Skip to content
CAI
Software that uses CAICheck a score

ben-manes/gradle-versions-plugin

62.5

Adequate · 25 September 2026

8.2k

lines of production code

Kotlin

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a Gradle plugin designed to detect and report outdated dependencies within multi-project builds. It provides detailed update reports that include version breadcrumbs, platform constraints, and reasons for skipped configurations, supporting multiple output formats such as HTML, JSON, and XML. The plugin integrates with Gradle's Problems API and supports advanced features like component selection rule filtering and aggregation across included builds.

How it got here

2012 — Build system modernization

4 changes.

The project underwent a comprehensive build infrastructure overhaul, migrating the build scripts from Groovy to Kotlin DSL and upgrading the Gradle wrapper to version 9.7.1. Legacy Groovy-based dependency update plugins were removed in favor of a modern Kotlin implementation, while repository-wide standards for code formatting and build reliability were established.

2022–2026 — reporting engine refactoring and aggregation

8 changes.

The plugin underwent a major refactoring of its dependency update reporting engine, introducing configurable release channels, enhanced provenance tracking, and support for Gradle's Problems API. It expanded multi-project aggregation capabilities via a new settings plugin and improved report granularity with platform constraints and version breadcrumbs. These changes were accompanied by stricter security checks, Gradle 8.4+ requirements, and comprehensive test coverage for configuration caching and composite builds.

Features

Add problems output format for dependency updates

The plugin now reports outdated dependencies using Gradle's Problems API (available from Gradle 8.13). This change introduces a new output format that structures dependency update information as problems with contextual labels, details, and solutions, allowing users to view and manage outdated dependencies through Gradle's standard problem reporting mechanisms.

gradle-versions-plugin/src/problems · high confidence

Reporter subsystem refactored with enhanced dependency provenance and version breadcrumbing

The reporter package has been restructured around a new AbstractReporter base class and a Reporter interface, unifying the HTML, JSON, PlainText, and XML reporters. Reports now explicitly state where a dependency's version originates (e.g., declared in a specific configuration, constrained by a platform, or contributed by a plugin) and name the projects involved. The PlainText and HTML reports display a version breadcrumb showing the progression from the current version through patch, minor, and pre-release steps. Additionally, the HTML report now includes a section for skipped configurations, the XML report uses javax.xml instead of xerces for Gradle 8.4 compatibility, and the JSON reporter properly handles absent optional properties.

gradle-versions-plugin/src/main/kotlin/com/github/benmanes/gradle/versions/reporter · high confidence

Removals

Removal of legacy Groovy-based dependency update plugin

The legacy Groovy implementation of the dependency update functionality has been removed. This includes the deletion of the \DependencyUpdates\ task class, the \VersionsPlugin\ registration class, and the corresponding \META-INF/gradle-plugins/versions.properties\ plugin descriptor. Users relying on this specific Groovy-based plugin entry point will no longer have access to these components, as the codebase has migrated to a Kotlin-based implementation.

src/main · high confidence

Behavioural changes

Component selection rules now support current version and bound-aware filtering

The plugin's resolution strategy now replays build-defined component selection rules against recorded candidates rather than live Gradle resolutions. This introduces \ComponentSelectionWithCurrent\, which exposes the currently resolved version and declared version constraints to rule logic, enabling users to filter updates based on whether a candidate is an upgrade, lies within declared bounds, or is a pre-release. The \ComponentFilter\ functional interface and \CollectingComponentSelectionRules\ allow rules to reject candidates consistently across both live and merged reports, while \RecordedComponentSelection\ handles rule application for included-build entries where metadata is unavailable.

gradle-versions-plugin/src/main/kotlin/com/github/benmanes/gradle/versions/updates/resolutionstrategy · high confidence

Dependency report now includes platform constraints, skipped configurations, and granular version details

The dependency update report has been enhanced to provide deeper context and transparency. It now identifies the platform projects that import a dependency and the specific platforms that constrain its version, helping users understand why a particular version is selected. Additionally, the report lists configurations that were skipped due to resolution strategy failures, including the reason for the skip, so users are aware of any dependencies that were not inspected. The version information for outdated dependencies is also more detailed, breaking down available updates into release, milestone, integration, pre-release, patch, and minor versions, allowing for more precise upgrade decisions.

gradle-versions-plugin/src/main/kotlin/com/github/benmanes/gradle/versions/reporter/result · high confidence

Introduce configurable Gradle update checking with release channels and timeouts

The plugin now checks for updates across specific Gradle release channels (current, release-candidate, nightly) instead of a single generic check. This implementation adds a 15-second timeout to API requests to prevent hanging and supports customizing the Gradle versions API base URL, allowing users to configure the update source.

gradle-versions-plugin/src/main/kotlin/com/github/benmanes/gradle/versions/updates/gradle · high confidence

Major refactoring of the dependency update reporting engine

The core logic for detecting and reporting dependency updates has been significantly restructured. The \DependencyUpdatesTask\ now exposes new command-line options (\--revision\, \--gradle-release-channel\, \--output-dir\, \--report-file-name\) and task properties to control resolution levels, pre-release handling, and output formatting. The \Coordinate\ and \DependencyStatus\ classes have been expanded to track platform constraints, script classpath origins, and specific failure reasons, enabling more detailed reports on why dependencies are skipped or unresolved. A new \EmbeddedKotlin\ module explicitly identifies and excludes Gradle's internal Kotlin dependencies from the report unless explicitly requested. The \DependencyUpdatesReporter\ now supports a \problems\ output format and integrates with Gradle's Problems API, while the \PartialResult\ data structures have been updated to carry richer metadata about platform projects and version constraints.

gradle-versions-plugin/src/main/kotlin/com/github/benmanes/gradle/versions/updates · high confidence

Plugin ID migration to io.github.ben-manes and new settings-based aggregation

The plugin has migrated its primary ID from com.github.ben-manes.versions to io.github.ben-manes.versions; applying the old ID now logs a deprecation warning and delegates to the new implementation. A new settings plugin (VersionsSettingsPlugin) allows the plugin to be applied via init scripts, enabling it to report versions declared in the settings script and aggregate updates from included builds into a single root report. Additionally, the plugin now enforces Gradle 8.4+ and checks for insecure XML parsers on Gradle versions up to 8.10.2, failing the build if an incompatible parser is detected.

gradle-versions-plugin/src/main/kotlin/com/github/benmanes/gradle/versions · high confidence

Standardized repository configuration and updated Gradle wrapper scripts

The repository now includes \.editorconfig\ and \.gitattributes\ to enforce consistent two-space indentation, LF line endings, and text/binary file handling across editors and Git. The \gradlew\ and \gradlew.bat\ scripts have been updated to the latest Gradle wrapper standard, improving POSIX compliance, symlink resolution, and error reporting, while the license URL in \LICENSE.txt\ was changed from HTTP to HTTPS.

(repo-wide) · high confidence

Upgrade Gradle wrapper to 9.7.1 and configure JVM toolchains

The Gradle wrapper has been upgraded from version 1.3 to 9.7.1, bringing significant changes to the build environment. To support this upgrade, a new \gradle-daemon-jvm.properties\ file has been added, configuring JVM toolchain URLs for various operating systems and architectures via the Foojay Disco API, with the target toolchain version set to 25. Additionally, the wrapper properties now include settings for network timeouts, retries, and distribution URL validation to improve build reliability.

gradle · high confidence

Test coverage

Added test coverage for multi-project dependency aggregation and configuration caching

Added comprehensive test specifications for the \dependencyUpdates\ task's multi-project aggregation capabilities, including \AggregationSpec\, \AggregationConfigurationCacheSpec\, and \AggregationSettingsSpec\. These tests verify that the plugin correctly aggregates dependency updates across subprojects, honors inherited settings from ancestor projects, and functions reliably with Gradle's configuration cache and configure-on-demand features. Additional tests cover edge cases such as \buildSrc\ aggregation, composite builds, configuration filtering, and pre-release version rejection.

gradle-versions-plugin/src/test · high confidence

Dependencies

Migrate build to Kotlin DSL and modernize dependency management

The project build has been converted from Groovy to Kotlin DSL (build.gradle.kts), introducing a version catalog (libs.versions.toml) to manage dependencies such as Kotlin 2.4.10, Gradle 8.4 minimum, and Spock 2.4-M4. The build now targets Java 8 bytecode while compiling with Kotlin 2.0, and includes examples for both Groovy and Kotlin consumers. Additionally, the plugin ID has been updated to io.github.ben-manes.versions, and the build infrastructure now uses Gradle Develocity for build scans and enforces dependency verification.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 44 → 63 (+19.0)
  • Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 99 → 95 (-4.3)
  • Architecture 94 → 100 (+5.9)
  • Maturity 52 → 56 (+4.0)
  • Readiness 32 → 59 (+27.2)
  • Security 35 → 60 (+24.8)

Resolved (23)

  • Coverage not measured — test suite did not build
  • Dimension evaluation failed
  • Duplicated block (17 lines × 2) (gradle-versions-plugin/src/main/kotlin/com/github/benmanes/gradle/versions/reporter/HtmlReporter.kt)
  • Duplicated block (20 lines × 2) (gradle-versions-plugin/src/main/kotlin/com/github/benmanes/gradle/versions/reporter/PlainTextReporter.kt)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • …and 3 more

New (49)

  • AggregationKt.registerAggregation (cognitive 17) (gradle-versions-plugin/src/main/kotlin/com/github/benmanes/gradle/versions/updates/Aggregation.kt)
  • Dependency hygiene PARTLY measured — Maven/Gradle declarations read, no dependency graph resolved
  • DependencyUpdatesTask.dependencyUpdates (cognitive 17) (gradle-versions-plugin/src/main/kotlin/com/github/benmanes/gradle/versions/updates/DependencyUpdatesTask.kt)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Duplicated block (13 lines × 2) (gradle-versions-plugin/src/main/kotlin/com/github/benmanes/gradle/versions/reporter/HtmlReporter.kt)
  • Duplicated block (13 lines × 3) (gradle-versions-plugin/src/main/kotlin/com/github/benmanes/gradle/versions/reporter/HtmlReporter.kt)
  • Duplicated block (14 lines × 2) (gradle-versions-plugin/src/main/kotlin/com/github/benmanes/gradle/versions/reporter/PlainTextReporter.kt)
  • FileTooLong: updates/Aggregation.kt (gradle-versions-plugin/src/main/kotlin/com/github/benmanes/gradle/versions/updates/Aggregation.kt)
  • FileTooLong: updates/DependencyUpdatesReporter.kt (gradle-versions-plugin/src/main/kotlin/com/github/benmanes/gradle/versions/updates/DependencyUpdatesReporter.kt)
  • FileTooLong: updates/Resolver.kt (gradle-versions-plugin/src/main/kotlin/com/github/benmanes/gradle/versions/updates/Resolver.kt)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • …and 29 more

Changes since last survey

  • 55 commits — 41 feature/other, 14 fixes

By area

  • gradle-versions-plugin/src — 33 commits
  • (root) — 17 commits
  • .github/workflows — 4 commits
  • examples/groovy — 1 commit

Notable commits

  • fix: Add filterDeclaredConfigurations to leave out entries by the name they show (fixes #1068) (#1069)
  • fix: Add a problems output format for Gradle's Problems API (fixes #974)
  • fix: Exempt the version lookups from dependency verification (fixes #1095) (#1096)
  • fix: Fix issues found testing the v0.60.0 release snapshot (#1065)
  • fix: Fix: read a dynamic version as a bound on the buildscript classpath
  • fix: Leave Gradle's log4j-core constraint out of the report (fixes #1128)
  • fix: Leave kotlin-bom and kotlin-stdlib out of the plugin's published dependencies (fixes #1112, fixes #962) (#1113)
  • fix: Name a report entry by the project's build tree path (fixes #1075) (#1076)
  • fix: Report a constraint without a version at the version resolved for it (fixes #1122)
  • fix: Report the configurations skipped when a resolutionStrategy throws (fixes #1073) (#1074)
  • fix: Report the latest patch and minor versions before the latest version (fixes #69, fixes #841) (#1118)
  • fix: Report the platforms a build imports through its own platform projects (fixes #1070) (#1071)
  • fix: Time out the Gradle update check after 15s (fixes #1119) (#1120)
  • fix: Warn on an unknown outputFormatter name (fixes #1130) (#1131)
  • change: Accept the task settings as command line options (#1085)
  • change: Apply the report's settings to the entries merged from an included build (#1094)
  • change: Build on Gradle 9.7.1 and run the suite on every supported JDK (#1105)
  • change: Bump EnricoMi/publish-unit-test-result-action (#1013)
  • change: Bump actions/setup-java from 5 to 6 (#1089)
  • change: Bump actions/upload-artifact from 6 to 7 (#1014)
  • …and 35 more

Architecture

  • Containers 0 added · 0 removed · contexts 1 added · 0 removed · edges 0 added · 0 removed

Added bounded contexts (1)

  • gradle-versions-plugin

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

ben-manes/gradle-versions-plugin was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 25 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 6e3dbaff24e824114720e9169d46778350c90aa1 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-9630dbd8b4f7.