Prevent NPE crash when updating `MODULE.bazel.lock` with `null` `RepoRuleId`. When a lockfile contains an entry from before commit 3d60f1c or from a merge conflict resolution that lacks `repoRuleId`, GSON deserializes `RepoSpec` with `repoRuleId = null`. Later, when Bazel updates and writes the lockfile in `BazelLockFileModule.updateLockfile`, serializing `RepoSpec` invokes `repoRuleId.toString()`, which throws an NPE resulting in a Bazel crash. Now we have proper `null`-safety checks in GSON TypeAdapters so that malformed lockfile entries with `null` repoRuleId are cleanly reported. Fixes https://github.com/bazelbuild/bazel/issues/24716 PiperOrigin-RevId: 971891689 Change-Id: I405c61d5c6f4d20b9908083099a1e64d7f571350
{Fast, Correct} - Choose two
Build and test software of any size, quickly and reliably.
Speed up your builds and tests: Bazel rebuilds only what is necessary. With advanced local and distributed caching, optimized dependency analysis and parallel execution, you get fast and incremental builds.
One tool, multiple languages: Build and test Java, C++, Android, iOS, Go, and a wide variety of other language platforms. Bazel runs on Windows, macOS, and Linux.
Scalable: Bazel helps you scale your organization, codebase, and continuous integration solution. It handles codebases of any size, in multiple repositories or a huge monorepo.
Extensible to your needs: Easily add support for new languages and platforms with Bazel's familiar extension language. Share and re-use language rules written by the growing Bazel community.
To report a security issue, please email security@bazel.build with a description of the issue, the steps you took to create the issue, affected versions, and, if known, mitigations for the issue. Our vulnerability management team will respond within 3 working days of your email. If the issue is confirmed as a vulnerability, we will open a Security Advisory. This project follows a 90 day disclosure timeline.
See CONTRIBUTING.md