Skip to content

Update all dependencies (end) - #586

Open
renovate[bot] wants to merge 1 commit into
endfrom
renovate/end-all
Open

renovate[bot] wants to merge 1 commit into
endfrom
renovate/end-all

Conversation

@renovate

@renovate renovate Bot commented Sep 18, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change Age Confidence
gradle (source) minor 9.7.1 → 9.8.0 age confidence
gradle/actions action minor v6.3.0 → v6.4.0 age confidence
androidx.work:work-testing (source) dependencies minor 2.11.2 → 2.12.0 age confidence
androidx.navigation:navigation-compose (source) dependencies patch 2.10.1 → 2.10.2 age confidence
androidx.core:core-ktx (source) dependencies patch 1.19.0 → 1.19.1 age confidence
androidx.tracing:tracing (source) dependencies patch 2.0.2 → 2.0.3 age confidence
androidx.work:work-runtime-ktx (source) dependencies minor 2.11.2 → 2.12.0 age confidence
androidx.navigation:navigation-testing (source) dependencies patch 2.10.1 → 2.10.2 age confidence
androidx.navigation:navigation-ui-ktx (source) dependencies patch 2.10.1 → 2.10.2 age confidence
androidx.navigation:navigation-fragment-ktx (source) dependencies patch 2.10.1 → 2.10.2 age confidence
androidx.fragment:fragment-ktx (source) dependencies patch 1.9.0 → 1.9.1 age confidence
com.diffplug.spotless plugin patch 8.10.2 → 8.10.3 age confidence
com.android.tools.build:gradle (source) dependencies patch 9.4.0 → 9.4.1 age confidence
com.android.legacy-kapt (source) plugin patch 9.4.0 → 9.4.1 age confidence
androidx.navigation:navigation-safe-args-gradle-plugin (source) dependencies patch 2.10.1 → 2.10.2 age confidence
androidx.tracing:tracing-ktx (source) dependencies patch 2.0.2 → 2.0.3 age confidence
androidx.media3:media3-ui dependencies patch 1.11.0 → 1.11.1 age confidence
androidx.media3:media3-exoplayer dependencies patch 1.11.0 → 1.11.1 age confidence
com.android.test (source) plugin patch 9.4.0 → 9.4.1 age confidence
com.android.application (source) plugin patch 9.4.0 → 9.4.1 age confidence

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

gradle/gradle (gradle)

v9.8.0: 9.8.0

Compare Source

The Gradle team is excited to announce Gradle 9.8.0.

Here are the highlights of this release:

  • Java 27 support
  • Maven mirror settings reuse
  • Linked problem locations in build output

Read the Release Notes

We would like to thank the following community members for their contributions to this release of Gradle:
Aman Gautam,
Björn Kautler,
Eng Zer Jun,
Hashim Khan,
Julian Krannich,
KBS,
Labh R Jethe,
Mark Dodgson,
Maxim,
monkey,
nataphon-ktsystems,
Paul King,
Qiu Tian,
rg_sandesh,
Roberto Perez Alcolea,
Sean,
Zongle Wang.

Upgrade instructions

Switch your build to use Gradle 9.8.0 by updating your wrapper:

./gradlew :wrapper --gradle-version=9.8.0 && ./gradlew :wrapper

See the Gradle 9.x upgrade guide to learn about deprecations, breaking changes and other considerations when upgrading.

For Java, Groovy, Kotlin and Android compatibility, see the full compatibility notes.

Reporting problems

If you find a problem with this release, please file a bug on GitHub Issues adhering to our issue guidelines.
If you're not sure you're encountering a bug, please use the forum.

We hope you will build happiness with Gradle, and we look forward to your feedback via Twitter or on GitHub.

gradle/actions (gradle/actions)

v6.4.0

Compare Source

Highlights

Gradle version support status in the Job Summary

The actions now report the support status of every Gradle version used in a workflow, as job
annotations and in the Job Summary (#​1057). Thanks to @​ov7a for the contribution.

version kind job annotation version table below the table
End-of-life — two or more major versions behind the latest release warning ⚠️ expandable section naming the affected release lines, pointing at the Gradle Security Subscription
Out of date — one major behind, or more than two minors behind on the current major notice ℹ️ one-line legend pointing at the Gradle release lifecycle docs
Current none — —

Deliberately not reported: patch releases (being on 9.7.0 when 9.7.1 exists is not flagged) and
pre-releases (release candidates, milestones and snapshots never produce annotations). The latest
Gradle release is determined from the wrapper checksum data already bundled with the action, so no
network access is required.

Note that these annotations are emitted independently of the add-job-summary setting: setting
add-job-summary: 'never' suppresses the Job Summary itself, but the warning and notice annotations
remain.

Gradle itself is now reported in the dependency graph

The dependency-submission action now applies v1.5.0 of the
GitHub Dependency Graph Gradle Plugin
(up from v1.4.2) (#​1069).

The headline change is that the Gradle Build Tool running the build is now reported as an
org.gradle:gradle-core dependency, so that GitHub can surface known vulnerabilities in the version
of Gradle used to run your build
. These are the coordinates that GitHub advisories for the Gradle
Build Tool are published against.

Details worth knowing:

  • The entry is always reported as a direct dependency with development scope.
  • It is not affected by the project, configuration or scope filters, so it appears even in graphs
    that filter aggressively.
  • Expect dependency graphs to gain this one new entry the first time a build runs after upgrading.
A new Gradle signing key, if you use dependency verification

[!IMPORTANT]
If your build has dependency verification
enabled, you must add a second trusted key before upgrading, or Dependency Graph generation will
fail signature verification.

github-dependency-graph-gradle-plugin 1.5.0 is signed with a new Gradle signing subkey, and the
key previously documented in our setup guide has been revoked upstream:

Artifact Signing key
org.gradle:github-dependency-graph-gradle-plugin 1.5.0 and later E2879931BCA1A42E55F2D64DD9B2DFBD9F3298BA (new)
org.gradle plugin versions before the rotation 7B79ADD11F8A779FE90FD3D0893A028475557671 (old, revoked)
com.gradle Develocity Gradle plugin, including 4.5.0 7B79ADD11F8A779FE90FD3D0893A028475557671 (old, revoked)

Because the Develocity Gradle plugin is still signed with the old key, you should trust both keys
rather than swapping one for the other — replacing the old key outright will break Develocity
injection. The documented snippet in
docs/setup-gradle.md
has been updated accordingly (#​1071):

<trusted-keys>
   <trusted-key id="7B79ADD11F8A779FE90FD3D0893A028475557671">
      <trusting group="com.gradle"/>
      <trusting group="org.gradle"/>
   </trusted-key>
   <trusted-key id="E2879931BCA1A42E55F2D64DD9B2DFBD9F3298BA">
      <trusting group="org.gradle"/>
   </trusted-key>
</trusted-keys>
cache-provider: external for externally managed Gradle User Home

Builds that save and restore Gradle User Home by some other mechanism (Develocity Artifact Cache, for
example) previously had to set cache-disabled: true, which was misleading: caching wasn't disabled,
it just wasn't managed by this action, and the Job Summary reported it as "Disabled".

cache-provider: external skips Gradle User Home restore/save exactly as cache-disabled does, but
reports a distinct External status in the Job Summary explaining that caching is handled by
another provider (#​1059).

- uses: gradle/actions/setup-gradle@v6
  with:
    cache-provider: 'external'
Develocity access keys containing OIDC tokens now work

Short-lived-token handling validated the server=key[;server=key]* access key format with a regex
whose key portion was too strict, so an access key holding an OIDC token value was rejected
outright. Worse, had it passed the regex, parsing split each entry on = and kept only the second
field — silently truncating any key containing = (as JWT padding does) and sending the mangled
key to the server. Both problems are fixed (#​1061).

Job Summary attribution

Job summaries produced by setup-gradle and dependency-submission now carry a top-level heading
naming the action, so the block stays attributable when another action's summary content lands in the
same job (#​1058).

Updated defaults
  • GitHub Dependency Graph Gradle Plugin: 1.4.2 → 1.5.0
  • 5 new known-good wrapper checksums for wrapper-validation (368 → 373 entries)

What's Changed

New Contributors

Full Changelog: gradle/actions@v6.3.0...v6.4.0

androidx/media (androidx.media3:media3-ui)

v1.11.1

Compare Source

This release includes the following changes since the
1.11.0 release:

  • ExoPlayer:
    • Move the flag to enable/disable HAGC metadata for progressive media from
      MediaSource.Factory to ExtractorsFactory. The previous
      setExperimentalEnableHagcPlayback method is removed and replaced by
      ExtractorsFactory.setParseHagcMetadata. This also resolves an issue
      where disabling didn't work for Matroska/WebM containers.
    • Fix a playback stall caused when prewarming a non-transitioning
      secondary renderer.
    • Fix pre-warming issue where the Surface should be returned to the
      primary renderer when a seek resets and disables both renderers.
    • Fix ArrayIndexOutOfBoundsException when a live timeline refresh moves
      the default position past a server-side inserted ad that is currently
      being played (#​3348).
    • Fix a scrubbing mode issue where stale video frames could be briefly
      displayed when seeking with
      ScrubbingModeParameters.allowSkippingMediaCodecFlush enabled.
  • Extractors:
    • Matroska: Fix issue where Tracks placed after clusters wouldn't result
      in a seekable timeline
      (#​3377).
  • Audio:
    • Fix buffer size calculation in SilenceSkippingAudioProcessor so that
      the minimum silence duration is not incorrectly scaled down by the frame
      size (#​3271).
    • Fix 8-bit PCM handling in PcmAudioUtil to treat samples as unsigned as
      defined by Android
      (#​3271).
    • Fix offload issue in which playback could stall during pre-roll or
      gapless transitions due to limited hardware buffer sizes.
    • Fix bug in DefaultAudioSink where release count doesn't decrease when
      playback thread is no longer alive
      (#​3338).
  • Session:
    • Fix NullPointerException when an in-process MediaController is
      released from a Player.Listener callback
      (#​3375).
    • Fix deadlock on the main thread when a legacy MediaBrowser connects to
      a service returning an asynchronous result from onGetLibraryRoot() or
      onConnectAsync()
      (#​3393).
  • HLS extension:
    • Fix calculation of content resume offset when the target segment for
      snapping is not yet in the playlist
      (#​3322).
    • Fix an issue where a fully consumed HlsMediaChunk retries loading on
      receiving EOFException from the extractor
      (#​3350).
  • DASH extension:
    • Fix incorrect sample timestamp calculation for image tracks with a
      presentationTimeOffset
      (#​3334).
  • Decoder extensions (FFmpeg, VP9, AV1, etc.):
    • Opus: Fix memory corruption when multiple OpusDecoder instances are
      initialized concurrently.
    • MPEG-H: Fix memory leak, truncation of non-ASCII characters, and
      potential native crash under low-memory conditions when sending commands
      to the MpeghUiManager
      (#​3365).

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Between 12:00 AM and 03:59 AM (* 0-3 * * *)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot force-pushed the renovate/end-all branch from 7e9e990 to 8b46f5e Compare September 18, 2026 21:03
@renovate renovate Bot changed the title Update all dependencies to v1.11.1 (end) Update all dependencies (end) Sep 18, 2026
@renovate
renovate Bot force-pushed the renovate/end-all branch 3 times, most recently from 9f70c9f to 3a74f0a Compare September 25, 2026 23:44
@renovate
renovate Bot force-pushed the renovate/end-all branch from 3a74f0a to fb6956b Compare September 28, 2026 20:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants