Skip to content

build(deps): bump org.snakeyaml:snakeyaml-engine from 2.9 to 3.0.1 - #2

Open
dependabot[bot] wants to merge 31 commits into
mainfrom
dependabot/maven/org.snakeyaml-snakeyaml-engine-3.0.1
Open

dependabot[bot] wants to merge 31 commits into
mainfrom
dependabot/maven/org.snakeyaml-snakeyaml-engine-3.0.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 26, 2026

Copy link
Copy Markdown
Contributor

Bumps org.snakeyaml:snakeyaml-engine from 2.9 to 3.0.1.

Commits
  • 41acee8 Update maven-release-plugin
  • 66c6887 Merge branch 'master' into refactor-reader
  • 2f64159 Merge remote-tracking branch 'origin/refactor-reader'
  • cbb9c20 Merge branch 'refactor-reader'
  • 304db10 Merge branch 'master' into issue-68-comment-after-alias
  • d06e8e6 Issue 68: improve comment
  • 554a919 Update junit
  • 872571f Update junit-jupiter
  • 69d9b15 Update maven-changes-plugin to version 3.0.0-M3
  • b0191ac Minor refactoring in StreamReader
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Adds scripts/build-archive.sh which produces a versioned
quark-platform-v<N>.zip archive in /home/z/my-project/download/.

Features:
  - Auto-increments the version number based on existing archives
  - Includes the full .git/ directory (per the bootstrap convention)
  - Excludes build artifacts: target/, *.class, Go binaries
    (server/quark-server, cli/quarkctl, quark-catalog/quark-catalog),
    quark-state/, dataplane-logs/, example output JSONL, log files
  - Preserves .mvn/wrapper/maven-wrapper.jar (required for ./mvnw)
  - Renames the top-level dir inside the archive to match the version

Usage:
  ./scripts/build-archive.sh [version]   # explicit version
  ./scripts/build-archive.sh             # auto-increment

Verified: extracting the archive to a fresh dir and running
'make build && make run-example' succeeds end-to-end (5/5 nodes
ACTIVE/HEALTHY, 30 JSONL lines, 10 events persisted).
Updates the docs/content/docs/*.mdx files to reflect the v6
architecture:

  - com.quarkloop.quark.core.* → com.quarkloop.quark.runtime.*
  - core/quark-{domain,engine,event,registry,script} → runtime/quark-core
  - server/quark-server/target/quark-server-0.1.0-SNAPSHOT-runner
    → server/quark-server (Go binary)

Files updated: design.mdx, environment-bootstrap.mdx, node.mdx.
Other docs (abstraction, declaration, user-story) only mentioned
these terms in passing and didn't need updates after the sweep.
Adds server/quark-server to .gitignore — it's the Go control plane
binary produced by 'make build-server'. Same convention as the
existing cli/quarkctl and quark-catalog/quark-catalog entries.
Adds 5 new test cases for sniffSystemMeta:

  TestSniffSystemMeta_NameWithSpaces       — names with spaces work
  TestSniffSystemMeta_QuarkTsComment       — comments with 'name:' or
                                             'runtime:' substrings don't
                                             fool the sniffer (regex is
                                             anchored to start-of-line)
  TestSniffSystemMeta_OnlyName             — minimum required field;
                                             documents the multi-line
                                             convention requirement
  TestSniffSystemMeta_RuntimeWithMixedCase — 'Isolated' != 'isolated'
                                             (case-sensitive, intentional)
  TestSniffSystemMeta_NestedObjectWithName — nested objects with their
                                             own 'name:' field don't
                                             shadow the top-level name

Brings the deploy package to 12 test cases total. All pass.
Prefix top-level component directories with 'quark-' to make the
repo layout self-documenting and avoid name collisions when
multiple components are checked out side-by-side.
…ectories

Symmetric with quark-cli/. The Maven modules inside (quark-core,
quark-script, quark-polyglot, quark-app, quark-runtime) keep their
own names — only the top-level parent directory is renamed.
…ries

Symmetric with quark-cli/ and quark-runtime/.
…tories

Symmetric with quark-cli/, quark-runtime/, quark-nodes/. All four
top-level component directories now share the quark- prefix.

Note: quark-catalog/ already had the prefix and was not renamed.
… rename

The parent POM declares Maven modules by relative path. After
git mv runtime quark-runtime, every <module> declaration needs the
new prefix. The server/ comment is updated to note it's now a Go
module (no longer a Maven module).
Updates CLI_DIR, SERVER_DIR, RUNTIME_JAR, RUNTIME_NATIVE, and the
Maven -pl module paths to use the new quark-prefixed directory
names. Header comment also updated to match the new layout.
run-example.sh and build-archive.sh reference build artifacts by
relative path. Update them to use the new quark-prefixed directory
names so 'make run-example' and the archive packaging continue to
work.
The previous Dockerfile referenced module paths (core/, server/quark-app/,
runtime/providers/) that haven't existed since the v6 architecture
refactor — it was broken and would fail at COPY time.

Rewrite to match the current layout:
- Stage 1 builds the Java data plane from quark-runtime/ (Maven reactor)
- Stage 2 builds three Go binaries: quark-server, quark-cli/quarkctl,
  quark-catalog
- Stage 3 assembles a runtime image with all four artifacts plus a JRE

Default CMD now runs the Go control plane (quark-server), which
spawns the data plane as a child process via ProcessManager — matches
the production runtime model.
The simple-streaming example README shows commands like
'./cli/quarkctl apply ...' — update to './quark-cli/quarkctl' to
match the new directory layout.
AGENTS.md is the navigation map for AI agents working on this repo.
Update every reference to the four renamed top-level directories:
- Tree-section entries (├── server/, ├── runtime/, ├── nodes/, ├── cli/)
- Backtick paths in prose (e.g. `server/quark-server` → `quark-server/quark-server`)
- Architecture-comparison table cells
- ASCII diagram boxes
- Prose mentions in the 'doesn't depend on' column

Internal paths that point INSIDE a renamed directory (cmd/server/main.go
inside quark-server/, internal/server/ inside quark-catalog/) are left
alone — they are correct as-is.
Update every reference to the four renamed top-level directories in
README.md:
- Tree-section entries (├── server/ → ├── quark-server/, etc.)
- Backtick paths in prose and tables
- CLI invocation examples (./cli/quarkctl → ./quark-cli/quarkctl)
- ASCII diagram boxes
- POM comment about which modules are Maven vs Go

Internal paths that point INSIDE a renamed directory (cmd/server/main.go
inside quark-server/, internal/server/ inside quark-catalog/) are left
alone — they are correct as-is.
This repository is licensed under the Apache License, Version 2.0.
The full license text is in LICENSE. Copyright assigned to
'Quarkloop Contributors' to allow contributions under the same
license without requiring individual CLAs.

Apache 2.0 was chosen over MIT because:
- It includes an explicit patent grant, which protects contributors
  and users in case any contributor's employer holds relevant patents.
- It's the de facto license for infrastructure-grade open source
  (Kubernetes, etcd, Prometheus, gRPC, and many Apache Foundation
  projects all use it).
- It's compatible with the GPL and most other OSS licenses.
Update Go build-artifact ignores to use the new directory names:
- cli/quarkctl → quark-cli/quarkctl
- cli/dist/ → quark-cli/dist/
- server/quark-server → quark-server/quark-server
- Removed cli/cli (was a duplicate pattern)

Also consolidate the 'workspace files' section by removing the
now-redundant quark-catalog/quark-catalog and server/quark-server
lines that were already updated above.
Append a standard 'License' section at the end of the README pointing
at the LICENSE file. Matches the wording used by other Apache 2.0
projects (Kubernetes, gRPC, etc.).
Covers:
- Per-component toolchain prerequisites (Go 1.24, JDK 21, GraalVM
  for native builds)
- Build targets (make build, make go, make runtime, make native)
- Test targets (make test-go, make test-java, make run-example)
- Docker verification (make docker-verify)
- Pull request workflow
- Conventional Commits conventions with the build: prefix added
- Per-language code style rules (Go gofmt+vet, Java Quarkus best
  practices)
- Test expectations (every package has _test.go, every Java module
  has JUnit 5)
- Bug report template
- Cross-links to SECURITY.md and CODE_OF_CONDUCT.md
Defines:
- Supported versions (main + latest two tagged minor releases)
- Private vulnerability reporting process (email, not GitHub issues)
- 30-day disclosure timeline with reporter coordination
- In-scope vulnerabilities per component (REST API auth bypass,
  NATS cross-tenant leakage, RCE via GraalJS sandbox escape, SQL
  injection, supply chain)
- Out-of-scope items (NATS server, GraalVM, Go stdlib — report
  upstream)
- Production hardening recommendations (TLS for NATS, restrict REST
  API, validate .quark.ts before deploy, pin images by digest)
- ASCII trust-boundary diagram showing trusted vs untrusted zones
Standard Contributor Covenant v2.0. Establishes community expectations
for behavior and provides a reporting path
(reza.ebrahimi.dev@gmail.com) for violations.
Initial CHANGELOG with:
- [Unreleased] section documenting the open-source polish work:
  Apache 2.0 license, CONTRIBUTING/SECURITY/CODE_OF_CONDUCT additions,
  directory renames, Dockerfile rewrite, path-reference updates
- [0.1.0] pre-release section summarizing the architecture (five
  components, three-service model, NATS-based multi-tenancy)

The first tagged 0.1.0 release will land once 'make docker-verify'
confirms a clean container build of the full platform.
The standard-library README mentions nodes/ as the top-level directory
and shows example paths like nodes/quark/io/file/watch/v1/. Update
both to use the new quark-nodes/ prefix.
The control-plane README mentions server/ as the top-level directory
in its build output and package-layout sections. Update both to use
the new quark-server/ prefix. The internal cmd/server/main.go path
is unchanged — it's correct as-is.
The 9-phase node implementation checklist references nodes/quark/...
paths throughout (examples, ls commands, unzip commands). Update all
to use the new quark-nodes/quark/... prefix.
Update path references in the documentation site (docs/) and the
example README to use the new quark-prefixed directory names.

Files updated:
- docs/content/docs/cli.mdx
- docs/content/docs/design.mdx
- docs/content/docs/environment-bootstrap.mdx
- docs/content/docs/node.mdx
- docs/content/docs/declaration.mdx
- docs/content/docs/node-layout.mdx
- docs/app/page.tsx

References to internal paths (cmd/server/main.go, internal/server/)
and unrelated matches (nats-server binary, nodes/{node} URI template)
are left alone.
Restructure the documentation to follow the unified template used
across all quarkloop repositories:

README.md (short, ~85 lines):
  - Overview (1 paragraph value prop)
  - Features (9 bullet points)
  - Installation (clone + make build)
  - Quick start (make run-example)
  - Documentation (links to root-level .md files)
  - Compatibility
  - Contributing + License

ARCHITECTURE.md (new, in root — NOT docs/ which is the Next.js site):
  - Three-service architecture diagram + descriptions
  - Native binary characteristics table
  - Process types table
  - Runtime isolation (shared vs isolated, runtimeId encoding)
  - Node lifecycle: build → push → pull → run
  - Per-namespace CPU attribution
  - Repository layout

API.md (new, in root):
  - REST API reference (namespaces, systems, nodes, events, registry, health)
  - CLI (quarkctl) reference: apply, get, watch, delete, node registry
  - JSON output flag for AI agents and scripting
  - Cross-link to @quarkloop/quark-js SDK

PROTOCOL.md (new, in root):
  - NATS wire protocol specification
  - Control-plane ↔ data-plane subjects (deploy, undeploy, events, heartbeat)
  - Catalog subjects (system/node/event/source/package)
  - Serialization (JSON, ISO 8601, base64 for binary)
  - Reliability (request-reply timeout, pub/sub fire-and-forget, no persistence)

BUILD.md (new, in root):
  - Prerequisites (Java 21+, Go 1.24+, NATS, optional GraalVM)
  - Build modes (JVM vs Native Image)
  - Build commands (everything, native, per-component)
  - Run commands (example, server, dev mode)
  - Test instructions
  - Docker verification
  - Makefile target reference

Note: docs/ directory remains reserved for the Next.js documentation
site. New markdown reference files live in the repo root.
The Next.js documentation app has moved to the dedicated
quarkloop/docs repository. This repo now contains only markdown
content — no Next.js code, no package.json, no configs.

Changes:
- Deleted docs/app/, docs/components/, docs/lib/, and all Next.js
  config files (next.config.mjs, package.json, tsconfig.json,
  tailwind.config.ts, postcss.config.mjs, source.config.ts,
  mdx-components.tsx, .gitignore)
- Flattened docs/content/docs/*.mdx to docs/*.mdx (removed the
  content/docs/ nesting — no longer needed without the Next.js app)
- Moved root-level docs into docs/ as .mdx:
  - API.md → docs/api.mdx
  - ARCHITECTURE.md → docs/architecture.mdx
  - BUILD.md → docs/build.mdx
  - PROTOCOL.md → docs/protocol.mdx
- Added frontmatter to the moved files
- Updated docs/meta.json sidebar to include the new pages organized
  into Concepts, Specification, and Guides sections
- Updated README.md links to point to new docs/ locations
…tuck section

Added the Repository metadata section (name, language, license, repo
URL, guidelines link) following the unified 8-section template from
github.com/quarkloop/guidelines.

Added a 'When you're stuck' section at the end with links to docs
and the guidelines spec.

Total: 400 lines (large repo target: >=400).

References: github.com/quarkloop/guidelines
Add standardized configuration files following the quarkloop
guidelines (github.com/quarkloop/guidelines):

- .editorconfig: universal language-aware editor config (tabs for
  Go/Makefile, spaces for Java/YAML/Markdown)
- .markdownlint.json + .markdownlintignore: markdown linting (ignores
  target/, dist/, docs/content/)
- .github/ISSUE_TEMPLATE/bug_report.yml: structured bug report form
- .github/ISSUE_TEMPLATE/feature_request.yml: feature request form
- .github/PULL_REQUEST_TEMPLATE.md: PR template with platform-specific
  checklist (arch-check, no TS parsing in control plane, GraalJS
  scoped to data plane)
- .github/dependabot.yml: weekly updates for go-modules, maven, and
  github-actions

References: github.com/quarkloop/guidelines
Bumps [org.snakeyaml:snakeyaml-engine](https://bitbucket.org/snakeyaml/snakeyaml-engine) from 2.9 to 3.0.1.
- [Commits](https://bitbucket.org/snakeyaml/snakeyaml-engine/branches/compare/snakeyaml-engine-3.0.1..snakeyaml-engine-2.9)

---
updated-dependencies:
- dependency-name: org.snakeyaml:snakeyaml-engine
  dependency-version: 3.0.1
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Jun 26, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: dependencies. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant