Let the libraries float on minor and patch

Library versions now read "1.+" instead of "1.19.0". Three groups stay pinned,
and the reasons differ:

  agp/kotlin/ksp are version-locked to each other -- AGP 9.3.1's POM declares
  kotlin-gradle-plugin 2.2.10, so a float that picked up Kotlin 2.4.x would put
  the Compose compiler ahead of the Kotlin AGP actually compiles with.

  ktlint/detekt/jacoco because a linter is not a library. A library bump that
  misbehaves usually still compiles; a new lint rule makes files nobody touched
  stop passing, turning a PR red for something absent from its diff. Upgrading
  those is worth a commit that reads the new findings.

  The FFmpeg AAR is a committed file, not a coordinate.

The componentSelection block is the part that makes this safe rather than the
part that makes it work. Gradle resolves "+" to the highest version it can find
and does not skip prereleases, and androidx routinely publishes alphas numbered
above the current stable: lifecycle 2.12.0-alpha01, work 2.12.0-rc01, navigation
2.10.0-rc01, datastore 1.3.0-alpha10, annotation 1.11.0-alpha01 all outrank the
releases this app uses. Without the guard, five dependencies would have moved
onto unreleased code on the next build with nothing in the diff to say so. With
it, every float resolves to exactly the version that was pinned before -- checked
against :app:dependencies, not assumed.

So this changes nothing today. Every library was already at its newest stable
when the catalog was audited; floating is about what happens next month, not
this commit.

Trying a prerelease is still possible: name the exact version, which pins it
rather than floating it. That is the right way round -- an alpha should be a
deliberate act with a version number attached to it.

Verified: ktlint, detekt, lint, unit tests, androidTest compile, assembleDebug
all green, and the configuration cache still reuses across runs of the same task
set.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
2026-08-22 14:46:59 -05:00
co-authored by Claude Opus 5
parent 3841f58c74
commit e9542d2223
3 changed files with 100 additions and 25 deletions
+30 -19
View File
@@ -11,27 +11,38 @@ agp = "9.3.1"
kotlin = "2.2.10"
ksp = "2.3.11"
# AndroidX / Compose
composeBom = "2026.08.00"
coreKtx = "1.19.0"
activityCompose = "1.13.0"
lifecycle = "2.11.0"
navigation = "2.9.8"
work = "2.11.2"
datastore = "1.2.1"
media3 = "1.11.0"
room = "2.8.4"
documentfile = "1.1.0"
annotation = "1.10.0"
# AndroidX / Compose -- floating on minor + patch. The prerelease guard in
# app/build.gradle.kts is what keeps `+` from selecting an alpha: several of these
# (lifecycle, navigation, work, datastore, annotation) publish alphas and RCs with
# version numbers ABOVE their newest stable, and Gradle's `+` would take them.
composeBom = "2026.+"
coreKtx = "1.+"
activityCompose = "1.+"
lifecycle = "2.+"
navigation = "2.+"
work = "2.+"
datastore = "1.+"
media3 = "1.+"
room = "2.+"
documentfile = "1.+"
annotation = "1.+"
# Test
junit = "4.13.2"
androidxJunit = "1.3.0"
espressoCore = "3.7.0"
smartException = "0.2.1"
# Test -- floating, same rules as above.
junit = "4.+"
androidxJunit = "1.+"
espressoCore = "3.+"
smartException = "0.+"
# Lint/format. ktlint owns formatting; detekt owns static analysis (its formatting
# ruleset stays off, so the two can never disagree about the same line).
# Lint/format. PINNED, deliberately, while the libraries above float.
#
# A library bump that misbehaves usually still compiles. An analysis-tool bump does
# something worse: a new rule in ktlint or detekt makes files nobody touched stop
# passing, so CI goes red on a PR whose diff cannot explain it. Upgrading these is
# therefore an act with its own commit -- run the tool, read the new findings, fix or
# relax them -- which is exactly the reviewable step floating is meant to skip.
#
# ktlint owns formatting; detekt owns static analysis (its formatting ruleset stays
# off, so the two can never disagree about the same line).
# detekt 2.0 is the only line with Gradle 9 support -- stable 1.23.x tops out at
# Gradle 8.12, and this project is on 9.5.
ktlint = "14.2.0"