Sourced from com.diffplug.spotless:spotless-plugin-gradle's releases.
Gradle Plugin v8.5.1
Fixed
licenseHeaderwithsetLicenseHeaderYearsFromGitHistory()no longer runsgit logthrough a shell, eliminating a shell-injection vector when formatting files whose names contain shell metacharacters.Gradle Plugin v8.5.0
Added
scalafmt()now reads the version from theversionfield in the scalafmt config file when no version is explicitly set in the plugin config, falling back to the built-in default only if neither is available. (#2922)- Add
tomlformat type withversionCatalog()step for formatting and sorting Gradle version catalog files. (#2916)- Add
withIndentStyleandwithIndentSizeconfiguration totableTestFormatterfor setting the fallback indent when no.editorconfigis found. (#2893)- Add
javaparserVersion(...)tocleanthat, allowing users to override the JavaParser version pulled in transitively by Cleanthat. (#2903)Fixed
- Fix
tableTestFormattereditorconfig cache not honoring.editorconfigchanges across Gradle daemon runs due to a shared staticEditorConfigProvider. (#2893)- Preserve case of JDBI named bind params that collide with SQL keywords (e.g.
:limit,:offset) in the DBeaver SQL formatter. (#2899)- Fix non-idempotent formatting when
importOrder()is combined withgreclipse(): a single catch-all group no longer strips blank lines thatgreclipse()independently inserted between import groups. (#2914)- Fix
predeclareDepsFromBuildscript()on Gradle 9 by avoiding mutation of the root buildscript configuration container. (#2929, fixes #2599)Changes
- Fix
expandWildcardImportsfailing on JDK XML types such asorg.xml.sax.InputSource. (#2921)- Use Eclipse JDT's collator-based comparison when sorting Java members to better match Eclipse save actions. (#2920)
- Bump default
cleanthatversion2.24->2.25. (#2903)- Bump default
eclipse-jdtversion from4.35to4.39. (#2912)- Make
spotlessPredeclarevisible to Gradle Kotlin DSL type-safe accessors. (#2925)- Allow
spotlessPredeclareto be used directly without enabling it first in spotless extension. (#2925)
c1595c8
Published gradle/8.5.1b26b570
Published lib/4.6.1ac3f6f1
Bump plexus-utils to 4.0.3 to address CVE-2025-67030 (#2932)f5039f6
Bump plexus-utils to 4.0.3 to address CVE-2025-670300e77837
Fix shell-injection in LicenseHeaderStep SET_FROM_GIT mode (#2931)84f6423
Fix shell-injection in LicenseHeaderStep SET_FROM_GIT modeb87eb75
Published maven/3.5.097c3baf
Published gradle/8.5.03dd1a96
Published lib/4.6.005d8954
Feature maven expand wildcard import (#2930
fixes #2829)