Library versions now read "1.+" instead of "1.19.0". Three groups stay pinned,
and the reasons differ:
agp/kotlin/ksp are version-locked to each other -- AGP 9.3.1's POM declares
kotlin-gradle-plugin 2.2.10, so a float that picked up Kotlin 2.4.x would put
the Compose compiler ahead of the Kotlin AGP actually compiles with.
ktlint/detekt/jacoco because a linter is not a library. A library bump that
misbehaves usually still compiles; a new lint rule makes files nobody touched
stop passing, turning a PR red for something absent from its diff. Upgrading
those is worth a commit that reads the new findings.
The FFmpeg AAR is a committed file, not a coordinate.
The componentSelection block is the part that makes this safe rather than the
part that makes it work. Gradle resolves "+" to the highest version it can find
and does not skip prereleases, and androidx routinely publishes alphas numbered
above the current stable: lifecycle 2.12.0-alpha01, work 2.12.0-rc01, navigation
2.10.0-rc01, datastore 1.3.0-alpha10, annotation 1.11.0-alpha01 all outrank the
releases this app uses. Without the guard, five dependencies would have moved
onto unreleased code on the next build with nothing in the diff to say so. With
it, every float resolves to exactly the version that was pinned before -- checked
against :app:dependencies, not assumed.
So this changes nothing today. Every library was already at its newest stable
when the catalog was audited; floating is about what happens next month, not
this commit.
Trying a prerelease is still possible: name the exact version, which pins it
rather than floating it. That is the right way round -- an alpha should be a
deliberate act with a version number attached to it.
Verified: ktlint, detekt, lint, unit tests, androidTest compile, assembleDebug
all green, and the configuration cache still reuses across runs of the same task
set.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>