Skip to content

CN 243 & CN 219 Spring Boot 3.5.16 to 4.1.1 on Java 21 (Java 25 ready) - #31

Merged
ravindra-tummuru merged 14 commits into
mainfrom
CN-219-spike-investigate-upgrading-the-case-processor-and-case-api-to-spring-boot-v4
Sep 17, 2026
Merged

ravindra-tummuru merged 14 commits into
mainfrom
CN-219-spike-investigate-upgrading-the-case-processor-and-case-api-to-spring-boot-v4

Conversation

@ravindra-tummuru

@ravindra-tummuru ravindra-tummuru commented Sep 7, 2026 •

Copy link
Copy Markdown
Contributor

Motivation and Context

Spring Boot 3.5 left OSS support on 30 June 2026. 3.5.16 is its final free patch release - there are no further community security fixes for Boot 3.5, Spring Framework 6.2, Hibernate 6.6 or the Jackson 2 line as shipped in that BOM. Staying put means running the 2027 test event, and then the census run-up, on an unsupported framework stack.

The spike that preceded this ticket set out to assess the upgrade for the Case Processor and Case API. Its conclusion was that the upgrade is not optional and not deferrable, that it reaches further than those two services, and that the shared libraries, and DDL generator have to move first because everything else compiles against them.

What has changed

Updated census-rm-caseprocessor pom.xml:

  1. Spring Boot 3.5.16 to 4.1.1 on Java 21 (Java 25 ready)
  2. spring-cloud 2025.0.3 to 2025.1.3 (Oakwood)
  3. spring-cloud-gcp 7.4.8 to 8.1.0
  4. shared libs to ${census-rm-shared.version} = 1.0-SNAPSHOT
  5. Added spring-boot-starter-jackson as Boot 4 split JSON out of the core starter and brings Jackson 3
  6. jackson-datatype-jsr310 and jackson-datatype-jdk8 are merged into Jackson 3 databind
  7. hypersistence-utils-hibernate-63:3.15.4 to -73:3.15.5
  8. logstash-logback-encoder 7.4 to 9.0
  9. opencsv 5.9 to 5.12.0 and commons-validator 1.10.1 to 1.11.0
  10. lombok, aspectjweaver, and jakarta.xml.bind pins removed as they are Spring Boot-managed
  11. true REMOVED as this feature deleted in Boot 4
  12. Wire format frozen with use-jackson2-defaults so Pub/Sub payloads are byte-identical to baseline.
  13. Tool Chain updated (Error Prone, JaCoCo, PMD, Spotless, GJF)
  14. Test changes limited to Boot 4's relocated test infrastructure.
  15. No logic changes.

Follow-up tasks to include in existing ticket post migration to address below issues/observations
Remove spring.jackson.use-jackson2-defaults estate-wide, as one announced contract change. Coordinated with integration teams, H2 2027.

Clear the Error Prone 2.50 / PMD 7.26 warning backlog as necessary.

No refactoring. Follow-up task/ticket as above possible breaking change to integration team.
No behaviour or functionality changed. A technology-only migration of seven repositories including this shared library from Spring Boot 3.5.16 to 4.1.1 on a pinned Java 21 baseline, with every repository ready for Java 25 migration.

No functional change/s so no new tests.

How to test?

Run make build in this repository
Run make test in acceptance tests repository

Links

https://officefornationalstatistics.atlassian.net/browse/CN-243
https://officefornationalstatistics.atlassian.net/browse/CN-219
https://officefornationalstatistics.atlassian.net/wiki/x/eYFcGg

Screenshots (if appropriate):

image image

…ration changes necessary for technology only migration. No logic changes.
@ravindra-tummuru ravindra-tummuru added enhancement New feature or request patch A non-feature change, e.g. bug or issue fix labels Sep 7, 2026
@ravindra-tummuru
ravindra-tummuru requested a review from a team September 7, 2026 11:03
@ravindra-tummuru ravindra-tummuru changed the title Cn 219 spike investigate upgrading the case processor and case api to spring boot v4 CN 243 & CN 219 Spring Boot 3.5.16 to 4.1.1 on Java 21 (Java 25 ready) Sep 7, 2026
Comment thread pom.xml Outdated
@github-actions

github-actions Bot commented Sep 8, 2026 •

Copy link
Copy Markdown

🦙 MegaLinter status: ✅ SUCCESS

Descriptor Linter Files Fixed Errors Warnings Elapsed time
✅ MARKDOWN markdownlint 2 0 0 0.22s

See detailed report in MegaLinter reports

MegaLinter is graciously provided by OX Security

Comment thread pom.xml Outdated
Comment thread pom.xml Outdated
Comment thread src/main/java/uk/gov/ons/census/caseprocessor/config/DefaultListenerSupport.java Outdated
Comment thread src/main/java/uk/gov/ons/census/caseprocessor/config/DefaultListenerSupport.java Outdated

@AdamHawtin AdamHawtin left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@AdamHawtin AdamHawtin added the do not merge Do not merge this pull request label Sep 9, 2026
- Import the legacy Spring RetryListener and keep the core retry listener fully qualified to avoid the type-name collision.

- Also add an inline comment explaining that this class intentionally bridges migrated runtime retry wiring and legacy @retryable listener usage, with no behavioural change.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Unresolved critical mapper and Logback findings, plus a moderate retry-listener compatibility issue, must be addressed.

Once you've addressed the issues Copilot identified, you can request another Copilot review.

Pull request overview

This pull request upgrades the Case Processor from Spring Boot 3.5.16 to 4.1.1 with Jackson 3, updated Spring Cloud dependencies, and Java 21 compatibility.

Changes:

  • Updates framework, dependency, and build-tool versions.
  • Migrates JSON handling and retry APIs.
  • Updates logging and Jackson compatibility configuration.
  • Adjusts tests for Boot 4 APIs.
File summaries
File Reviewed changes Findings
src/test/java/uk/gov/ons/census/caseprocessor/testutils/PubsubHelper.java Updates test JSON and HTTP APIs. No final comment.
src/test/java/uk/gov/ons/census/caseprocessor/testutils/JsonHelper.java Migrates test JSON handling to Jackson 3. No final comment.
src/test/java/uk/gov/ons/census/caseprocessor/messaging/ManagedMessageRecovererTest.java Adds retry-exception recovery coverage. No final comment.
src/test/java/uk/gov/ons/census/caseprocessor/messaging/FulfilmentRequestReceiverTest.java Updates Jackson 3 test handling. No final comment.
src/test/java/uk/gov/ons/census/caseprocessor/messaging/FulfilmentRequestReceiverIT.java Updates Jackson 3 integration-test handling. No final comment.
src/main/resources/logback-spring.xml Updates logging configuration. Critical: The DOCTYPE does not match the configuration root and may prevent startup.
src/main/resources/application.yml Adds Jackson compatibility configuration. No final comment.
src/main/java/uk/gov/ons/census/caseprocessor/utils/RedactHelper.java Migrates Jackson exception and mapper types. No final comment.
src/main/java/uk/gov/ons/census/caseprocessor/utils/ObjectMapperFactory.java Creates the Jackson 3 mapper. Critical: The mapper does not apply the configured compatibility defaults, risking changed wire-format output.
src/main/java/uk/gov/ons/census/caseprocessor/utils/JsonHelper.java Migrates JSON serialization and exception handling. No final comment.
src/main/java/uk/gov/ons/census/caseprocessor/messaging/ManagedMessageRecoverer.java Supports updated retry recovery callbacks. No final comment.
src/main/java/uk/gov/ons/census/caseprocessor/config/MessageConsumerConfig.java Uses the Spring Core retry listener API. No final comment.
src/main/java/uk/gov/ons/census/caseprocessor/config/DefaultListenerSupport.java Bridges retry listener contracts. Moderate: Core retry callback signatures are not implemented, making the bridge ineffective.
src/main/java/uk/gov/ons/census/caseprocessor/Application.java Updates the relocated EntityScan import. No final comment.
pom.xml Updates platform, dependency, and build-plugin versions. No final comment.
Review details

Suppressed comments (1)

src/main/java/uk/gov/ons/census/caseprocessor/config/DefaultListenerSupport.java:10

  • This class is declared as a bridge for both retry APIs, but its overridden methods still use org.springframework.retry.RetryContext and RetryCallback. The bean is registered as org.springframework.core.retry.RetryListener, whose callbacks use the Spring Core retry types, so the new runtime will call its default methods rather than these overloads; the bridge is therefore ineffective. Implement the Core retry callback signatures separately, retaining the legacy overloads only if @Retryable support is still required.
/* Bridge both listener contracts so one bean supports migrated runtime wiring and legacy @Retryable
listeners. */
public class DefaultListenerSupport
    implements org.springframework.core.retry.RetryListener, RetryListener {
  • Files reviewed: 14/15 changed files
  • Comments generated: 1
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread src/main/java/uk/gov/ons/census/caseprocessor/utils/ObjectMapperFactory.java Outdated
…at directly guard the Jackson 3 compatibility contracts and additional tests on retry functionality as per the review comments.
…vocations using:

- MESSAGE_TOTAL_ATTEMPTS = 3
- maxRetries(MESSAGE_TOTAL_ATTEMPTS - 1)
- This preserves the pre-migration runtime behavior.
@ravindra-tummuru ravindra-tummuru removed the do not merge Do not merge this pull request label Sep 17, 2026
@ravindra-tummuru
ravindra-tummuru merged commit 6029110 into main Sep 17, 2026
4 of 5 checks passed
@ravindra-tummuru
ravindra-tummuru deleted the CN-219-spike-investigate-upgrading-the-case-processor-and-case-api-to-spring-boot-v4 branch September 17, 2026 15:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request patch A non-feature change, e.g. bug or issue fix

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants