Guides Gradle 9 build changes in apache/grails-core on the 8.0.x line, favoring the repo's convention plugins, BOM platforms and patterns over generic Gradle advice.
Install the "gradle-developer" agent skill from https://github.com/apache/grails-core/tree/8.0.x/.agents/skills/gradle-developer into .claude/skills/gradle-developer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gradle-developer", then confirm the skill loads.
Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Type this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
skills CLI
$ npx skills add apache/grails-core --skill gradle-developer -a codex
Project install goes to .agents/skills/; add -g for ~/.codex/skills/.
Install the "gradle-developer" agent skill from https://github.com/apache/grails-core/tree/8.0.x/.agents/skills/gradle-developer into .agents/skills/gradle-developer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gradle-developer", then confirm the skill loads.
Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add apache/grails-core --skill gradle-developer -a cursor
Project install goes to .agents/skills/; add -g for ~/.cursor/skills/.
Install the "gradle-developer" agent skill from https://github.com/apache/grails-core/tree/8.0.x/.agents/skills/gradle-developer into .cursor/skills/gradle-developer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gradle-developer", then confirm the skill loads.
Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
skills CLI
$ npx skills add apache/grails-core --skill gradle-developer -a gemini-cli
Project install goes to .agents/skills/; add -g for ~/.gemini/skills/.
Install the "gradle-developer" agent skill from https://github.com/apache/grails-core/tree/8.0.x/.agents/skills/gradle-developer into .gemini/skills/gradle-developer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gradle-developer", then confirm the skill loads.
Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Installs for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
skills CLI
$ npx skills add apache/grails-core --skill gradle-developer -a github-copilot
Project install goes to .agents/skills/; add -g for ~/.copilot/skills/.
Install the "gradle-developer" agent skill from https://github.com/apache/grails-core/tree/8.0.x/.agents/skills/gradle-developer into .github/skills/gradle-developer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gradle-developer", then confirm the skill loads.
GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add apache/grails-core --skill gradle-developer -a opencode
OpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
Install the "gradle-developer" agent skill from https://github.com/apache/grails-core/tree/8.0.x/.agents/skills/gradle-developer into .opencode/skills/gradle-developer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gradle-developer", then confirm the skill loads.
OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Facts
Skill name
gradle-developer
GitHub stars
2.9k
Token cost
~11k tokens
SKILL.md length
4,200 words
Files
1
Skills in repo
9
Repo updated
First seen
Licence
Apache-2.0
At a glance
Guides Gradle 9 build changes in apache/grails-core on the 8.0.x line, favoring the repo's convention plugins, BOM platforms and patterns over generic Gradle advice.
Works in 5 steps: Match neighboring modules. Before… → Prefer existing convention plugins over… → Gradle docs are secondary. Official… → …
Editing build.gradle, settings.gradle or anything under build-logic
SKILL.md covers What I Do, When to Use Me, Prime Directive: This Repo Wins and Topology (Know Where You Are), plus 9 more sections
Calls gradle; reaches develocity.apache.org
What it does
The skill tells the agent to write and change Gradle build scripts the way this repository already does on the 8.0.x line, which uses Gradle 9.8.x. Its prime directive is that the repo wins over generic best practice: copy neighboring modules' build.gradle files, reuse existing convention plugins instead of inline configuration, and treat the official Gradle docs as secondary, because the monorepo deliberately differs, for example by leaving the configuration cache off and using a custom BOM validator.
Coverage includes the composite builds (build-logic, grails-gradle, grails-forge, end-to-end), convention plugins, BOM and platform() dependency management, test wiring, publishing hooks and Gradle 9 task-configuration traps learned from recent PRs. Loading it is mandatory before editing build.gradle, settings.gradle, gradle.properties or dependencies.gradle, adding or renaming a module, bumping a dependency or the wrapper, changing test, publish, SBOM, code-style or JaCoCo wiring, or diagnosing configuration-cache and task-graph failures. Other skills handle static-analysis violations, failing tests, plugin-repo merges and Grails 8 upgrades.
When your agent uses it
Editing build.gradle, settings.gradle or anything under build-logic
Adding or renaming a module in the Grails monorepo
Bumping a dependency version or the Gradle wrapper
Diagnosing configuration-cache, dependency-resolution or task-graph failures
Example prompts
“Add a new subproject to grails-core and wire it up like its neighbors.”
“Bump the Gradle wrapper and fix whatever breaks in build-logic.”
“A build fails inside afterEvaluate on the 8.0.x branch. Find the cause.”
