This is a patch release for Gradle 9.8.0. We recommend using 9.8.1 instead of 9.8.0.
This release addresses three high rated vulnerabilities:
- Unauthenticated worker-to-daemon channel deserializes untrusted Java objects
- Deserialization of untrusted Java objects before authentication in the client - daemon communication
- Failure to disable repositories failing to establish an SSL connection can expose builds to malicious artifacts
The following issues were resolved:
- [Gradle 9.8.0 complains again about invalid Toolchains on Debian / Ubuntu packaged systems]- (#39358)
- Gradle 9.8.0 removes root java.util.logging handlers installed by a custom LogManager (breaks Quarkus test log capture)
- Dependency resolution regression
We would like to thank the following community members for their contributions to this release of Gradle:
Aman Gautam,
Björn Kautler,
Eng Zer Jun,
Hashim Khan,
Julian Krannich,
KBS,
Labh R Jethe,
Mark Dodgson,
Maxim,
monkey,
nataphon-ktsystems,
Paul King,
Qiu Tian,
rg_sandesh,
Roberto Perez Alcolea,
Sean,
Zongle Wang.
Upgrade instructions
Switch your build to use Gradle 9.8.1 by updating your wrapper:
./gradlew :wrapper --gradle-version=9.8.1 && ./gradlew :wrapper
See the Gradle 9.x upgrade guide to learn about deprecations, breaking changes and other considerations when upgrading.
For Java, Groovy, Kotlin and Android compatibility, see the full compatibility notes.
Reporting problems
If you find a problem with this release, please file a bug on GitHub Issues adhering to our issue guidelines.
If you're not sure you're encountering a bug, please use the forum.
We hope you will build happiness with Gradle, and we look forward to your feedback via Twitter or on GitHub.