Bazel: Bump rules_js, rules_ts and rules_nodejs

Update the JS ruleset stack: aspect_rules_js 3.1.2 -> 3.2.3,
aspect_rules_ts 3.8.8 -> 3.9.2, rules_nodejs 6.7.4 -> 6.7.5, and adapt
the tree to what the new versions require and enable.

The rules_ts options validator now resolves outDir through the tsconfig
extends chain and rejects the inherited yarn/IDE outDir
(../../.ts-out/...), which escapes the Bazel package. Override it in the
bazel tsconfigs, kept in sync with the out_dir attributes the ts_project
targets already carry.

rules_nodejs 6.7.5 reads the node version from .nvmrc
(node_version_from_nvmrc), so the version is pinned in one cross-tool
file that nvm, editors and CI honor as well -- previously the yarn dev
flow had no node pin at all. Versions newer than the ruleset's built-in
table are auto-fetched and recorded in MODULE.bazel.lock. This retires
the hand-maintained node checksum dict, the per-platform use_repo
boilerplate and the unused root alias of the pnpm extension (rules_js
resolves its own pnpm; the npm_translate_lock update machinery never
consumed the root alias).

The bundled pnpm moves to 10.34.5, whose import marks git-hosted tarball
resolutions with gitHosted: true (10.34.1 lockfile schema). Whether it
also records an integrity field for such tarballs depends on the local
store state: a cold store downloads the tarballs and emits integrity, a
warm store omits it and strips it on re-import -- same version, same
inputs, different lockfile. Reproducer:
https://github.com/davido/pnpm-codeload-repro, filed upstream as
https://github.com/pnpm/pnpm/issues/13338. The committed lock is the
warm-store form, consistent with the action caches below.

That nondeterminism broke CI: every fresh checkout re-ran pnpm import
(cold) and failed with "pnpm-lock.yaml file updated". The root cause is
that the npm_translate_lock action caches were gitignored, so
update_pnpm_lock could never see that the lock is current. Check the
.aspect/rules/external_repository_action_cache files in, as the rules_js
documentation prescribes -- the action cache "persists the state of
package and lock files that may effect the pnpm-lock.yaml generation and
should be checked into the source control along with the pnpm-lock.yaml
file" ("update_pnpm_lock" in
https://github.com/aspect-build/rules_js/blob/main/docs/pnpm.md): with
matching caches the import is skipped entirely and CI no longer depends
on pnpm's store-state behavior.

This stack also pulls in aspect_tools_telemetry, which reports ruleset
usage with repo and user fingerprints at module-resolution time; opt the
whole tree out via ASPECT_TOOLS_TELEMETRY=-all in .bazelrc.

Release-Notes: skip
Change-Id: I018b2e4754a921a69b6004ca78c38dbf08bd7539
14 files changed
tree: 89921477e2fb1bee264f8181881320f038617d32
  1. .agents/
  2. .aspect/
  3. .gemini/
  4. .github/
  5. .settings/
  6. .ts-out/
  7. antlr3/
  8. configs/
  9. contrib/
  10. Documentation/
  11. e2e-tests/
  12. java/
  13. javatests/
  14. lib/
  15. modules/
  16. plugins/
  17. polygerrit-ui/
  18. prolog/
  19. prologtests/
  20. proto/
  21. resources/
  22. tools/
  23. webapp/
  24. .bazelignore
  25. .bazelproject
  26. .bazelrc
  27. .bazelversion
  28. .editorconfig
  29. .git-blame-ignore-revs
  30. .gitignore
  31. .gitmodules
  32. .gitreview
  33. .mailmap
  34. .nvmrc
  35. .pydevproject
  36. .zuul.yaml
  37. AGENTS.md
  38. BUILD
  39. COPYING
  40. external_deps.lock.json
  41. INSTALL
  42. Jenkinsfile
  43. MODULE.bazel
  44. MODULE.bazel.lock
  45. package.json
  46. pnpm-lock.yaml
  47. pnpm-workspace.yaml
  48. README.md
  49. SUBMITTING_PATCHES
  50. web-dev-server.config.mjs
  51. yarn.lock
README.md

Gerrit Code Review

Gerrit is a code review and project management tool for Git based projects.

Build Status Maven Central

Objective

Gerrit makes reviews easier by showing changes in a side-by-side display, and allowing inline comments to be added by any reviewer.

Gerrit simplifies Git based project maintainership by permitting any authorized user to submit changes to the master Git repository, rather than requiring all approved changes to be merged in by hand by the project maintainer.

Documentation

For information about how to install and use Gerrit, refer to the documentation.

Source

Our canonical Git repository is located on googlesource.com. There is a mirror of the repository on Github.

Reporting bugs

Please report bugs on the issue tracker.

Contribute

Gerrit is the work of hundreds of contributors. We appreciate your help!

Please read the contribution guidelines.

Note that we do not accept Pull Requests via the Github mirror.

Getting in contact

The Developer Mailing list is repo-discuss on Google Groups.

License

Gerrit is provided under the Apache License 2.0.

Build

Install Bazel and run the following:

    git clone --recurse-submodules https://gerrit.googlesource.com/gerrit
    cd gerrit && bazel build release

Install binary packages (Deb/Rpm)

The instruction how to configure GerritForge/BinTray repositories is here

On Debian/Ubuntu run:

    apt-get update && apt-get install gerrit=<version>-<release>

NOTE: release is a counter that starts with 1 and indicates the number of packages that have been released with the same version of the software.

On CentOS/RedHat run:

    yum clean all && yum install gerrit-<version>[-<release>]

On Fedora run:

    dnf clean all && dnf install gerrit-<version>[-<release>]

Use pre-built Gerrit images on Docker

Docker images of Gerrit are available on DockerHub

To run a CentOS 8 based Gerrit image:

    docker run -p 8080:8080 gerritcodereview/gerrit[:version]-centos8

To run a Ubuntu 20.04 based Gerrit image:

    docker run -p 8080:8080 gerritcodereview/gerrit[:version]-ubuntu20

NOTE: release is optional. Last released package of the version is installed if the release number is omitted.