Requirements
A checkout of apache/grails-core on the 8.0.x line
Workflow steps
5 steps, taken from the first numbered list in SKILL.md.
1Match neighboring modules. Before inventing structure, open 2-3 similar build.gradle files and copy their plugin block, dependency style…
2Prefer existing convention plugins over inline configuration. If CompilePlugin already sets encoding, release, jars, and reproducibility…
3Gradle docs are secondary. Official Gradle 9 docs are useful for APIs and deprecations, but this monorepo intentionally diverges…
4Do not use io.spring.dependency-management / Spring Dependency Management plugin in core modules or applications. The intentional…
5Scope Gradle invocations to the touched subproject (:module:test, not root test) unless the change is cross-cutting.
What it can do on your machine
Read from SKILL.md and the folder at commit 3d6db18. It shows what the files ask for, not the result of running them.
Tool permissions
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Runs code
Shell commands in SKILL.md call:
gradle
From the folder's file list and the shell code blocks in SKILL.md.
Network
Hosts in commands or code, which the agent is likely to contact:
develocity.apache.org
Also links to:
docs.gradle.org
From URLs in SKILL.md, links to its own repository left out.
Credentials
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Context cost
Grails Gradle Developer loads about 11k tokens when it runs. Until then it costs about 64 tokens; SKILL.md has 4,200 words of instructions outside code blocks.
Always· name and description, kept in context so the agent knows when to use it
~64
When it runs· the whole SKILL.md, loaded when a task matches
~11k
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
Safety
Auto-check passed
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
Download SKILL.mdSave it as .claude/skills/gradle-developer/SKILL.md (or your agent's skills folder).
name
gradle-developer
description
Expert guide for Gradle 9 builds in apache/grails-core on the 8.0.x line - multi-project topology, convention plugins, BOM platforms, dependency rules, task configuration hygiene, and repo-specific patterns that override generic Gradle docs
license
Apache-2.0
<!--
SPDX-License-Identifier: Apache-2.0
Licensed to the Apache Software Foundation (ASF) under one or more contributor license agreements; and to You under the Apache License, Version 2.0.
-->
What I Do
Write and change Gradle build scripts the way this repository already does them on 8.0.x (Gradle 9.8.x).
Keep agents off generic Gradle "best practice" when it conflicts with established monorepo patterns.
Cover composite builds (build-logic, grails-gradle, grails-forge, end-to-end), convention plugins, BOM/platform() dependency management, test wiring, publishing hooks, and Gradle 9 task-configuration traps learned from recent PRs.
Make Gradle changes boring, copy-paste consistent, and correct on the first try.
When to Use Me
MANDATORY before any of the following:
Editing build.gradle, settings.gradle, gradle.properties, dependencies.gradle, or anything under gradle/, build-logic/, grails-gradle/
Adding or renaming a module / subproject
Bumping a dependency version or the Gradle wrapper
Changing test, publish, SBOM, code-style, or JaCoCo Gradle wiring
Touching Grails Gradle plugins used by apps (org.apache.grails.gradle.*)
Diagnosing configuration-cache, resolution, afterEvaluate, or task-graph failures
Also load when a change looks like application code but requires build script updates (new module, new published artifact, CLI companion jar, functional test app).
Related skills (do not substitute this one):
Need
Skill
CodeNarc / Checkstyle / PMD / SpotBugs reports
violation-fixer
Failing tests / aggregate reports
test-fixer
Merging an external plugin repo into the monorepo
mono-repo-integration
App-facing Grails 8 upgrade guidance
grails-8-upgrade
Prime Directive: This Repo Wins
Match neighboring modules. Before inventing structure, open 2-3 similar build.gradle files and copy their plugin block, dependency style, and apply { from ... } scripts.
Prefer existing convention plugins over inline configuration. If CompilePlugin already sets encoding, release, jars, and reproducibility, do not re-declare those in the module script.
Gradle docs are secondary. Official Gradle 9 docs are useful for APIs and deprecations, but this monorepo intentionally diverges (configuration cache off, no Spring DM plugin, heavy projectDir remapping, presence-based -P flags, custom BOM validator). When docs and this repo disagree, follow this repo unless you are deliberately fixing a known issue with a tracked reason.
Do not useio.spring.dependency-management / Spring Dependency Management plugin in core modules or applications. The intentional regression fixture at grails-test-examples/spring-dependency-management is the only exception. Grails 8 otherwise uses native platform() / enforcedPlatform() plus org.apache.grails.gradle.bom-property-overrides (see PR #15467).
