f450b1946a3c66538ab6"
      ],
      "author": {
        "name": "Simon Mavi Stewart",
        "email": "simon.m.stewart@gmail.com",
        "time": "Sat Jan 10 10:56:20 2026 +0000"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sat Jan 10 10:56:20 2026 +0000"
      },
      "message": "[gradle] Handle aggregating dependencies and relocation version conflicts (#1512)\n\nThis change improves the Gradle resolver\u0027s handling of two edge cases:\n\n1. Aggregating dependencies with only classified artifacts:\n   Dependencies that exist solely to group platform-specific artifacts\n   (e.g., native libraries with -osx-aarch_64.jar but no base JAR) are\n   now correctly identified and collapsed.\n\n2. Relocation version conflicts:\n   When a relocated artifact has a different version than requested,\n   the resolver now correctly handles this by preferring the target\n   artifact.\n\nKey changes:\n- Add collapseAggregatingDependencies() to handle deps with only\n  classified artifacts (sources, javadoc, platform-specific)\n- Improve hasDownloadableArtifact() to check for actual non-POM files\n- Handle relocation where target version differs from requested\n- Add test for aggregating dependency resolution\n\nFixes issues where resolution would fail for native libraries or\nproduce incorrect graphs for relocated artifacts with version changes."
    },
    {
      "commit": "125245ed274ca5fdb572f450b1946a3c66538ab6",
      "tree": "56162951b44a2a58c14ce057a35079412cb1a370",
      "parents": [
        "39dac421006052cda2c40f76c8126b08c71b9172"
      ],
      "author": {
        "name": "Vincent Rose",
        "email": "vrose@confluent.io",
        "time": "Fri Jan 09 09:34:09 2026 -0700"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jan 09 16:34:09 2026 +0000"
      },
      "message": "BOM Fixes (#1506)\n\nAddress gaps in bom generation, dedupe some of the pom/bom logic\n"
    },
    {
      "commit": "39dac421006052cda2c40f76c8126b08c71b9172",
      "tree": "d8292e30f4224af8157e6aaf44028fc887eb9829",
      "parents": [
        "0e71e08a3160e8c1a0e44b26741dd16d28b92e78"
      ],
      "author": {
        "name": "Simon Mavi Stewart",
        "email": "simon.m.stewart@gmail.com",
        "time": "Fri Jan 09 13:46:16 2026 +0000"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jan 09 13:46:16 2026 +0000"
      },
      "message": "Allow an optional index of dep -\u003e class to be created (#1492)\n\nWhen the index is generated, the information that used to be in the lock file is moved to the index. This will reduce the size of the lock file."
    },
    {
      "commit": "0e71e08a3160e8c1a0e44b26741dd16d28b92e78",
      "tree": "e63958b1c9995ecc705698a9a2268ebc324cb71a",
      "parents": [
        "fb9c549bf7adbe195d7c370e39057d318b58853d"
      ],
      "author": {
        "name": "Simon Mavi Stewart",
        "email": "simon.m.stewart@gmail.com",
        "time": "Fri Jan 09 13:45:11 2026 +0000"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jan 09 13:45:11 2026 +0000"
      },
      "message": "Put files in `ResolutionResult` (#1484)\n\nThis will allow an optimisation for when the resolver has already downloaded all\nthe files so we can avoid a \"double download\"\n"
    },
    {
      "commit": "fb9c549bf7adbe195d7c370e39057d318b58853d",
      "tree": "584b93dd24e2221932b7e190a940a56d66481acb",
      "parents": [
        "523b21c71afebd06294dd6a1273b73ba0d9ef92f"
      ],
      "author": {
        "name": "Simon Mavi Stewart",
        "email": "simon.m.stewart@gmail.com",
        "time": "Fri Jan 09 09:32:12 2026 +0000"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jan 09 09:32:12 2026 +0000"
      },
      "message": "Optimize dependency graph building with O(1) lookups (#1483)\n\nReplace O(n²) linear searches with O(1) hash set lookups when checking\nif a dependency is in the requested deps list. Previously, isRequestedDep()\nwas called inside nested loops, doing a full stream().anyMatch() scan for\nevery dependency and child dependency, causing long delays on large\ndependency graphs.\n\nNow creates a Set\u003cString\u003e lookup cache at the start of parseDependencies()\nand uses constant-time contains() checks instead of linear scans."
