build(deps): bump org.snakeyaml:snakeyaml-engine from 2.9 to 3.0.1 - #2
Open
dependabot[bot] wants to merge 31 commits into
Open
dependabot[bot] wants to merge 31 commits into
dependabot[bot] wants to merge 31 commits into
Conversation
Adds scripts/build-archive.sh which produces a versioned
quark-platform-v<N>.zip archive in /home/z/my-project/download/.
Features:
- Auto-increments the version number based on existing archives
- Includes the full .git/ directory (per the bootstrap convention)
- Excludes build artifacts: target/, *.class, Go binaries
(server/quark-server, cli/quarkctl, quark-catalog/quark-catalog),
quark-state/, dataplane-logs/, example output JSONL, log files
- Preserves .mvn/wrapper/maven-wrapper.jar (required for ./mvnw)
- Renames the top-level dir inside the archive to match the version
Usage:
./scripts/build-archive.sh [version] # explicit version
./scripts/build-archive.sh # auto-increment
Verified: extracting the archive to a fresh dir and running
'make build && make run-example' succeeds end-to-end (5/5 nodes
ACTIVE/HEALTHY, 30 JSONL lines, 10 events persisted).
Updates the docs/content/docs/*.mdx files to reflect the v6
architecture:
- com.quarkloop.quark.core.* → com.quarkloop.quark.runtime.*
- core/quark-{domain,engine,event,registry,script} → runtime/quark-core
- server/quark-server/target/quark-server-0.1.0-SNAPSHOT-runner
→ server/quark-server (Go binary)
Files updated: design.mdx, environment-bootstrap.mdx, node.mdx.
Other docs (abstraction, declaration, user-story) only mentioned
these terms in passing and didn't need updates after the sweep.
Adds server/quark-server to .gitignore — it's the Go control plane binary produced by 'make build-server'. Same convention as the existing cli/quarkctl and quark-catalog/quark-catalog entries.
Adds 5 new test cases for sniffSystemMeta:
TestSniffSystemMeta_NameWithSpaces — names with spaces work
TestSniffSystemMeta_QuarkTsComment — comments with 'name:' or
'runtime:' substrings don't
fool the sniffer (regex is
anchored to start-of-line)
TestSniffSystemMeta_OnlyName — minimum required field;
documents the multi-line
convention requirement
TestSniffSystemMeta_RuntimeWithMixedCase — 'Isolated' != 'isolated'
(case-sensitive, intentional)
TestSniffSystemMeta_NestedObjectWithName — nested objects with their
own 'name:' field don't
shadow the top-level name
Brings the deploy package to 12 test cases total. All pass.
Prefix top-level component directories with 'quark-' to make the repo layout self-documenting and avoid name collisions when multiple components are checked out side-by-side.
…ectories Symmetric with quark-cli/. The Maven modules inside (quark-core, quark-script, quark-polyglot, quark-app, quark-runtime) keep their own names — only the top-level parent directory is renamed.
…ries Symmetric with quark-cli/ and quark-runtime/.
…tories Symmetric with quark-cli/, quark-runtime/, quark-nodes/. All four top-level component directories now share the quark- prefix. Note: quark-catalog/ already had the prefix and was not renamed.
… rename The parent POM declares Maven modules by relative path. After git mv runtime quark-runtime, every <module> declaration needs the new prefix. The server/ comment is updated to note it's now a Go module (no longer a Maven module).
Updates CLI_DIR, SERVER_DIR, RUNTIME_JAR, RUNTIME_NATIVE, and the Maven -pl module paths to use the new quark-prefixed directory names. Header comment also updated to match the new layout.
run-example.sh and build-archive.sh reference build artifacts by relative path. Update them to use the new quark-prefixed directory names so 'make run-example' and the archive packaging continue to work.
The previous Dockerfile referenced module paths (core/, server/quark-app/, runtime/providers/) that haven't existed since the v6 architecture refactor — it was broken and would fail at COPY time. Rewrite to match the current layout: - Stage 1 builds the Java data plane from quark-runtime/ (Maven reactor) - Stage 2 builds three Go binaries: quark-server, quark-cli/quarkctl, quark-catalog - Stage 3 assembles a runtime image with all four artifacts plus a JRE Default CMD now runs the Go control plane (quark-server), which spawns the data plane as a child process via ProcessManager — matches the production runtime model.
The simple-streaming example README shows commands like './cli/quarkctl apply ...' — update to './quark-cli/quarkctl' to match the new directory layout.
AGENTS.md is the navigation map for AI agents working on this repo. Update every reference to the four renamed top-level directories: - Tree-section entries (├── server/, ├── runtime/, ├── nodes/, ├── cli/) - Backtick paths in prose (e.g. `server/quark-server` → `quark-server/quark-server`) - Architecture-comparison table cells - ASCII diagram boxes - Prose mentions in the 'doesn't depend on' column Internal paths that point INSIDE a renamed directory (cmd/server/main.go inside quark-server/, internal/server/ inside quark-catalog/) are left alone — they are correct as-is.
Update every reference to the four renamed top-level directories in README.md: - Tree-section entries (├── server/ → ├── quark-server/, etc.) - Backtick paths in prose and tables - CLI invocation examples (./cli/quarkctl → ./quark-cli/quarkctl) - ASCII diagram boxes - POM comment about which modules are Maven vs Go Internal paths that point INSIDE a renamed directory (cmd/server/main.go inside quark-server/, internal/server/ inside quark-catalog/) are left alone — they are correct as-is.
This repository is licensed under the Apache License, Version 2.0. The full license text is in LICENSE. Copyright assigned to 'Quarkloop Contributors' to allow contributions under the same license without requiring individual CLAs. Apache 2.0 was chosen over MIT because: - It includes an explicit patent grant, which protects contributors and users in case any contributor's employer holds relevant patents. - It's the de facto license for infrastructure-grade open source (Kubernetes, etcd, Prometheus, gRPC, and many Apache Foundation projects all use it). - It's compatible with the GPL and most other OSS licenses.
Update Go build-artifact ignores to use the new directory names: - cli/quarkctl → quark-cli/quarkctl - cli/dist/ → quark-cli/dist/ - server/quark-server → quark-server/quark-server - Removed cli/cli (was a duplicate pattern) Also consolidate the 'workspace files' section by removing the now-redundant quark-catalog/quark-catalog and server/quark-server lines that were already updated above.
Append a standard 'License' section at the end of the README pointing at the LICENSE file. Matches the wording used by other Apache 2.0 projects (Kubernetes, gRPC, etc.).
Covers: - Per-component toolchain prerequisites (Go 1.24, JDK 21, GraalVM for native builds) - Build targets (make build, make go, make runtime, make native) - Test targets (make test-go, make test-java, make run-example) - Docker verification (make docker-verify) - Pull request workflow - Conventional Commits conventions with the build: prefix added - Per-language code style rules (Go gofmt+vet, Java Quarkus best practices) - Test expectations (every package has _test.go, every Java module has JUnit 5) - Bug report template - Cross-links to SECURITY.md and CODE_OF_CONDUCT.md
Defines: - Supported versions (main + latest two tagged minor releases) - Private vulnerability reporting process (email, not GitHub issues) - 30-day disclosure timeline with reporter coordination - In-scope vulnerabilities per component (REST API auth bypass, NATS cross-tenant leakage, RCE via GraalJS sandbox escape, SQL injection, supply chain) - Out-of-scope items (NATS server, GraalVM, Go stdlib — report upstream) - Production hardening recommendations (TLS for NATS, restrict REST API, validate .quark.ts before deploy, pin images by digest) - ASCII trust-boundary diagram showing trusted vs untrusted zones
Standard Contributor Covenant v2.0. Establishes community expectations for behavior and provides a reporting path (reza.ebrahimi.dev@gmail.com) for violations.
Initial CHANGELOG with: - [Unreleased] section documenting the open-source polish work: Apache 2.0 license, CONTRIBUTING/SECURITY/CODE_OF_CONDUCT additions, directory renames, Dockerfile rewrite, path-reference updates - [0.1.0] pre-release section summarizing the architecture (five components, three-service model, NATS-based multi-tenancy) The first tagged 0.1.0 release will land once 'make docker-verify' confirms a clean container build of the full platform.
The standard-library README mentions nodes/ as the top-level directory and shows example paths like nodes/quark/io/file/watch/v1/. Update both to use the new quark-nodes/ prefix.
The control-plane README mentions server/ as the top-level directory in its build output and package-layout sections. Update both to use the new quark-server/ prefix. The internal cmd/server/main.go path is unchanged — it's correct as-is.
The 9-phase node implementation checklist references nodes/quark/... paths throughout (examples, ls commands, unzip commands). Update all to use the new quark-nodes/quark/... prefix.
Update path references in the documentation site (docs/) and the
example README to use the new quark-prefixed directory names.
Files updated:
- docs/content/docs/cli.mdx
- docs/content/docs/design.mdx
- docs/content/docs/environment-bootstrap.mdx
- docs/content/docs/node.mdx
- docs/content/docs/declaration.mdx
- docs/content/docs/node-layout.mdx
- docs/app/page.tsx
References to internal paths (cmd/server/main.go, internal/server/)
and unrelated matches (nats-server binary, nodes/{node} URI template)
are left alone.
