Skip to content

fix: Build against the Jackson version of the latest Spring Boot release. - #15

Merged
goloroden merged 1 commit into
mainfrom
jackson-from-spring-boot
Oct 8, 2026
Merged

goloroden merged 1 commit into
mainfrom
jackson-from-spring-boot

Conversation

@goloroden

Copy link
Copy Markdown
Member

Builds and tests all modules against the Jackson version of the Spring Boot release in the version catalog (today Spring Boot 4.1.1, i.e. Jackson 3.1.5), instead of a Jackson version of their own (3.2.3 so far).

Why

Spring Boot applications use the Jackson version Spring Boot pins, no matter what our POM says. A client built against a newer Jackson can fail there at runtime.

This is not hypothetical. The client calls treeToValue with a JsonNode. Jackson 3.1 added an overload for exactly that, and the compiler silently picks it. On Jackson 3.0, where the overload does not exist, reading typed event data fails with a NoSuchMethodError. 14 tests fail there.

The same trap would reopen with every Jackson release newer than Spring Boot's. Our tests would not notice, as they run on the new version. Built against Spring Boot's Jackson, the compiler can not pick anything newer.

How

  • Version catalog: jackson-databind no longer names a version. spring-boot-dependencies comes in, at the existing spring-boot version.
  • Conventions plugin: It adds Spring Boot's BOM as a platform to the compile and test classpaths of all modules. The BOM is not published, and the client gets no Spring code: its runtime classpath holds jspecify, jackson-core, jackson-databind and jackson-annotations only. A platform can only raise versions. Everything else it manages is at our versions or lower today (JUnit, SLF4J, Testcontainers, AssertJ, JSpecify), so it only decides Jackson.
  • Published versions: The POMs list the versions the modules were built against, via versionMapping { fromResolutionResult() }. The client's POM lists jackson-databind 3.1.5 and no dependencyManagement.
  • Updates: The Spring Boot release is pinned, so that builds stay reproducible. Dependabot keeps it current, and Jackson moves along in the same pull request.
  • README: "Getting Started" now states the Jackson requirement.

Older Spring Boot releases with an older Jackson are not supported. Their users update Spring Boot, or stay on an earlier client version.

Tests

make qa passes from a clean build (191 + 13 + 10 tests, 100% coverage). Before this change, the client tests were also run once against Jackson 3.1.0 and 3.1.4 (all green) and 3.0.0 and 3.0.4 (14 failures each), by forcing the runtime version.

🤖 Generated with Claude Code

https://claude.ai/code/session_01Hc2MPSLu7HDHTm8HiBsrDz

@goloroden
goloroden requested a review from a team as a code owner October 8, 2026 20:11
@goloroden goloroden self-assigned this Oct 8, 2026
@goloroden
goloroden merged commit 1f1ba52 into main Oct 8, 2026
2 checks passed
@goloroden
goloroden deleted the jackson-from-spring-boot branch October 8, 2026 20:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant