Repository navigation
Freeze v5 support matrix and migration policy (#1156) - #1318
Conversation
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
v5 keeps every lockfile format, but the docs did not say how mature each one is. docs/ecosystems.md now has a tier table (Supported, Beta, Legacy, Not supported) per ecosystem and mode: - Hosted and vendored Maven/Gradle and the Scala tools are Beta, with the open rewriter gaps named and a "run the build before you trust --vex" check. - bun.lockb, vendored pnpm 7/8 locks and vlt pre-1.0 locks are Legacy: still read and written in v5, each with an upgrade path and an undo path. - A support policy: v5.x never removes a format or makes one refuse that v5.0 accepts; removing a Legacy writer needs a major release and keeps rollback working. The migration guide gets a short Support tiers section that links to the table. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
BugBot review |
There was a problem hiding this comment.
✅ Bugbot reviewed your changes and found no new issues!
Comment @cursor review or bugbot run to trigger another review on this PR
Reviewed by Cursor Bugbot for commit 396aed0. Configure here.
|
[final reviewer] I disarmed auto-merge at Generated by Claude Code |
|
Ready for review at
Labeled Generated by Claude Code |
LLM Description written by Claude Code:claude-opus-5-5
Fixes #1156
Summary
Freezes the v5 support matrix and migration policy in the docs, as the maintainer's 2026-10-09 triage comment on #1156 asks. Docs only. No behavior changes and no format is dropped or refused.
docs/ecosystems.mdgets a new v5 support tiers section (after the mode × ecosystem matrix):<classifier>, profiles/plugins/comments,${property}, imported BOMs, mirrors), links thepm:maven/pm:gradleissue lists, and says to run the build before trusting a JVM--vex. Agent-mode JVM stays Supported with its existing caveats.bun.lockb(hosted and vendored), vendored pnpm 7/8 locks (5.4/6.0), and vlt eras A0–B. Each keeps full read/write in v5 and gets an upgrade path and an undo path table. Hostedbun.lockbundo is the existinggit checkout -- bun.lockbrefusal.list/vex/rollbackreading the format.docs/migrating-to-v5.mdgets a short Support tiers section that summarizes the above and links to it.Root cause
The matrix listed what each mode handles, but not how mature that support is. Hosted JVM coverage and the retired-by-upstream lock formats had no stated tier or deprecation policy.
Facts checked against the code and tracker
formats/pnpm/mod.rssniff_lock_grammar), so pnpm 1–6 vendored is "Not supported".bun.lockbrollback refusal comes fromdocs/testing/bun-compatibility.md.<classifier>and suffixes sources/tests/native classifier dependencies, which breaks the build #262, Maven hosted scan pins, and VEX attests, artifacts the project doesn't depend on (the crawler lists all of~/.m2) #265, Maven pom rewrites add a second <repositories> or <dependencyManagement> section when the existing one is self-closed or has a comment before <dependencies>, so Maven refuses the pom #342, Vendored Maven reactor pins over an imported BOM or external parent, so a build that uses 1.11.0 is silently downgraded to 1.10.0-socket.* and a later BOM bump never takes effect #488 (v5-blocker) and Vendored JVM fetches upstream artifacts and checksums only from Maven Central, ignoring the build's mirrors and repositories #1069, Vendored Maven reactor ignores profile <properties>, so a version an active profile raises is silently downgraded to the patched base (1.11.0 → 1.10.0-socket.*) with exit 0 and no warning #459 and others (p3).Checklist
No CHANGELOG edit (AGENTS.md).
🤖 Generated with Claude Code
Note
Low Risk
Documentation-only; no runtime, lockfile, or refusal behavior changes.
Overview
Documents the v5 support maturity model and release policy without changing CLI behavior.
docs/ecosystems.mdadds a v5 support tiers block after the mode matrix: tier definitions (Supported / Beta / Legacy / Not supported), an ecosystem×mode tier table, explicit Beta labeling for hosted and vendored Maven/Gradle (plus sbt/Mill/scala-cli) with rewriter-gap context and issue links, Legacy upgrade/undo paths forbun.lockb, vendored pnpm 7/8 locks, and pre-1.0 vlt locks, and a support policy (no format removal in v5.x minors/patches; tier moves; Legacy write removal only on major).docs/migrating-to-v5.mdadds a short Support tiers section that summarizes Beta/Legacy expectations and links to the ecosystems page.Reviewed by Cursor Bugbot for commit 396aed0. Configure here.
Generated by Claude Code