    },
    {
      "commit": "523b21c71afebd06294dd6a1273b73ba0d9ef92f",
      "tree": "96a59da4037b763c32cb196fb32da7ea11d295d4",
      "parents": [
        "6b130f130ea4e946f7c6273411c38e3e6bc607f5"
      ],
      "author": {
        "name": "Simon Mavi Stewart",
        "email": "simon.m.stewart@gmail.com",
        "time": "Wed Jan 07 23:18:45 2026 +0000"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Jan 07 23:18:45 2026 +0000"
      },
      "message": "Provide a mechanism to list all resolved direct deps for a workspace (#1510)\n\nYou can do this by running `bazel run @maven//:direct_deps`"
    },
    {
      "commit": "6b130f130ea4e946f7c6273411c38e3e6bc607f5",
      "tree": "503d10c3e9ff6f0ba50ce847d6de1397f7e4f0c2",
      "parents": [
        "9d006ef1a929ad0a484d981cf129a562c87459ba"
      ],
      "author": {
        "name": "Simon Mavi Stewart",
        "email": "simon.m.stewart@gmail.com",
        "time": "Mon Jan 05 17:52:13 2026 +0000"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jan 05 17:52:13 2026 +0000"
      },
      "message": "Handle relocations in the gradle resolver (#1485)\n\n"
    },
    {
      "commit": "9d006ef1a929ad0a484d981cf129a562c87459ba",
      "tree": "6248d51972cc773bd00c1bd2c0b134ef76e9ae4d",
      "parents": [
        "8197c2a331716ae1755cf7a7d8c541ba045435e2"
      ],
      "author": {
        "name": "cheister",
        "email": "cheister@squareup.com",
        "time": "Mon Jan 05 09:24:14 2026 -0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jan 05 17:24:14 2026 +0000"
      },
      "message": "Add logback to Gradle Resolver to resolve SLF4J provider not found message (#1508)\n\n"
    },
    {
      "commit": "8197c2a331716ae1755cf7a7d8c541ba045435e2",
      "tree": "44700b8a9350aadb88bbdb91c670ec5c5457208b",
      "parents": [
        "e95b9d7d2e70b32c11dc363f48d04bf3d619e5be"
      ],
      "author": {
        "name": "Yavor Paunov",
        "email": "YavorPaunov@users.noreply.github.com",
        "time": "Tue Dec 23 05:41:45 2025 -0500"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Dec 23 10:41:45 2025 +0000"
      },
      "message": "fix(pom_file): exclusions referenced before assignment (#1503)\n\nUnder specific circumstances, the exclusions variable inside _pom_file_impl ends up being referenced before assignment. Moving it outside the if block fixes this.\n\nMore specifically, this happens when a maven_export has the target parameter set (to point to a jar file) instead of a lib_name. I have also added a test case that triggers this to prevent regression."
    },
    {
      "commit": "e95b9d7d2e70b32c11dc363f48d04bf3d619e5be",
      "tree": "80462adffe48e3f70bdb4b8016df1104c3f8edb9",
      "parents": [
        "26709ad21d74c31b13e38272aa65f72573459006"
      ],
      "author": {
        "name": "JonathanPerry651",
        "email": "jonathan.perry@gs.com",
        "time": "Tue Dec 16 12:58:23 2025 +0000"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Dec 16 12:58:23 2025 +0000"
      },
      "message": "Add finegrained control of the visibility of override targets (#1488)\n\n* Add finegrained control of the visibility of targets generated through overrides\n\n* Fix visibility test to work in CI\n\nThe genquery attr() function doesn\u0027t reliably match visibility attributes,\nso simplified the test to verify the target exists with the visibility set.\nThis is sufficient since incorrect visibility would cause target generation\nto fail.\n\n---------\n\nCo-authored-by: Jonathan Perry \u003cjonpez63@gmail.com\u003e"
    },
    {
      "commit": "26709ad21d74c31b13e38272aa65f72573459006",
      "tree": "257716edb6f1b02a9eb6ad2da8e5ad73d3b470f4",
      "parents": [
        "a23c85cf0af3a2b10d3d84da7a0160261b38e2bb"
      ],
      "author": {
        "name": "Vincent Rose",
        "email": "vrose@confluent.io",
        "time": "Thu Dec 11 10:42:25 2025 -0700"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Dec 11 17:42:25 2025 +0000"
      },
      "message": "Fix issue with pom generation failing when checking exclusions (#1500)\n\nWhen a `java_export` had a transitive dependency (through another `java_export`) on a maven artifact with exclusions defined via `maven.artifact()`, POM generation would fail. This happened because the validation was comparing exclusions from the entire transitive dependency graph against only the direct dependencies that appear in the POM.\n\nThis change removes the incorrect validation check. The existing code already handles this case correctly. Added tests to verify both the transitive java_export chain case and the bundled java_library case work correctly."
    },
    {
      "commit": "a23c85cf0af3a2b10d3d84da7a0160261b38e2bb",
      "tree": "713408e771030d38314303187b2cc6e20aa90a16",
      "parents": [
        "ef4b80d9ce3b3269dd58c59b62689acd1852adad"
      ],
      "author": {
        "name": "Gergely Fábián",
        "email": "gergo.fb@gmail.com",
        "time": "Tue Dec 02 17:49:16 2025 +0100"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Dec 02 16:49:16 2025 +0000"
      },
      "message": "rules_java: add rules loads to fix autoload on Bazel 9 (#1493)\n\nAutoload is disabled for rules_java by default on Bazel 9.\nMany of these were already fixed in #1271, but some more are still left."
    },
    {
      "commit": "ef4b80d9ce3b3269dd58c59b62689acd1852adad",
      "tree": "cfcac1447782e3d8bc4ec38704b7db0205e21e93",
      "parents": [
        "9213ad630e944c2fe2b4a9010aac974dde2ef70e"
      ],
      "author": {
        "name": "Sridhar Mocherla",
        "email": "smocherla@brex.com",
        "time": "Sun Nov 23 07:24:25 2025 -0500"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun Nov 23 12:24:25 2025 +0000"
      },
      "message": "Use persistent gradle home between invocations (#1473)\n\n"
    },
    {
      "commit": "9213ad630e944c2fe2b4a9010aac974dde2ef70e",
      "tree": "f3c156070c865b7754e0dc86643cdafad7b00085",
      "parents": [
        "cc7ea6020ffbfd3832755012ccb6ad6ce6411a29"
      ],
      "author": {
        "name": "Ted Kaplan",
        "email": "tkaplan@roku.com",
        "time": "Tue Nov 18 21:43:29 2025 -0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Nov 19 05:43:29 2025 +0000"
      },
      "message": "Remove protobuf-java runtime jars from java_export when using toolchains_protoc (#1481)\n\n"
    },
    {
      "commit": "cc7ea6020ffbfd3832755012ccb6ad6ce6411a29",
      "tree": "c4bd4c3f222b67388fd9fe58cdb4744b55f00471",
      "parents": [
        "8ecfd36e4db64257ba2de5c0fb9000dbb4f12c0d"
      ],
      "author": {
        "name": "Matt Brown",
        "email": "mattbrown@spotify.com",
        "time": "Wed Nov 19 00:37:39 2025 -0500"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Nov 19 05:37:39 2025 +0000"
      },
      "message": "coursier: ignore dependencies with classifier\u003d\"sources\" and no \"file\" (#1479)\n\nWhen coursier is asked to resolve an artifact that has a transitive\ndependency on `org.apache.logging.log4j:log4j:3.0.0-beta3` (note the\nlack of packaging in the [real-world example here][0]) and\n`fetch_sources\u003dTrue` is set, coursier will return this in the list of\ndependencies:\n\n```\n{\n  \"coord\": \"org.apache.logging.log4j:log4j:jar:sources:3.0.0-beta3\",\n  \"file\": null,\n  \"directDependencies\": [],\n  \"dependencies\": []\n}\n```\n\nIn `rules_jvm_external` 6.8 this will cause errors when building the\nexternal repo generated by RJE since RJE will end up handling this\ndependency by a) generating a `http_file` with an empty list of `urls`\nand b) emitting a `copy_file` rule in the external repo\u0027s BUILD file\nthat refers to the non-existing `http_file` repo from A. See\n[this comment][1] for a breakdown of why this happens.\n\nPR #1207 added `pom` to the list of `SUPPORTED_PACKAGING_TYPES` so that\nthe dependencies of the pom could be aggregated (Maven interprets a\ndependency on an artifact with packaging\u003dpom as depending on the\n`\u003cdependencies\u003e` in that pom), but that PR didn\u0027t test what happens with\n`fetch_sources\u003dTrue` nor did it consider the case like with\n`org.apache.logging.log4j:log4j:3.0.0-beta3` where the coordinates\noutput by coursier don\u0027t mention the packaging at all.\n\nfixes #1477\n\n[0]: https://central.sonatype.com/artifact/org.opencadc/cadc-util/1.12.10\n[1]: https://github.com/bazel-contrib/rules_jvm_external/issues/1477#issuecomment-3530832168\n"
    },
    {
      "commit": "8ecfd36e4db64257ba2de5c0fb9000dbb4f12c0d",
      "tree": "1d7755008d9b735d82e59e174c2562d0de0ab7c8",
      "parents": [
        "a4b7dde578d3ad20a72aa1054b3144f56628c22e"
      ],
      "author": {
        "name": "Alex Humesky",
        "email": "ahumesky@google.com",
        "time": "Wed Nov 05 13:31:03 2025 -0500"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Nov 05 18:31:03 2025 +0000"
      },
      "message": "Update to use Starlark rules_android. Reapply ba7310ce4a1d8fb14434597fbc7440a4074f7695 (#1297)\n\nUpdate to use Starlark rules_android. Reapply ba7310ce4a1d8fb14434597fbc7440a4074f7695\n\nReverts https://github.com/bazel-contrib/rules_jvm_external/pull/1215 plus accounting for additional changes since https://github.com/bazel-contrib/rules_jvm_external/commit/ba7310ce4a1d8fb14434597fbc7440a4074f7695 went in\n\n---------\n\nCo-authored-by: Simon Mavi Stewart \u003csimon.m.stewart@gmail.com\u003e"
    },
    {
      "commit": "a4b7dde578d3ad20a72aa1054b3144f56628c22e",
      "tree": "3793c497b5d500e5769802272d8b5843333e0af7",
      "parents": [
        "5bfbe81ac0fb3709a71ce31f328ddb9fbddbd2de"
      ],
      "author": {
        "name": "Simon Mavi Stewart",
        "email": "simon.m.stewart@gmail.com",
        "time": "Wed Nov 05 17:58:30 2025 +0000"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Nov 05 17:58:30 2025 +0000"
      },
      "message": "Move the `MavenPublisherTest` to live with the other tests (#1476)\n\n"
    },
    {
      "commit": "5bfbe81ac0fb3709a71ce31f328ddb9fbddbd2de",
      "tree": "a64df02b955e3a049bb73068d7badcb8bcdcbc80",
      "parents": [
        "c68bcf90d60413208ae010139447c0cc46b58653"
      ],
      "author": {
        "name": "Simon Mavi Stewart",
        "email": "simon.m.stewart@gmail.com",
        "time": "Tue Nov 04 17:47:34 2025 +0000"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Nov 04 17:47:34 2025 +0000"
      },
      "message": "[resolver] Ensure gradle resolver rewrites known extensions when required (#1474)\n\n"
    },
    {
      "commit": "c68bcf90d60413208ae010139447c0cc46b58653",
      "tree": "49464c712f178466e6baf82c8baa711cfbb4528f",
      "parents": [
        "425cdc8d6ed037f4cd66733ced3d682c013dbe0a"
      ],
      "author": {
        "name": "Simon Mavi Stewart",
        "email": "simon.m.stewart@gmail.com",
        "time": "Tue Nov 04 17:03:31 2025 +0000"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Nov 04 17:03:31 2025 +0000"
      },
      "message": "[resolver] Allow gradle resolver to have self loops (#1475)\n\n"
    },
    {
      "commit": "425cdc8d6ed037f4cd66733ced3d682c013dbe0a",
      "tree": "190320537fb1d837e7c7c912786fab07b9f86baf",
      "parents": [
        "3300641c915691645b89c3c37dabc32fbd5073e6"
      ],
      "author": {
        "name": "Simon Mavi Stewart",
        "email": "simon.m.stewart@gmail.com",
        "time": "Tue Nov 04 12:56:22 2025 +0000"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Nov 04 12:56:22 2025 +0000"
      },
      "message": "Prepare for 6.9 release (#1425)\n\n"
    },
    {
      "commit": "3300641c915691645b89c3c37dabc32fbd5073e6",
      "tree": "116109646819fb77a5fa1b96e6b6976beeae3807",
      "parents": [
        "4fb7c4659fa50654a6f72f1455cc9ddbe0b1cf2d"
      ],
      "author": {
        "name": "Sridhar Mocherla",
        "email": "smocherla@brex.com",
        "time": "Tue Nov 04 07:15:18 2025 -0500"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Nov 04 12:15:18 2025 +0000"
      },
      "message": "Fix cycles with some dependencies with gradle resolver (#1472)\n\n"
    },
    {
      "commit": "4fb7c4659fa50654a6f72f1455cc9ddbe0b1cf2d",
      "tree": "39a3b65e6f541fa540495e17c9b42392c9809270",
      "parents": [
        "61cd272adff0a867966396230c8e9a759da3e568"
      ],
      "author": {
        "name": "Sridhar Mocherla",
        "email": "smocherla@brex.com",
        "time": "Wed Oct 22 14:10:32 2025 -0400"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Oct 22 19:10:32 2025 +0100"
      },
      "message": "Fix gradle resolver to throw exception on unresolved dependencies (#1466)\n\nOnly throw exception if it\u0027s a requested dependency"
    },
    {
      "commit": "61cd272adff0a867966396230c8e9a759da3e568",
      "tree": "4f7bb107c5e32abfa9b1bd1a97ab4116e2880f06",
      "parents": [
        "568c0ce4ecdbf01ee432d6ec140ec65bb3427297"
      ],
      "author": {
        "name": "Simon Mavi Stewart",
        "email": "simon.m.stewart@gmail.com",
        "time": "Mon Oct 20 23:58:46 2025 +0100"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Oct 20 23:58:46 2025 +0100"
      },
      "message": "Handle all known variants used in gradle version catalogues (#1468)\n\n"
    },
    {
      "commit": "568c0ce4ecdbf01ee432d6ec140ec65bb3427297",
      "tree": "b72d792210d32931840bd0fb73f315aac6a5562a",
      "parents": [
        "cc6d5b6077f67b057cb6157ea1fcaec3fadc1ad6"
      ],
      "author": {
        "name": "Simon Mavi Stewart",
        "email": "simon.m.stewart@gmail.com",
        "time": "Mon Oct 20 23:11:22 2025 +0100"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Oct 20 15:11:22 2025 -0700"
      },
      "message": "Fix yaml file so CI builds pass (#1469)\n\n* Fix yaml file so CI builds pass\n\n* Run IJ\u0027s yaml code formatter"
    },
    {
      "commit": "cc6d5b6077f67b057cb6157ea1fcaec3fadc1ad6",
      "tree": "d583ab4999b87fb0b1f4bc0c4b16a265c20362a0",
      "parents": [
        "786201f360f227b409129ebc5a80f9b624b63ca6"
      ],
      "author": {
        "name": "utzcoz",
        "email": "43091780+utzcoz@users.noreply.github.com",
        "time": "Tue Oct 14 12:58:08 2025 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Oct 14 05:58:08 2025 +0100"
      },
      "message": "ci: Enable local_test example on macOS (#1459)\n\nSigned-off-by: utzcoz \u003cutzcoz@outlook.com\u003e"
    },
    {
      "commit": "786201f360f227b409129ebc5a80f9b624b63ca6",
      "tree": "1605188ce1aa98395a4975b90cefd900c251eca3",
      "parents": [
        "739db0842da6b15936c796f2b7bbadcc1f5bad9e"
      ],
      "author": {
        "name": "Simon Mavi Stewart",
        "email": "simon.m.stewart@gmail.com",
        "time": "Wed Oct 08 18:04:09 2025 +0100"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Oct 08 18:04:09 2025 +0100"
      },
      "message": "Ensure packaging is respected when resolving artifacts (#1463)\n\nCloses #1461"
    },
    {
      "commit": "739db0842da6b15936c796f2b7bbadcc1f5bad9e",
      "tree": "495c5b2a1bde1855016a372a58a961b720cc756a",
      "parents": [
        "75ff71ea84141466507740a5b62238b2b5d0d7f5"
      ],
      "author": {
        "name": "Simon Mavi Stewart",
        "email": "simon.m.stewart@gmail.com",
        "time": "Wed Oct 08 16:53:52 2025 +0100"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Oct 08 16:53:52 2025 +0100"
      },
      "message": "Untangle resolvers (#1458)\n\nUntil now the `maven` and `gradle` resolvers have been linked into the\nsame binary. While this is convenient, it means that people need to\ndownload dependencies they won\u0027t otherwise use.\n\nThis change breaks the resolvers into their own `java_binary` targets\nso that they can be referenced individually, thus reducing the amount\nof dependencies that need to be downloaded before resolution can\nbegin.\n\nAfter this change:\n\n```\nbazel query \u0027somepath(@regression_testing_maven//:pin, @gradle//...:*)\u0027\n```\n\nreturns an empty set.\n"
    },
    {
      "commit": "75ff71ea84141466507740a5b62238b2b5d0d7f5",
      "tree": "f28bb47154e277e7688303184adc33050517e6a5",
      "parents": [
        "752d446bdb7ccfd4fbfbefb69b17a8f47bd25af2"
      ],
      "author": {
        "name": "Simon Mavi Stewart",
        "email": "simon.m.stewart@gmail.com",
        "time": "Wed Oct 08 09:50:36 2025 +0100"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Oct 08 09:50:36 2025 +0100"
      },
      "message": "[gradle] Symlink user cache dir when `RJE_UNSAFE_CACHE` is set (#1448)\n\n"
    },
    {
      "commit": "752d446bdb7ccfd4fbfbefb69b17a8f47bd25af2",
      "tree": "d6aaa215442fc2430f546a8fbffdbe07fa79005f",
      "parents": [
        "6dd15aa87f53123fa15b06d944d82041e1f8e496"
      ],
      "author": {
        "name": "Simon Mavi Stewart",
        "email": "simon.m.stewart@gmail.com",
        "time": "Wed Oct 08 09:49:44 2025 +0100"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Oct 08 09:49:44 2025 +0100"
      },
      "message": "Ensure that resolved artifact hash is calculated the same way in Java and Starlark (#1462)\n\n"
    },
    {
      "commit": "6dd15aa87f53123fa15b06d944d82041e1f8e496",
      "tree": "56ae8e8a5e9345de77fe42238e99f288f0ac54fd",
      "parents": [
        "15c8d59963eeaf1409a591e3fe9720707ed44b89"
      ],
      "author": {
        "name": "Sridhar Mocherla",
        "email": "smocherla@brex.com",
        "time": "Tue Oct 07 05:58:55 2025 -0400"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Oct 07 10:58:55 2025 +0100"
      },
      "message": "Add more unit tests for gradle resolver (#1457)\n\n"
    }
  ],
  "next": "15c8d59963eeaf1409a591e3fe9720707ed44b89"
}
