Repository navigation
Conversation
…ng a resource id as const Dependabot #42: Kotlin before 2.4.20 could execute code through unsafe deserialization in the build cache metadata. The alert names 2.4.20-Beta1 as the first fix; 2.4.20 is stable on Maven Central, so that is the one taken. The multiplatform, serialization and compose plugins move together from 2.3.21. One thing broke, and it was ours. PcGridAdapter declared its View tag key as private const val TAG_PC_HOLDER = R.id.status_dot. A resource id is not a compile-time constant, and 2.4.20 folds that const to its placeholder, so View.setTag refused the key on two grid tests. It is a plain val now, which is what it should have been on any compiler. Verification: KotlinGridAdaptersMigrationTest 15/15, the full unit suite 1635 tests with no failures, and all three debug APK ABIs assembled on 2.4.20.
…can be found The default bundle behind codeql-action@v4 refuses Kotlin 2.4.20 as too recent. tools: latest pulls the newest CodeQL CLI; if that one supports 2.4.20 the security bump can land, and if not this commit is reverted and the bump waits.
…in 2.4.20 too CodeQL 2.27.0 (2026-09-09), pulled through tools: latest, says the same thing the default bundle did: Kotlin version 2.4.20 is too recent, CodeQL currently supports versions below 2.4.20. So the probe proved its point and has nothing left to do. The bump waits for a CodeQL release that extracts 2.4.20. This reverts commit 7fa89de.
papi-ux
marked this pull request as draft
September 14, 2026 13:48
Owner
Author
|
Parked, not abandoned. The bump and the |
Owner
Author
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes Dependabot alert #42 (Kotlin build cache unsafe deserialization). The alert's first fix is a beta; 2.4.20 is stable on Maven Central, so that is what this takes. Multiplatform, serialization and compose plugins move together from 2.3.21.
One thing broke and it was ours:
PcGridAdapterdeclared its View tag key asprivate const val TAG_PC_HOLDER = R.id.status_dot. A resource id is not a compile-time constant, and 2.4.20 folds thatconstto its placeholder, soView.setTagrejected the key in two grid tests. Plainvalnow, correct on any compiler.Verification on the branch:
KotlinGridAdaptersMigrationTest15/15, fulltestNonRoot_gameDebugUnitTest1635 tests / 0 failures, all three debug APK ABIs assembled on 2.4.20.