Upgrade to Java 27 & small improvements - #570
Conversation
- Compact Object Headers are on by default, so the jre creation was simplified - C1 is the new GC, and for the bot usage should be better than Generational Shenandoah
These checks enable the new jdk nullability data, so nullable lib methods are properly annotated now
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Warning Review limit reachedYou've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Next included review available in 44 minutes. View limit detailsLimit details: You’ve used the included review currently available. Review configuration: ⚙️ Run configuration
⛔ Files ignored due to path filters (1)
📒 Files selected for processing (4)
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (2)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughThe project now uses Java 27 in its build, CI, Docker builder, and setup instructions. The Gradle build updates jlink and nullability settings and packages an OpenTelemetry agent. Application code, the Windows launcher, and test helpers also change. ChangesProject updates
Priority: ⬇️ Low Merge Risk: 🟡 Moderate · up to Installed launchers can fail to start when invoked outside the installation directory. Resolve the agent path before merging. Security Architecture ReviewSecurity architecture risk: 🟡 Moderate · up to The packaged launchers select the monitoring agent relative to the caller's working directory. A local attacker able to place a same-named JAR there could have it loaded with the bot process's authority. The standard Docker command resolves the intended packaged agent, limiting exposure for that invocation. Retained concerns
Security review detailsSecurity Blast Radius
Security Findings and Attack Paths
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Actionable comments posted: 2
ℹ️ Review info
⚙️ Run configuration
- Configuration used: Repository UI
- Review profile: CHILL
- Plan: Advanced
- Run ID:
0fd6f75e-b040-44b5-b29f-76dd03185ee2
📒 Files selected for processing (6)
Dockerfilebuild.gradle.ktsbuildSrc/src/main/java/com/github/stickerifier/stickerify/DownloadOpenTelemetryAgentTask.javagradle/libs.versions.tomlsrc/main/java/com/github/stickerifier/stickerify/bot/Stickerify.javasrc/main/java/com/github/stickerifier/stickerify/process/OsConstants.java
💤 Files with no reviewable changes (1)
- Dockerfile
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.
You will not be missed
Summary by CodeRabbit
Compatibility
Media
Bug Fixes