GradleUp/shadow
63.0
Adequate · 25 September 2026
5.3k
lines of production code
Kotlin
primary language
4
measurements over time
What this system is
This system is the Gradle Shadow Plugin, a build tool extension that creates executable 'fat' JARs by merging application code with its dependencies. It provides capabilities for relocating classes, filtering and transforming resources, and minimizing the final artifact using R8. The plugin supports Java, Kotlin Multiplatform, and application distribution packaging while ensuring reproducible and cacheable builds.
How it got here
2012–2024 — Kotlin rewrite and R8 minimization
15 changes.
The project underwent a comprehensive rewrite of the Shadow Gradle plugin in Kotlin, introducing a modular architecture and a formal public API. This period also integrated R8-based application minimization, modernized the build infrastructure with Kotlin 2.4 and Gradle 9.4+, and established reproducible build standards alongside extensive test coverage.
2025 — comprehensive test coverage expansion
7 changes.
This period focused on significantly expanding the project's test suite by adding extensive functional and unit tests for the Shadow plugin's core capabilities, including dependency filtering, resource transformers, and integration with various build plugins. New test utilities were introduced to support Maven repository simulation, JAR construction, and JAR inspection, while existing test kit behaviors were refined to improve reliability and configuration management.
2026 — Documentation test isolation and build logic
4 changes.
The project refactored document tests to execute Groovy and Kotlin snippets in isolated Gradle projects, ensuring reliable validation without cross-test interference. Concurrently, build infrastructure was enhanced with a new GenerateDocTests task to auto-generate tests from documentation and stubbed build logic components.
Features
Introduce R8-based application minimization
Users can now minimize the final shadowed JAR using R8 instead of the previous dependency-analysis approach. This change adds internal support for an R8-based shrinker (R8Minimizer, DefaultR8Spec, DefaultMinimizeSpec) that runs after all relocations and resource merging, allowing configuration of obfuscation, optimization, ProGuard rules, and classpath files. It also includes supporting internal components for dependency filtering, manifest handling, and bytecode remapping to integrate this new minimization path.
src/main/kotlin/com/github/jengelman/gradle/plugins/shadow/internal · high confidence
Project initialization and documentation overhaul
The repository has been initialized with a comprehensive documentation structure, including a new MkDocs-based user guide, a detailed changelog, and updated contributing and releasing guidelines. The project now enforces consistent code formatting via EditorConfig and Spotless, standardizes line endings with Git attributes, and provides a Gradle wrapper for reproducible builds. The README has been expanded to clarify the plugin's purpose, display compatibility matrices for Gradle and Java versions, and note the maintenance transfer to the GradleUp organization.
(repo-wide) · high confidence
ShadowJar now supports R8-based minimization
The ShadowJar task now offers an R8-based minimization option alongside the existing dependency analyzer. Users can configure this via the new \minimize()\ DSL, selecting the \R8\ tool in \MinimizeSpec\ and providing rules through \R8Spec\ (including \proguardRules\, \proguardRuleFiles\, and classpath configuration). This enables more aggressive shrinking of the shadowed JAR. The previous \minimizeJar\ property is deprecated in favor of this new configuration.
src/main/kotlin/com/github/jengelman/gradle/plugins/shadow/tasks · high confidence
API
Initial public API surface for Gradle Shadow Plugin
The plugin now exposes a formal public API contract via the \api/shadow.api\ file, defining the stable interfaces and classes for users. This includes the core plugins (\ShadowApplicationPlugin\, \ShadowBasePlugin\, \ShadowJavaPlugin\, \ShadowKmpPlugin\, \ShadowPlugin\), the main extension point (\ShadowExtension\), and key task/transformer components like \DependencyFilter\, \FindResourceInClasspath\, and the relocation system (\Relocator\, \SimpleRelocator\, \RelocateClassContext\). This establishes the boundary for binary compatibility and documents the public-facing capabilities of the plugin.
api · high confidence
Behavioural changes
2 commits (1 fix) modifying src/testKit
A change to existing behaviour in src/testKit — 2 commits (1 fix), 1 file.
src/testKit · medium confidence · unverified
Add empty BuildLogicPlugin stub in build-logic
A new \BuildLogicPlugin\ class has been added to the \gradle/build-logic\ module. This class implements the Gradle \Plugin\<Project\>\ interface but performs no operations in its \apply\ method, serving as a placeholder or registration point for build logic configuration.
gradle/build-logic/src/main/kotlin/com/github/jengelman/gradle/plugins/shadow · high confidence
Add legacy plugin implementation class
A new properties file has been added to register the legacy shadow plugin implementation, pointing to the \LegacyShadowPlugin\ class. This change enables the plugin to be applied using legacy plugin IDs, supporting backward compatibility for users relying on older plugin application methods.
src/main · high confidence
Independent document test execution for Groovy and Kotlin snippets
Document tests now execute build snippets in isolated, independent Gradle projects rather than relying on a shared test infrastructure. The new \SnippetExecutable\ interface and its \GroovyBuildExecutable\ and \KotlinBuildExecutable\ implementations generate temporary multi-project builds (including \api\ and \main\ subprojects) to validate documentation examples against both Groovy (\build.gradle\) and Kotlin (\build.gradle.kts\) DSLs. This change ensures that each snippet is tested in a clean environment, improving reliability by preventing cross-test interference and allowing for more accurate validation of build script configurations.
src/documentTest/kotlin/com/github/jengelman/gradle/plugins/shadow · high confidence
Relocator interface now supports skipping string constant remapping
The Relocator interface has been updated to include a new skipStringConstants property, which defaults to false. This allows relocator implementations to opt out of remapping string constants within source content, providing finer control over how string literals are handled during the relocation process.
src/main/kotlin/com/github/jengelman/gradle/plugins/shadow/relocation · high confidence
Reproducible builds, deduplication, and relocation improvements
This release introduces several changes to improve build reproducibility, resource handling, and relocation logic. Reproducible properties are now serialized without comments and with sorted keys to ensure consistent output across builds. A new DeduplicatingResourceTransformer detects and fails on duplicate resources with different content, while allowing exclusions for legitimate duplicates like POM metadata. Relocation logic has been refined with new context objects (RelocateClassContext, RelocatePathContext) and extensions for Iterable\<Relocator\>, and SimpleRelocator now supports skipping string constant remapping. Additionally, ZIP entry writing is centralized with path traversal protection and case-insensitive filesystem handling, and the deprecated TransformerContext.Builder is marked for removal in Shadow 10.
repository · high confidence
Resource transformers migrated to Kotlin with caching and pattern filtering
The resource transformers in the shadow plugin have been rewritten in Kotlin and annotated with @CacheableTransformer to enable Gradle build caching. Most transformers now implement PatternFilterableResourceTransformer, allowing users to filter which resources are processed using standard Gradle pattern sets. Several transformers have been deprecated in favor of simpler alternatives: ApacheLicenseResourceTransformer and DontIncludeResourceTransformer are replaced by ShadowJar.exclude, IncludeResourceTransformer by ShadowJar.from, and ManifestAppenderTransformer by ManifestResourceTransformer. New transformers have been added, including MergeLicenseResourceTransformer for aggregating license files, ProGuardFilesResourceTransformer for merging R8/ProGuard rules, and DeduplicatingResourceTransformer for content-based deduplication.
src/main/kotlin/com/github/jengelman/gradle/plugins/shadow/transformers · high confidence
Shadow plugin rewritten in Kotlin with modular architecture and new configuration options
The Shadow Gradle plugin has been completely rewritten in Kotlin and restructured into a modular architecture. The main entry point, ShadowPlugin, now delegates to specialized plugins (ShadowBasePlugin, ShadowJavaPlugin, ShadowApplicationPlugin, and ShadowKmpPlugin) based on the applied Gradle plugins, replacing the previous monolithic implementation. This change introduces a new ShadowExtension interface that allows users to configure behavior via properties such as addShadowVariantIntoJavaComponent, addTargetJvmVersionAttribute, bundlingAttribute, and addShadowJarToAssembleLifecycle. The plugin now supports Kotlin Multiplatform by configuring shadowJar tasks for JVM targets, while explicitly failing when used with the Android Gradle Plugin. Additionally, the ShadowDslMarker annotation has been renamed to ShadowDsl, with the old name deprecated as an error-level deprecation.
src/main/kotlin/com/github/jengelman/gradle/plugins/shadow · high confidence
Test coverage
Add test utility functions for object factories and ZIP streams; Added GenerateDocTests build task; Added functional tests for resource transformers; Added test resources for Maven Wagon component configuration; Added tests for Shadow plugin properties and task configurations; Added tests for ShadowCopyAction Zip64 handling and parallel remapping; Added unit tests for internal Shadow plugin components; Added unit tests for relocation logic and signature pattern mapping; Added unit tests for resource transformers; Expanded functional test coverage for Shadow plugin capabilities; New test utility classes for Maven repository simulation and JAR construction; New test-kit utilities for JAR inspection and Gradle runner configuration.
Dependencies
Initialize Gradle Wrapper with version 9.8.0
The project now includes a Gradle wrapper configuration file (gradle-wrapper.properties) that pins the build tool to version 9.8.0. This ensures that all developers and CI systems use the same specific Gradle distribution, downloaded from the official services URL, rather than relying on a globally installed version. The wrapper is configured to validate the distribution URL and store the downloaded archives in the user's home directory.
gradle/wrapper · high confidence
Shadow plugin 9.7.0-SNAPSHOT: Kotlin 2.4.20, Gradle 9.4.0+, and modernized build infrastructure
This release updates the Shadow Gradle plugin to version 9.7.0-SNAPSHOT, raising the minimum supported Gradle version to 9.4.0 and migrating the build to Kotlin 2.4.20. The project now uses a version catalog (libs.versions.toml) to manage dependencies, including updates to core libraries like jdependency (2.16), Log4j (2.26.1), and ASM/plexus components. The build infrastructure includes a dedicated build-logic subproject, integration with Develocity 4.6.0 for build scans, and configuration for publishing to Maven Central under the new \com.gradleup.shadow\ group. Users benefit from improved compatibility with modern Gradle features like the configuration cache and isolated projects, as well as stricter Kotlin ABI validation.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 42 → 63 (+21.0)
- Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 99 → 97 (-2.1)
- Architecture 96 → 99 (+3.7)
- Maturity 54 → 63 (+9.0)
- Readiness 28 → 57 (+28.8)
- Security 35 → 58 (+22.7)
Resolved (24)
- Coverage not measured — test suite did not build
- Dimension evaluation failed
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 4 more
New (49)
- ApacheNoticeResourceTransformer.modifyOutputStream (cognitive 16) (src/main/kotlin/com/github/jengelman/gradle/plugins/shadow/transformers/ApacheNoticeResourceTransformer.kt)
- ApacheNoticeResourceTransformer.transform (cognitive 35) (src/main/kotlin/com/github/jengelman/gradle/plugins/shadow/transformers/ApacheNoticeResourceTransformer.kt)
- ApacheNoticeResourceTransformer.transform (cyclomatic 17) (src/main/kotlin/com/github/jengelman/gradle/plugins/shadow/transformers/ApacheNoticeResourceTransformer.kt)
- Change coupling: ShadowPlugin.kt ↔ ShadowJar.kt (src/main/kotlin/com/github/jengelman/gradle/plugins/shadow/ShadowPlugin.kt)
- Dependency hygiene PARTLY measured — Maven/Gradle declarations read, no dependency graph resolved
- Duplicated block (5 lines × 2) (src/main/kotlin/com/github/jengelman/gradle/plugins/shadow/transformers/AppendingTransformer.kt)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 29 more
Changes since last survey
- 176 commits — 166 feature/other, 10 fixes
By area
- (root) — 37 commits
- src/main — 37 commits
- src/functionalTest — 25 commits
- gradle/libs.versions.toml — 23 commits
- docs/configuration — 13 commits
- docs/changes — 10 commits
- src/test — 9 commits
- src/documentTest — 7 commits
- gradle/wrapper — 4 commits
- src/testKit — 4 commits
- .github/workflows — 2 commits
- gradle/build-logic — 2 commits
- docs/README.md — 1 commit
- docs/getting-started — 1 commit
- docs/kotlin-plugins — 1 commit
Notable commits
- fix: Comment regression test for issue 1534
- fix: Fix ManifestAppenderTransformer clearing attributes on transform (#2220)
- fix: Fix ManifestResourceTransformer.manifestEntries value type to Any and support CC (#2198)
- fix: Reorder Deprecated section before Fixed in changelog (#2211)
- fix: Revert "Narrow Log4j2Plugins.dat to test sources"
- fix: Revert "Remove _minimizeJar from sourceSetsClassesDirs convention (#2279)"
- fix: Revert "Remove parallel flags (#2035)" (#2299)
- fix: Revert "Run documentation tests in parallel (#2187)"
- fix: Revert "Run testRetry for functionalTest only (#2153)"
- fix: Revert "Workaround missing coroutines dependency in buildscript document tests" (#2314)
- change: Add ProGuardFilesResourceTransformer to merge R8/ProGuard rule files (#2196)
- change: Add R8/ProGuard into the plugin tags (#2177)
- change: Add Renovate updater workflow
- change: Add ShadowJar execution flowchart (#2222)
- change: Add comment for sourceSetsClassesDirs
- change: Add functional tests for missing resource transformers (#2219)
- change: Add functional tests for non-jar exclude and custom r8 args (#2295)
- change: Add testPluginRuntimeOnly for dependencyScope (#2268)
- change: Add tests for Zip64RequiredException handling in ShadowCopyAction (#2303)
- change: Add tests for annotation string values and Kotlin Metadata relocation (#2258)
- …and 156 more
Architecture
- Containers 0 added · 0 removed · contexts 2 added · 0 removed · edges 0 added · 0 removed
Added bounded contexts (2)
- build-logic
- repository
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
GradleUp/shadow was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 25 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 70a0674af36c4ae9bd6bbf5c95e6cba79b07dbb8 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-a9cd699f3cd5.