Restructure the documentation to follow the unified template used across all quarkloop repositories: README.md (short, ~85 lines): - Overview (1 paragraph value prop) - Features (9 bullet points) - Installation (clone + make build) - Quick start (make run-example) - Documentation (links to root-level .md files) - Compatibility - Contributing + License ARCHITECTURE.md (new, in root — NOT docs/ which is the Next.js site): - Three-service architecture diagram + descriptions - Native binary characteristics table - Process types table - Runtime isolation (shared vs isolated, runtimeId encoding) - Node lifecycle: build → push → pull → run - Per-namespace CPU attribution - Repository layout API.md (new, in root): - REST API reference (namespaces, systems, nodes, events, registry, health) - CLI (quarkctl) reference: apply, get, watch, delete, node registry - JSON output flag for AI agents and scripting - Cross-link to @quarkloop/quark-js SDK PROTOCOL.md (new, in root): - NATS wire protocol specification - Control-plane ↔ data-plane subjects (deploy, undeploy, events, heartbeat) - Catalog subjects (system/node/event/source/package) - Serialization (JSON, ISO 8601, base64 for binary) - Reliability (request-reply timeout, pub/sub fire-and-forget, no persistence) BUILD.md (new, in root): - Prerequisites (Java 21+, Go 1.24+, NATS, optional GraalVM) - Build modes (JVM vs Native Image) - Build commands (everything, native, per-component) - Run commands (example, server, dev mode) - Test instructions - Docker verification - Makefile target reference Note: docs/ directory remains reserved for the Next.js documentation site. New markdown reference files live in the repo root.
The Next.js documentation app has moved to the dedicated quarkloop/docs repository. This repo now contains only markdown content — no Next.js code, no package.json, no configs. Changes: - Deleted docs/app/, docs/components/, docs/lib/, and all Next.js config files (next.config.mjs, package.json, tsconfig.json, tailwind.config.ts, postcss.config.mjs, source.config.ts, mdx-components.tsx, .gitignore) - Flattened docs/content/docs/*.mdx to docs/*.mdx (removed the content/docs/ nesting — no longer needed without the Next.js app) - Moved root-level docs into docs/ as .mdx: - API.md → docs/api.mdx - ARCHITECTURE.md → docs/architecture.mdx - BUILD.md → docs/build.mdx - PROTOCOL.md → docs/protocol.mdx - Added frontmatter to the moved files - Updated docs/meta.json sidebar to include the new pages organized into Concepts, Specification, and Guides sections - Updated README.md links to point to new docs/ locations
…tuck section Added the Repository metadata section (name, language, license, repo URL, guidelines link) following the unified 8-section template from github.com/quarkloop/guidelines. Added a 'When you're stuck' section at the end with links to docs and the guidelines spec. Total: 400 lines (large repo target: >=400). References: github.com/quarkloop/guidelines
Add standardized configuration files following the quarkloop guidelines (github.com/quarkloop/guidelines): - .editorconfig: universal language-aware editor config (tabs for Go/Makefile, spaces for Java/YAML/Markdown) - .markdownlint.json + .markdownlintignore: markdown linting (ignores target/, dist/, docs/content/) - .github/ISSUE_TEMPLATE/bug_report.yml: structured bug report form - .github/ISSUE_TEMPLATE/feature_request.yml: feature request form - .github/PULL_REQUEST_TEMPLATE.md: PR template with platform-specific checklist (arch-check, no TS parsing in control plane, GraalJS scoped to data plane) - .github/dependabot.yml: weekly updates for go-modules, maven, and github-actions References: github.com/quarkloop/guidelines
Bumps [org.snakeyaml:snakeyaml-engine](https://bitbucket.org/snakeyaml/snakeyaml-engine) from 2.9 to 3.0.1. - [Commits](https://bitbucket.org/snakeyaml/snakeyaml-engine/branches/compare/snakeyaml-engine-3.0.1..snakeyaml-engine-2.9) --- updated-dependencies: - dependency-name: org.snakeyaml:snakeyaml-engine dependency-version: 3.0.1 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
Contributor
Author
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps org.snakeyaml:snakeyaml-engine from 2.9 to 3.0.1.
Commits
41acee8Update maven-release-plugin66c6887Merge branch 'master' into refactor-reader2f64159Merge remote-tracking branch 'origin/refactor-reader'cbb9c20Merge branch 'refactor-reader'304db10Merge branch 'master' into issue-68-comment-after-aliasd06e8e6Issue 68: improve comment554a919Update junit872571fUpdate junit-jupiter69d9b15Update maven-changes-plugin to version 3.0.0-M3b0191acMinor refactoring in StreamReaderDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)