Scope Gradle invocations to the touched subproject (:module:test, not root test) unless the change is cross-cutting.
Change workflow
Inspect 2-3 sibling modules and the relevant convention plugin or shared script.
Confirm the Gradle project path in settings.gradle, including any projectDir mapping.
Edit the smallest appropriate build file or convention plugin.
Run scoped compile, test, and validateDependencyVersions tasks for the changed project.
For grails-gradle changes, run the relevant plugin TestKit tests from grails-gradle/ with its wrapper.
Topology (Know Where You Are)
This git repo is several independent Gradle builds, not one flat multiproject:
Build
Path
Role
How to run
Root framework
repo root
60+ published modules, BOMs, test-examples, profiles, docs
./gradlew … from root
build-logic
build-logic/
Shared convention plugins via includeBuild
cd build-logic && ./gradlew … (or root pluginManagement includeBuild)
grails-gradle
grails-gradle/
Published Grails Gradle plugins for apps
cd grails-gradle && ./gradlew …
grails-forge
grails-forge/
App generator (own wrapper, own deps)
cd grails-forge && ./gradlew …
end-to-end
end-to-end/
Tests against published artifacts in build/local-maven
Full 3-step flow below (see end-to-end/README.md)
gradle-bootstrap
gradle-bootstrap/
Regenerates shared wrappers from .sdkmanrc
gradle -p gradle-bootstrap (see wrapper section)
end-to-end is not a composite consumer of the root build. It resolves real published coordinates from <repo>/build/local-maven (the TestCaseMavenRepo), not~/.m2 and not via publishAllToMavenLocal. Do not add includeBuild('..') substitution - that defeats validating consumer metadata, CLI companions, and POM/BOM shape.
Full local run (three steps, in order):
bash
# 1) Publish grails-gradle + root into build/local-maven (both required)
(cd grails-gradle && ./gradlew publishAllPublicationsToTestCaseMavenRepoRepository)
./gradlew publishAllPublicationsToTestCaseMavenRepoRepository
# 2) Build the standalone Grails 7 fixture jar (JDK 17 / Gradle 8.x via its .sdkmanrc)
cd end-to-end/legacy-g7-command-plugin
sdk env
./gradlew jar
cd ../..
# 3) Run the suite on the root JDK 21 environment
sdk env # from repository root (.sdkmanrc)
cd end-to-end
./gradlew check
Leave legacy-g7-command-plugin's wrapper on its pinned Grails 7 Gradle version when bumping the main line.
Root settings.gradle wires:
groovy
pluginManagement {
includeBuild('./grails-gradle') { name = 'grails-gradle' }
includeBuild('./build-logic') { name = 'build-logic-root' }
// ...
}
build-logic exists because composite builds do not share buildSrc plugins. Internal conventions live there so root, grails-gradle, and forge can consume them.
Always use the Gradle project path in task names (./gradlew :grails-data-hibernate7-core:test). Confirm with settings.gradleinclude + projectDir when unsure. Do not invent paths from folder names alone.
Micronaut "island"
grails-micronaut*, micronaut BOMs, and related test-examples are gated in settings.gradle:
-PskipMicronautProjects forces exclude (used by groovy-joint CI)
-PincludeMicronautProjects forces include on older JDKs (still may not compile)
Presence-based flags (property present, value optional) match skipFunctionalTests / skipCodeStyle style elsewhere.
Gradle Version Sync (Hard Rule)
Current line: Gradle 9.8.0 (distributionUrl + gradleToolingApiVersion=9.8.0). Upstream may already ship a newer 9.8.x patch - this repo rides close to latest only after a deliberate multi-location bump PR. Do not "helpfully" jump one wrapper ahead of the rest.
Two Groovy stacks: Gradle itself embeds Groovy 4 for build logic. Application/runtime code on 8.0.x is Groovy 5. That is why dependencies.gradle keeps separate maps:
Set the new Gradle version in .sdkmanrc (gradle=…).
Run the bootstrap project (uses a system gradle to regenerate shared wrappers from .sdkmanrc):
bash
gradle -p gradle-bootstrap
Bootstrap generates the wrapper under gradle-bootstrap/, copies it to grails-forge, grails-gradle, and end-to-end, then moves the generated wrapper into the repository root. It also runs legacyG7Wrapper so end-to-end/legacy-g7-command-plugin stays on its pinned Grails 7 Gradle version (currently 8.x - do not force it to 9). Root is therefore bootstrap-covered; do not re-list it as a manual step.
Manually refresh the locations bootstrap does not cover. For each tree, keep the full wrapper set in sync (gradle-wrapper.properties, gradle-wrapper.jar, gradlew, gradlew.bat) - not properties alone:
build-logic/ - run its wrapper task or copy the complete set from root after bootstrap
grails-profiles/base/skeleton/ and grails-profiles/profile/skeleton/
grails-shell-cli/src/test/resources/gradle-sample/ (and bin/test copy if present)
Forge generated-app wrapper assets (all of these - properties alone is not enough):
gradle.properties → gradleToolingApiVersion (must match the new Gradle version)
Verify every main-line tree matches on properties and scripts/jars. The only intentional holdout is end-to-end/legacy-g7-command-plugin (Gradle 8.x).
Also keep gradlew.bat LF line endings on this line (PR #15709). Comment at top of root gradle-wrapper.properties remains a human checklist.
Root gradle.properties Flags (Do Not "Fix" Blindly)
Property
Value / note
org.gradle.caching
true
org.gradle.parallel
true
org.gradle.daemon
true
org.gradle.configuration-cache
false until #15497 resolved - do not enable casually
org.gradle.configureondemand
commented off - Gradle issue #9489
org.gradle.jvmargs
-Xmx3G (daemon only; groovydoc and the guide run in their own JVMs)
javaVersion
21 (CompilePlugin reads this for --release)
projectVersion
framework version
slf4jPreventExclusion
true - Grails Gradle plugin POM behavior
CI vs local behavior is branched on System.getenv('CI') and SOURCE_DATE_EPOCH (reproducible builds disable remote cache).
groovydocMaxHeapSize and guideMaxHeapSize are not keys in gradle.properties - do not add
them. Each documentation JVM carries its own default (1g per groovydoc task, raised to 3g/2g by the
two aggregates; 1500m for the guide), and these exist only as -P overrides that beat the build
script when a documentation run will not fit.
Standard Published Library Module
Canonical pattern (see grails-core/build.gradle, grails-controllers/build.gradle, grails-services/build.gradle):
groovy
/*
* Licensed to the Apache Software Foundation (ASF) under one
* ... Apache header ...
*/
plugins {
id 'groovy'
id 'java-library'
id 'project-report' // optional but common
id 'org.apache.grails.buildsrc.properties'
id 'org.apache.grails.buildsrc.dependency-validator'
id 'org.apache.grails.buildsrc.compile'
id 'org.apache.grails.buildsrc.publish'
id 'org.apache.grails.buildsrc.sbom'
id 'org.apache.grails.buildsrc.vulnerability-scan' // when appropriate
id 'org.apache.grails.gradle.grails-code-style'
id 'org.apache.grails.gradle.grails-jacoco'
}
version = projectVersion
group = 'org.apache.grails' // or org.apache.grails.web / .data / etc. - match siblings
dependencies {
implementation platform(project(':grails-bom')) // or :grails-hibernate7-bom, etc.
api project(':grails-core')
api 'org.apache.groovy:groovy'
// versions come from the platform - do NOT hardcode versions here
compileOnly 'jakarta.servlet:jakarta.servlet-api'
testImplementation 'org.spockframework:spock-core'
testImplementation 'org.apache.groovy:groovy-test-junit5'
testImplementation 'org.junit.jupiter:junit-jupiter-api'
testRuntimeOnly 'org.junit.jupiter:junit-jupiter-engine'
// junit-platform-launcher is added by gradle/test-config.gradle
}
apply {
from rootProject.layout.projectDirectory.file('gradle/docs-config.gradle')
from rootProject.layout.projectDirectory.file('gradle/test-config.gradle')
}
Rules for module scripts
Apache license header on every new .gradle / .gradle.kts file.
Prefer Groovy DSL (this repo is almost entirely .gradle, not .kts).
version = projectVersion and explicit group - do not invent version schemes per module.
Use rootProject.layout.projectDirectory.file('gradle/…') for shared scripts (lazy layout API), not brittle rootProject.file string soup in new code.
Prefer tasks.named('x') / tasks.withType(T).configureEach over eager task x << or bare tasks.x { } mutation when touching existing modernized code.
Configuration avoidance: do not call .get() on providers during configuration unless required; do not resolve configurations at configuration time.
api vs implementation vs compileOnly vs runtimeOnly vs testImplementation - follow Java Library plugin semantics; public types in your API surface → api.
Project deps: project(':grails-foo') using the settings path.
External deps: coordinate without version when the BOM manages them.
CLI companion modules
Command-bearing modules may apply org.apache.grails.gradle.grails-plugin-cli and declare cliApi / cliImplementation configurations (PR #15948). Framework modules that wire CLI with project deps set ext.grailsCliAutoProvision = false (root build.gradle does this for non-test-example projects). Do not dump CLI-only deps back onto the main runtime classpath.
Functional / Test-Example Apps
See grails-test-examples/app1/build.gradle:
Apply Grails app plugins: org.apache.grails.gradle.grails-web, often org.apache.grails.gradle.grails-gsp, and cloud.wondrify.asset-pipeline
Still use implementation platform(project(':grails-bom'))
Depend on published coordinates (org.apache.grails:grails-dependencies-starter-web) - root applies dependency substitution via gradle/functional-test-config.gradle so local projects replace Maven coordinates
Apply gradle/functional-test-config.gradle (and datastore-specific scripts like hibernate7-test-config.gradle when needed)
Do not disable substitution without understanding multi-project resolution
Dependency Management (BOM Is Law)
Single source of versions
File
What it owns
Rootdependencies.gradle
Application/runtime BOM versions (bomDependencyVersions, bomDependencies, bomPlatformDependencies) and gradle-tooling maps (gradleBomDependencyVersions, etc.). grails-gradle applies this same file via ../dependencies.gradle - there is no separate grails-gradle/dependencies.gradle on this line
No gradle/libs.versions.toml. This monorepo does not use Gradle version catalogs. Do not introduce a catalog "because Gradle docs recommend it." Dependabot and the published BOM pipeline are built around the root dependencies.gradle maps (see comment at top of that file).
Map naming contract
For POM property generation, map key must be the dependency name prefix:
Applied via org.apache.grails.buildsrc.dependency-validator.
Implementation detail (GrailsDependencyValidatorPlugin): for each resolved coordinate that the BOM also manages, it fails when bomVersion != resolvedVersion - any mismatch, not only "resolved is newer."
How to fix by direction:
Situation
Fix
Transitive resolved newer than BOM
Bump the pin in dependencies.gradle so the BOM is >= the winner (usual case; AGENTS.md rule 14)
Resolved older / forced / strict conflict
Find the force, strict constraint, or second platform pulling the other version; remove the force, align platforms, or document a deliberate override
Intentional divergence that must stay
ext.allowedBomOverrides = ['group:name', …] with a commented reason - last resort
Whole project cannot validate
Prefer ext.skipDependencyValidation = true in the build script. CLI: -PskipDependencyValidation is presence-based and skips validation; -PskipDependencyValidation=true is also valid. Use the documented form that best communicates intent.
Also:
Prefer inheriting Spring Boot managed versions over re-pinning duplicates (PR #15730). Only pin when diverging (security override, missing from Boot BOM, lockstep companion like graphql-java-extended-scalars).
Same coordinate managed in multiple BOM maps must use the same version everywhere or enforcedPlatform resolution explodes.
Do not silence validation with exclusions as a shortcut to avoid a BOM bump.
validateBomProperties (parent BOM property rules)
Registered by its own plugin, org.apache.grails.buildsrc.bom-property-validator, which every BOM applies (on java-platform projects only). Like validateDependencyVersions it is not attached to check or build; CI runs it by name in its own Validate BOM Properties job (root BOMs and grails-gradle-bom). It has its own opt-out, skipBomPropertyValidation, which works like skipDependencyValidation (-PskipBomPropertyValidation, -PskipBomPropertyValidation=true, or ext.skipBomPropertyValidation = true); each property skips only its own task. It reads the POM a BOM publishes (generatePomFileForMavenPublication). Every version property the BOM owns (ext.bomVersionProperties: gradleBomDependencyVersions for grails-gradle-bom, bomDependencyVersions for grails-base-bom, customBomVersions for each variant) must be used by some published entry. It also compares the POM with the parent BOMs named by ext.parentBoms (spring-boot-dependencies, set in dependencies.gradle), including the BOMs they import, and for every module both manage it fails when:
Rule
Example failure
Fix
(any owned property) No published entry uses the version key
liquibase-hibernate5.version = 4.27.0
Delete the key, or add the dependency that should use it
The pin uses a different property than the parent controls the module with
${jackson3.version} should be ${jackson-bom.version}
Rename the version key, and the dependency keys that prefix it (map naming contract)
The pin overrides a version the parent writes literally (all of Spring Boot's own org.springframework.boot:* entries)
${foo.version}, where only ${spring-boot.version} moves the parent's version
Drop the pin, or add a documented exemption - renaming it to the parent's import property would only repeat the parent's version
The pin repeats the parent's version
graphql-java.version = 25.0
Drop the pin and inherit the parent's version
A module the parent manages through an imported BOM belongs to the property the parent imports that BOM with (jackson-bom.version for all of tools.jackson:jackson-bom), because that is the property a consumer sets to move the family. Coordinates and versions are resolved from each parent POM's properties, its own parents' and the Maven built-ins (${project.groupId}, as the Kotlin and Brave BOMs write their group, ${project.version}, ${project.parent.version}); an entry that cannot be resolved fails the task with Cannot resolve <entry>, managed by <bom> instead of going unchecked, so teach PomVersions.properties the missing built-in. Deliberate exceptions go in bomUnusedVersionExemptions / bomPropertyNameExemptions / bomRedundantVersionExemptions in dependencies.gradle, each with its reason.
Adding or bumping a dependency
Decide if Spring Boot already manages it - if same version, omit pin; if a different version, name the version key after Spring Boot's property (validateBomProperties enforces both).
If Grails must manage it, add/bump in the correct map in dependencies.gradle.
Use the unversioned coordinate in module dependencies {}.
Run ./gradlew :that-module:validateDependencyVersions (and affected consumers).
Security overrides: comment with CVE and previous Boot version (see existing httpcore5/jackson/logback pins).
Exclusions
Use sparingly, always with a reason. Common pattern for Hibernate:
Do not exclude your way out of a BOM version fight. Prefer the direction-aware fixes in the validator table above (usually bump the BOM when a transitive is newer; otherwise align forces/platforms).
Convention Plugins (build-logic)
Plugin IDs (implementation under build-logic/plugins/…/buildsrc/):
JavaCompile.options.release from javaVersion (21) - not outdated sourceCompatibility/targetCompatibility pairs in new code
UTF-8 everywhere
-parameters for reflection/IDE
Forked compilation with -Dgrails.isolated.build=true and a per-projectBaseDirArgumentProvider supplying -Dbase.dir=<projectDir>. It is marked @Internal, not @InputDirectory, because projectDir contains build outputs. Do not remove it: it prevents grails.factories leaking between compiler daemons (#15799 / CompilePlugin comments).
The compile-time base.dir provider is required, but absolute base.dir values are forbidden in Test.systemProperties: they make cache keys machine-specific. Never "simplify" by removing the compiler provider or adding an absolute test property.
Jar.duplicatesStrategy = FAIL - duplicate entries are configuration bugs
Reproducible archives: no timestamps, fixed order, unix 0644/0755
Groovy configurationScript → gradle/groovy-compile-configscript.groovy (annotation member order / GROOVY-12146 workaround, PR #15963)
Published Grails Gradle plugins (grails-gradle)
Use the fully qualified plugin IDs in plugins { id '…' } blocks. Most are registered in grails-gradle/plugins/build.gradle. org.apache.grails.gradle.grails-publish is supplied by the external grails-publish-plugin implementation dependency (not listed in that file's gradlePlugin {} block) but is still the correct ID for publishing.
Parallelism: configuredTestParallel from -PmaxTestParallel or CI default 3 / local availableProcessors * 3/4.
Env:
DO_NOT_CACHE_TESTS=1 - force test re-run without full --rerun-tasks
debug.tests system prop - attach debugger args
SUPPRESS_DEPRECATION_WARNINGS=true - strip some -Xlint noise
CI disables build cache for GroovyCompile and Test so AST transforms and tests stay honest.
Configuration Hygiene (Gradle 9.x Landmines)
These bit this repo in production PRs. Treat as hard rules when writing plugin or build code:
No configuration-time classpath resolution in task configureEach callbacks. Defer probes to execution (doFirst / task actions) or use proper providers (PR #16076).
No nested afterEvaluate that mutates configurations after another plugin may have resolved a related configuration (PR #16009). Prefer withPlugin / plugins.withId / lazy configurations.configureEach before observation.
Task inputs must include filter/token maps and any other non-file data that affects outputs (PR #16006).
All custom task types must declare caching intent (@DisableCachingByDefault or correct cacheable annotations) - required since Gradle 9 upgrade (PR #15365).
Prefer JavaPluginExtension over deprecated JavaPluginConvention; destinationFile over outputFile on WriteProperties; avoid ConfigureUtil / old convention APIs.
Tests need junit-platform-launcher on testRuntimeOnly (shared script adds it) - Gradle 9 requirement.
Do not enable configuration cache or configure-on-demand in this repo without an issue-linked plan.
evaluationDependsOn appears in BOM/docs scripts for a reason - do not cargo-cult it into random modules; it couples configuration order and slows builds.
Build Cacheability
The local build cache is enabled. Treat cacheability as a correctness constraint, not a later optimization.
Rule
Why / practice
Do not put absolute machine paths, especially base.dir, in Test.systemProperties
They poison cache keys across machines (#15483). The compiler's @InternalBaseDirArgumentProvider is the separate, required compile-time case.
Avoid doFirst and custom actions on cacheable tasks
They can make a task ineligible for the build cache. Prefer a dedicated task with declared inputs and outputs or model the I/O properly. Some tradeoffs are intentional: GroovyDoc compatibility with configuration cache and selected GroovyCompiledoFirst actions in GrailsGradlePlugin.
Give compiler configuration and reports task-specific paths
Overlapping outputs disable caching. Use names such as grailsGroovyCompilerConfig-{taskName}.groovy and separate Checkstyle / CodeNarc report paths (#15532).
Do not use outputs.upToDateWhen to bypass work when it also prevents cache loading
Model inputs and outputs instead. Keep GSP outputs separate, for example gsp-classes/main versus webapp (#15537).
Normalize generated unstable files packed into jars or classpaths
SbomPlugin uses normalization.runtimeClasspath.ignore("META-INF/sbom.json"). Add comparable normalization so unstable generated contents do not cascade cache misses.
Use Develocity experiments to prove a change: populate the cache, then delete task outputs (or clean) and rebuild - cacheable tasks should report FROM-CACHE. A plain second build with outputs still present usually reports UP-TO-DATE, which does not prove remote/local cache loading.
Adding a New Subproject (Checklist)
Choose directory layout consistent with family (grails-foo/… or nested under existing tree).
include 'grails-foo' (or nested name) in root settings.gradle.
If path != default, set project(':grails-foo').projectDir = file('…').
Copy a sibling build.gradle plugin/dependency skeleton; set group/ext.pom* as needed.
Wire platform(project(':grails-bom')) or the correct variant BOM.
If published: ensure publish plugin + BOM constraint inclusion (base BOM auto-discovers published projects with grails-publish plugins).
If it has commands: plan CLI companion artifact (grails-plugin-cli), not runtime leakage.
If test-example: use functional-test-config + external coordinates + substitution.
Register in any root aggregators if required (docs, publish-root-config, CI matrices).
Used deliberately for Micronaut-variant BOMs + validator
Prefer toolchains everywhere
options.release from javaVersion=21 via CompilePlugin (toolchains optional elsewhere)
JVM Test Suite plugin for extra suites
Existing test / integrationTest + shared gradle/*-test-config.gradle
Avoid afterEvaluate
Still present in plugins - change carefully; prefer plugins.withId for new code
Configure on demand
Explicitly disabled (Gradle #9489)
Removed/deprecated APIs AI still emits - reject on sight in new code: jcenter(), Project.exec / Project.javaexec (use injected ExecOperations), JavaPluginConvention, ConfigureUtil, old convention APIs, WriteProperties.outputFile (use destinationFile), bare tasks.create / eager getByName when register/named suffice.
Repositories
GrailsRepoSettingsPlugin configures settings-level repos and RepositoriesMode.FAIL_ON_PROJECT_REPOS. Adding repositories { mavenCentral() } inside a random subproject will fail the build. Fix repo needs in settings / the repo settings plugin, not per-module.
Lessons From Recent 8.0.x Gradle PRs
PR
Takeaway
#15467
Spring DM removed; platforms + bom-property-overrides
#15483
Cacheable tasks need portable inputs; avoid absolute test properties and normalize packed unstable SBOM metadata
#15365
Gradle 9.4 API cleanup; caching annotations; junit launcher
#15532
Overlapping task outputs disable caching; use per-task compiler and report paths
No hardcoded versions that belong in dependencies.gradle
validateDependencyVersions clean for touched modules (or documented override)
Scoped Gradle verify command green (:module:compileGroovy, :module:test, plugin TestKit as applicable)
Wrapper/version sync complete if Gradle version changed
No configuration-time resolution / nested afterEvaluate hazards introduced
No absolute machine paths in Test.systemProperties; compiler base.dir remains isolated in BaseDirArgumentProvider
No overlapping task outputs; classpath normalization considered for packed generated files
Apache headers on new files
User-facing behavior documented if it affects app builds (grails-doc)
For commit-ready work, use violation-fixer to run the AGENTS.md gate: ./gradlew clean aggregateViolations :grails-test-report:check --continue. This is not required merely to read this skill.
If you only remember three things: copy siblings, BOM owns versions, never resolve configurations while configuring tasks.
Grails Gradle Developer next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
Grails Gradle Developer compared with similar skills
Skill
Stars
Used in
Tokens
Auto-check
Licence
Repo updated
Grails Gradle Developer this skillapache/grails-core
Safely plan and execute dependency maintenance for JavaScript/TypeScript (npm, pnpm) and GitHub Actions, including npm lockfiles, pnpm workspaces, catalogs, overrides, SHA-pinned action versions…
Automatically fetch and fix Dependabot security alerts by querying GitHub REST API for open alerts, identifying vulnerable packages, researching secure versions, and updating package.json files…
Sets one monorepo's rules for toolchain pins, pnpm package operations, the shared dependency catalog and moon tasks, so the agent adds versions and scripts the right way.
Guide for writing modern Java 21 in a Grails and Groovy codebase: records, sealed classes, pattern matching, text blocks and how Java works alongside Groovy.
Guides running, reviewing and fixing test failures across grails-core modules with Gradle, including targeted runs and the aggregate HTML and Markdown reports.
Guide to running, reading and fixing code style and analysis violations in grails-core with CodeNarc, Checkstyle, PMD, SpotBugs, Spotless and JaCoCo through Gradle.
Guides Gradle 9 build changes in apache/grails-core on the 8.0.x line, favoring the repo's convention plugins, BOM platforms and patterns over generic Gradle advice. x.gradle files, reuse existing convention plugins instead of inline configuration, and treat the official Gradle docs as secondary, because the monorepo deliberately differs, for example by leaving the configuration cache off and using a custom BOM validator.
When should I use Grails Gradle Developer?
Grails Gradle Developer fits situations like: editing build.gradle, settings.gradle or anything under build-logic; adding or renaming a module in the Grails monorepo; bumping a dependency version or the Gradle wrapper; diagnosing configuration-cache, dependency-resolution or task-graph failures.
How do I install Grails Gradle Developer in Claude Code?
Run `npx skills add apache/grails-core --skill gradle-developer -a claude-code`. Or copy the skill folder (.agents/skills/gradle-developer in apache/grails-core) into .claude/skills/gradle-developer in your project. Claude Code loads it when a task matches its description.
How do I install Grails Gradle Developer in Codex?
Run `npx skills add apache/grails-core --skill gradle-developer -a codex`. Or copy the skill folder (.agents/skills/gradle-developer in apache/grails-core) into .agents/skills/gradle-developer in your project. Codex loads it when a task matches its description.
Can I use Grails Gradle Developer in Cursor, Gemini CLI or GitHub Copilot?
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add apache/grails-core --skill gradle-developer -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/gradle-developer, .gemini/skills/gradle-developer, .github/skills/gradle-developer and .opencode/skills/gradle-developer in your project.
What does Grails Gradle Developer need to run?
Going by SKILL.md and its folder, Grails Gradle Developer needs the command-line tools its instructions call (gradle). Our summary lists: A checkout of apache/grails-core on the 8.0.x line.
Does Grails Gradle Developer access the network?
SKILL.md names 2 domains. In commands or code: develocity.apache.org; the agent is likely to contact it when it follows the instructions. As links in the text: docs.gradle.org. This is read from the text; nothing was executed.
Is Grails Gradle Developer safe to install?
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
What licence does Grails Gradle Developer use?
Grails Gradle Developer is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
How many tokens does Grails Gradle Developer use?
About 11k tokens (SKILL.md is roughly 45k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
What are the alternatives to Grails Gradle Developer?
Skills that share tags, products or a category with Grails Gradle Developer: Linea Dependency Maintenance (Consensys-Incorporated/linea-attestation-registry, 177 stars), Pnpm Engine (teambit/bit, 18k stars), Dependabot Alerts Update (livesession/xyd, 114 stars) and Monorepo Tooling and Dependencies (pierrecomputer/pierre, 6.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Who maintains Grails Gradle Developer?
apache (a GitHub organization) maintains it in apache/grails-core, which has 2,934 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on October 7, 2026.
Source: apache/grails-core on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.