Skip to content

build: move Kotlin to 2.4.20 for GHSA-r937-wjx7-w2jp - #306

Closed
papi-ux wants to merge 3 commits into
masterfrom
nova/kotlin-2.4.20
Closed

papi-ux wants to merge 3 commits into
masterfrom
nova/kotlin-2.4.20

Conversation

@papi-ux

@papi-ux papi-ux commented Sep 14, 2026

Copy link
Copy Markdown
Owner

Closes Dependabot alert #42 (Kotlin build cache unsafe deserialization). The alert's first fix is a beta; 2.4.20 is stable on Maven Central, so that is what this takes. Multiplatform, serialization and compose plugins move together from 2.3.21.

One thing broke and it was ours: PcGridAdapter declared its View tag key as private const val TAG_PC_HOLDER = R.id.status_dot. A resource id is not a compile-time constant, and 2.4.20 folds that const to its placeholder, so View.setTag rejected the key in two grid tests. Plain val now, correct on any compiler.

Verification on the branch: KotlinGridAdaptersMigrationTest 15/15, full testNonRoot_gameDebugUnitTest 1635 tests / 0 failures, all three debug APK ABIs assembled on 2.4.20.

papi-ux and others added 3 commits September 14, 2026 09:26
…ng a resource id as const

Dependabot #42: Kotlin before 2.4.20 could execute code through unsafe
deserialization in the build cache metadata. The alert names 2.4.20-Beta1 as
the first fix; 2.4.20 is stable on Maven Central, so that is the one taken. The
multiplatform, serialization and compose plugins move together from 2.3.21.

One thing broke, and it was ours. PcGridAdapter declared its View tag key as
private const val TAG_PC_HOLDER = R.id.status_dot. A resource id is not a
compile-time constant, and 2.4.20 folds that const to its placeholder, so
View.setTag refused the key on two grid tests. It is a plain val now, which is
what it should have been on any compiler.

Verification: KotlinGridAdaptersMigrationTest 15/15, the full unit suite 1635
tests with no failures, and all three debug APK ABIs assembled on 2.4.20.
…can be found

The default bundle behind codeql-action@v4 refuses Kotlin 2.4.20 as too recent.
tools: latest pulls the newest CodeQL CLI; if that one supports 2.4.20 the
security bump can land, and if not this commit is reverted and the bump waits.
…in 2.4.20 too

CodeQL 2.27.0 (2026-09-09), pulled through tools: latest, says the same thing
the default bundle did: Kotlin version 2.4.20 is too recent, CodeQL currently
supports versions below 2.4.20. So the probe proved its point and has nothing
left to do. The bump waits for a CodeQL release that extracts 2.4.20.

This reverts commit 7fa89de.
@papi-ux
papi-ux marked this pull request as draft September 14, 2026 13:48
@papi-ux

papi-ux commented Sep 14, 2026

Copy link
Copy Markdown
Owner Author

Parked, not abandoned. The bump and the const val fix are complete and green everywhere except Analyze Java/Kotlin: CodeQL's Kotlin extractor refuses 2.4.20 as too recent, and the newest CLI (2.27.0, 2026-09-09, tried via tools: latest in 7fa89de5, reverted in cc907cbd) says the same. The only patched Kotlin for GHSA-r937-wjx7-w2jp is 2.4.20 or later, so this waits for a CodeQL release whose extractor supports it. Unblock: bump nothing here, just rerun CI once a newer CodeQL bundle ships in codeql-action; if it still refuses, re-add tools: latest and try again.

@papi-ux

papi-ux commented Sep 27, 2026

Copy link
Copy Markdown
Owner Author

superseded by #367, so closing this. the Kotlin 2.4.20 bump from this branch landed on staging as the same change, PcGridAdapter fix included, and is on master now through #367. the CodeQL block that parked it is gone too: Analyze Java/Kotlin passes on #367 with 2.4.20.

@papi-ux papi-ux closed this Sep 27, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant