Skip to content

docs(spec): restore nested-group Maven publication - #37857

Merged
wezell merged 2 commits into
mainfrom
issue-37854-maven-nested-group-spec
Oct 1, 2026
Merged

wezell merged 2 commits into
mainfrom
issue-37854-maven-nested-group-spec

Conversation

@wezell

@wezell wezell commented Oct 1, 2026 •

Copy link
Copy Markdown
Member

Defect specification

Refs #37854. Implementation: #37855.

This spec-only PR records the intended repair contract for the customer-blocking Maven publishing regression. The developer explicitly approved the documented hotfix route: implementation first, followed by the defect spec as its own PR.

The contract covers recursive nested-group discovery, preserved Maven paths, actual metadata group IDs, checksums, module filtering, and regression coverage. Live recovery is separately authorized to copy exact original GitHub release-run build artifacts; no JAR regeneration or relabeling older releases.

Directory-scan error hardening is explicitly deferred from this narrow hotfix. No implementation, plans, tasks, credentials, or binary artifacts are included in this PR.

The original release files have been copied for all seven affected published releases. Public CDN SHA-256/sidecar/metadata verification passed, and a cold consumer resolution against core 26.09.28-02 through repo.dotcms.com passed with checksum policy fail. Detailed provenance and operational evidence are being recorded on #37854.

This PR fixes: #37854

@claude

claude Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @wezell's task in 35s —— View job


Review

Task list

  • Read the diff and the added spec file
  • Assess the change for issues
  • Post review

This PR adds a single Spec-Kit document (specs/37854-maven-nested-group-publishing/spec.md, +79/−0). There is no code, build config, or dependency change in the diff, so the usual bug / security / convention / replay-safety checks have nothing executable to act on. I reviewed the spec for internal consistency and completeness against the stated hotfix contract.

New Issues

No issues found.

The spec reads cleanly and is internally consistent:

  • The root cause (specs/37854-maven-nested-group-publishing/spec.md:30-34 — single-depth glob, artifactId-only destination reconstruction, hardcoded com.dotcms metadata groupId) lines up with the fix scope (lines 36-51: recursive discovery, path-derived groupId, module filters applied at all depths with distinct paths preserved).
  • The regression evidence (lines 18-27: eight offline methods failing pre-fix, four existing-behavior tests passing) is consistent with the PR body.
  • The TDD/approval framing (lines 14-16) matches the fix-first, separate-spec-PR route the PR body describes, and the file correctly carries spec.md alone with no plan/task/credential/binary artifacts — consistent with the Spec-Kit "PR 1 (spec) alone" rule in CLAUDE.md.
  • The deferred non-goal (lines 50-51, fail-closed directory-scan error handling) is explicitly called out and cross-referenced to its residual risk (lines 72-73), so the gap is documented rather than silently dropped.

A couple of observations, neither blocking:

  • The spec deliberately leaves directory-scan failure fail-open (lines 50-51, 72-73). That is a conscious, developer-approved deferral for a narrow hotfix, and the compensating control (compare dry-run output against an expected release-module inventory before backfilling) is stated. Worth tracking as a follow-up issue so the deferral does not get lost.
  • Line 64-68 folds operational backfill/consumer-verification into "Acceptance and verification" while lines 46-49 class it as a non-goal for implementation CI. These are not contradictory (one is release acceptance, the other is CI scope), but a reader skimming only the acceptance list could read item 7 as a CI gate. Not a defect — just a place the two sections could cross-reference each other more explicitly.

The companion implementation lives in #37855; its actual Bash publisher changes and the offline regression tests are where the correctness review matters and should be done against that PR's diff.
· branch issue-37854-maven-nested-group-spec

@wezell wezell added the PR : dotbot review Trigger dotbot AI code review and the post-merge QA test plan label Oct 1, 2026
@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

dotbot code review:

  • Reviewer: meta/muse-spark-1.3 (medium)
  • Overall: patch is correct
  • New findings this run: 0
  • Prior unresolved dotbot findings still relevant: 0
  • Active findings total: 0

Spec-only addition with no executable code; no flag-worthy defect introduced by this patch. Deferred fail-closed scan handling is explicitly documented scope with compensating control.

Tip: comment with "/dotbot address comments" to attempt automated fixes for unresolved review threads.

reviewed by dotbot · meta/muse-spark-1.3 · medium

@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

dotbot code review:

  • Reviewer: ~z-ai/glm-latest (medium)
  • Overall: patch is correct
  • New findings this run: 0
  • Prior unresolved dotbot findings still relevant: 0
  • Active findings total: 0

The PR adds only a documentation spec file describing the Maven nested-group publishing hotfix contract; it contains no executable code, build config, or credentials. The spec is internally consistent and explicitly documents deferred fail-closed scan handling with compensating controls, so there is no flag-worthy defect.

Tip: comment with "/dotbot address comments" to attempt automated fixes for unresolved review threads.

reviewed by dotbot · ~z-ai/glm-latest · medium

@dotCMS-Machine-User dotCMS-Machine-User left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ dotbot review: all reviewer models (meta/muse-spark-1.3, ~z-ai/glm-latest) agree — patch is correct.

approved automatically by dotbot

@wezell
wezell added this pull request to the merge queue Oct 1, 2026
Merged via the queue into main with commit 50478ae Oct 1, 2026
49 checks passed
@wezell
wezell deleted the issue-37854-maven-nested-group-spec branch October 1, 2026 23:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

AI: Safe To Rollback PR : dotbot review Trigger dotbot AI code review and the post-merge QA test plan

Projects

Status: No status

Development

Successfully merging this pull request may close these issues.

Maven releases omit nested-group artifacts after Bunny migration

2 participants