← All recipes
Open source

Upgrade transitive Gradle dependencies

Recipe IDorg.openrewrite.gradle.UpgradeTransitiveDependencyVersion
Artifactorg.openrewrite:rewrite-gradle

Upgrades the version of a transitive dependency in a Gradle build file. There are many ways to do this in Gradle, so the mechanism for upgrading a transitive dependency must be considered carefully depending on your style of dependency management.

Single recipeApache 2.0

Usage

You’ll need the Moderne CLI configured before running the command below.

mod run . --recipe org.openrewrite.gradle.UpgradeTransitiveDependencyVersion --recipe-option "groupId=com.fasterxml.jackson*" --recipe-option "artifactId=jackson-module*"

If the recipe isn’t available locally, install it with:

mod config recipes jar install org.openrewrite:rewrite-gradle:8.88.0

Options

NameTypeDescription
groupIdrequiredStringThe first part of a dependency coordinate com.google.guava:guava:VERSION. This can be a glob expression.
e.g. com.fasterxml.jackson*
artifactIdrequiredStringThe second part of a dependency coordinate com.google.guava:guava:VERSION. This can be a glob expression.
e.g. jackson-module*
versionStringAn exact version number or node-style semver selector used to select the version number. You can also use latest.release for the latest available version and latest.patch if the current version is a valid semantic version. For more details, you can look at the documentation page of version selectors. Defaults to latest.release.
e.g. 29.X
versionPatternStringAllows version selection to be extended beyond the original Node Semver semantics. So for example,Setting 'newVersion' to "25-29" can be paired with a metadata pattern of "-jre" to select Guava 29.0-jre
e.g. -jre
becauseStringThe reason for upgrading the transitive dependency. For example, we could be responding to a vulnerability.
e.g. CVE-2021-1234
onlyForConfigurationsListA list of configurations to consider during the upgrade. For example, For example using implementation, runtimeOnly, we could be responding to a deployable asset vulnerability only (ignoring test scoped vulnerabilities).
e.g. implementation, runtimeOnly

Data tables

Structured output this recipe can produce.

  • Maven metadata failuresAttempts to resolve maven metadata that failed.org.openrewrite.maven.table.MavenMetadataFailures
  • Source files that had resultsSource files that were modified by the recipe run.org.openrewrite.table.SourcesFileResults
  • Source files that had search resultsSearch results that were found during the recipe run.org.openrewrite.table.SearchResults
  • Source files that errored on a recipeThe details of all errors produced by a recipe run.org.openrewrite.table.SourcesFileErrors
  • Recipe performanceStatistics used in analyzing the performance of recipes.org.openrewrite.table.RecipeRunStats