Adding VoyageAI integration - #1
Conversation
Bumps [actions/checkout](https://github.com/actions/checkout) from 5 to 6. - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](actions/checkout@v5...v6) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: '6' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
…ions/actions/checkout-6 Bump actions/checkout from 5 to 6
Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact) from 5 to 6. - [Release notes](https://github.com/actions/upload-artifact/releases) - [Commits](actions/upload-artifact@v5...v6) --- updated-dependencies: - dependency-name: actions/upload-artifact dependency-version: '6' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
…ions/actions/upload-artifact-6 Bump actions/upload-artifact from 5 to 6
Bumps org.apache.logging.log4j:log4j-core from 2.24.1 to 2.25.3. --- updated-dependencies: - dependency-name: org.apache.logging.log4j:log4j-core dependency-version: 2.25.3 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
…apache.logging.log4j-log4j-core-2.25.3 Java: Bump org.apache.logging.log4j:log4j-core from 2.24.1 to 2.25.3
Bumps [org.assertj:assertj-core](https://github.com/assertj/assertj) from 3.26.3 to 3.27.7. - [Release notes](https://github.com/assertj/assertj/releases) - [Commits](assertj/assertj@assertj-build-3.26.3...assertj-build-3.27.7) --- updated-dependencies: - dependency-name: org.assertj:assertj-core dependency-version: 3.27.7 dependency-type: direct:development ... Signed-off-by: dependabot[bot] <support@github.com>
…les/semantickernel-demos/semantickernel-spring-starter/org.assertj-assertj-core-3.27.7 Java: Bump org.assertj:assertj-core from 3.26.3 to 3.27.7 in /samples/semantickernel-demos/semantickernel-spring-starter
Bump testcontainers version
Bumps [com.fasterxml.jackson.core:jackson-core](https://github.com/FasterXML/jackson-core) from 2.18.0 to 2.18.6. - [Commits](FasterXML/jackson-core@jackson-core-2.18.0...jackson-core-2.18.6) --- updated-dependencies: - dependency-name: com.fasterxml.jackson.core:jackson-core dependency-version: 2.18.6 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [net.sourceforge.pmd:pmd-core](https://github.com/pmd/pmd) from 7.10.0 to 7.22.0. - [Release notes](https://github.com/pmd/pmd/releases) - [Commits](pmd/pmd@pmd_releases/7.10.0...pmd_releases/7.22.0) --- updated-dependencies: - dependency-name: net.sourceforge.pmd:pmd-core dependency-version: 7.22.0 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact) from 6 to 7. - [Release notes](https://github.com/actions/upload-artifact/releases) - [Commits](actions/upload-artifact@v6...v7) --- updated-dependencies: - dependency-name: actions/upload-artifact dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
…ions/actions/upload-artifact-7 Bump actions/upload-artifact from 6 to 7
…ntickernel-bom/com.fasterxml.jackson.core-jackson-core-2.18.6 Java: Bump com.fasterxml.jackson.core:jackson-core from 2.18.0 to 2.18.6 in /semantickernel-bom
…sourceforge.pmd-pmd-core-7.22.0 Java: Bump net.sourceforge.pmd:pmd-core from 7.10.0 to 7.22.0
Bumps org.apache.logging.log4j:log4j-core from 2.25.3 to 2.25.4. --- updated-dependencies: - dependency-name: org.apache.logging.log4j:log4j-core dependency-version: 2.25.4 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
…apache.logging.log4j-log4j-core-2.25.4 Java: Bump org.apache.logging.log4j:log4j-core from 2.25.3 to 2.25.4
Bumps [actions/github-script](https://github.com/actions/github-script) from 8 to 9. - [Release notes](https://github.com/actions/github-script/releases) - [Commits](actions/github-script@v8...v9) --- updated-dependencies: - dependency-name: actions/github-script dependency-version: '9' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
…ions/actions/github-script-9 Bump actions/github-script from 8 to 9
Update testcontainers and fix testing Remove unsused test
Allow disabling filter
Bumps [org.postgresql:postgresql](https://github.com/pgjdbc/pgjdbc) from 42.7.10 to 42.7.11. - [Release notes](https://github.com/pgjdbc/pgjdbc/releases) - [Changelog](https://github.com/pgjdbc/pgjdbc/blob/master/CHANGELOG.md) - [Commits](pgjdbc/pgjdbc@REL42.7.10...REL42.7.11) --- updated-dependencies: - dependency-name: org.postgresql:postgresql dependency-version: 42.7.11 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
…/semantickernel-data-postgres/org.postgresql-postgresql-42.7.11 Java: Bump org.postgresql:postgresql from 42.7.10 to 42.7.11 in /data/semantickernel-data-postgres
Bumps [actions/checkout](https://github.com/actions/checkout) from 6 to 7. - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](actions/checkout@v6...v7) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
…ions/actions/checkout-7 Bump actions/checkout from 6 to 7
Bumps [com.fasterxml.jackson.core:jackson-databind](https://github.com/FasterXML/jackson) from 2.21.2 to 2.22.0. - [Commits](https://github.com/FasterXML/jackson/commits) --- updated-dependencies: - dependency-name: com.fasterxml.jackson.core:jackson-databind dependency-version: 2.22.0 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
…ntickernel-bom/com.fasterxml.jackson.core-jackson-databind-2.22.0 Java: Bump com.fasterxml.jackson.core:jackson-databind from 2.21.2 to 2.22.0 in /semantickernel-bom
…nvironments that cannot pull docker images (microsoft#365)
Bumps [org.postgresql:postgresql](https://github.com/pgjdbc/pgjdbc) from 42.7.10 to 42.7.12. - [Release notes](https://github.com/pgjdbc/pgjdbc/releases) - [Changelog](https://github.com/pgjdbc/pgjdbc/blob/master/CHANGELOG.md) - [Commits](pgjdbc/pgjdbc@REL42.7.10...REL42.7.12) --- updated-dependencies: - dependency-name: org.postgresql:postgresql dependency-version: 42.7.12 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [org.postgresql:postgresql](https://github.com/pgjdbc/pgjdbc) from 42.7.11 to 42.7.12. - [Release notes](https://github.com/pgjdbc/pgjdbc/releases) - [Changelog](https://github.com/pgjdbc/pgjdbc/blob/master/CHANGELOG.md) - [Commits](pgjdbc/pgjdbc@REL42.7.11...REL42.7.12) --- updated-dependencies: - dependency-name: org.postgresql:postgresql dependency-version: 42.7.12 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
…/semantickernel-data-postgres/org.postgresql-postgresql-42.7.12 Java: Bump org.postgresql:postgresql from 42.7.11 to 42.7.12 in /data/semantickernel-data-postgres
…/semantickernel-data-jdbc/org.postgresql-postgresql-42.7.12 Java: Bump org.postgresql:postgresql from 42.7.10 to 42.7.12 in /data/semantickernel-data-jdbc
Bumps [com.fasterxml.jackson.core:jackson-core](https://github.com/FasterXML/jackson-core) from 2.22.0 to 2.22.1. - [Commits](FasterXML/jackson-core@jackson-core-2.22.0...jackson-core-2.22.1) --- updated-dependencies: - dependency-name: com.fasterxml.jackson.core:jackson-core dependency-version: 2.22.1 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [com.fasterxml.jackson.core:jackson-databind](https://github.com/FasterXML/jackson) from 2.22.0 to 2.22.1. - [Commits](https://github.com/FasterXML/jackson/commits) --- updated-dependencies: - dependency-name: com.fasterxml.jackson.core:jackson-databind dependency-version: 2.22.1 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
…ntickernel-bom/com.fasterxml.jackson.core-jackson-core-2.22.1 Java: Bump com.fasterxml.jackson.core:jackson-core from 2.22.0 to 2.22.1 in /semantickernel-bom
…ntickernel-bom/com.fasterxml.jackson.core-jackson-databind-2.22.1 Java: Bump com.fasterxml.jackson.core:jackson-databind from 2.22.0 to 2.22.1 in /semantickernel-bom
Bumps [actions/stale](https://github.com/actions/stale) from 10 to 11. - [Release notes](https://github.com/actions/stale/releases) - [Changelog](https://github.com/actions/stale/blob/main/CHANGELOG.md) - [Commits](actions/stale@v10...v11) --- updated-dependencies: - dependency-name: actions/stale dependency-version: '11' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
…ions/actions/stale-11 Bump actions/stale from 10 to 11
…CONSTRUCTOR_THROW SpotBugs (bug-check profile) flagged CT_CONSTRUCTOR_THROW on classes whose constructors throw validation exceptions while being non-final, which the Java CI build treats as an error and fails merge-gatekeeper. Marking these value/service classes final removes the finalizer-attack vector SpotBugs warns about while preserving the existing constructor validation.
After merging upstream/main, the repository version advanced to 1.5.1-SNAPSHOT while the VoyageAI module still pinned the old 1.4.4-RC3-SNAPSHOT parent, which made the semantickernel-bom import unresolvable and broke the reactor build.
The VoyageAIModels request/response DTOs expose their mutable list and array fields directly through getters, setters and one constructor, which SpotBugs (bug-check profile) flags as EI_EXPOSE_REP/EI_EXPOSE_REP2. These are plain Jackson-mapped data holders, so annotate the individual accessors with @SuppressFBWarnings, matching the pattern already used by the other aiservices DTOs (e.g. HuggingFace, OpenAI, Google).
fzowl
commented
Aug 16, 2026
VERDICT:CHANGES_NEEDED The CI-repair objective this round was aimed at is met, and commit hygiene is clean — but there are correctness and convention issues that should be fixed before merge. What's solid
Should fix before merge
Items 1–4 are the ones I'd want addressed; the CI fixes themselves are correct and can stay as-is. |
fzowl
commented
Aug 16, 2026
CI-repair round — merge-gatekeeper statusInvestigated the Root cause is the fork-PR workflow-approval gate, not a code defect. All five upstream workflow runs on the head commit are stuck at
Combined commit status is The actual build is verified green locally on the current head (
The only unrelated local build noise is No code change is warranted for this scoped round (merge-gatekeeper only). The separate review items (blocking I/O, OkHttp version, etc.) are out of scope here and left untouched. |
fzowl
commented
Aug 16, 2026
VERDICT:CHANGES_NEEDED Thanks for this — it's a substantial, well-organized contribution. The diff is cleanly scoped (16 files vs the merge-base with Commit hygiene: clean. No That said, a few items should be addressed before merge: 1. Module missing from 2. HTTP client diverges from project convention (design — please justify or align). 3. Blocking I/O on the subscriber thread (reactive correctness). 4. Reactive contract violation (minor). Minor / optional:
None of these are blockers in spirit — (1) and (3) are the ones I'd want resolved, and (2) is worth a conscious decision from the maintainers. Happy to re-review once addressed. |
karianna
commented
Aug 19, 2026
@johnoliver - Can you review this with a view to future direction of Microsoft Agent Framework. Happy to accept extra functionality in principle. |
What
Adds a VoyageAI integration module (
aiservices/voyageai) providing text embedding, multimodal embedding, contextualized embedding, and reranking services, plus a small reranking abstraction (TextRerankingService,RerankResult) insemantickernel-api.Why this round (CI repair)
The upstream PR (microsoft#345) was red on
merge-gatekeeper, which was blocked by theJava CIbuild failing under thebug-checkprofile. Root causes and fixes:CT_CONSTRUCTOR_THROW:RerankResultand the four VoyageAI service classes plusVoyageAIClientthrow validation exceptions from non-final constructors (finalizer-attack vector). Marked these classesfinal(behavior unchanged; validation preserved). This was the failure that stopped the CI build atsemantickernel-api.EI_EXPOSE_REP/EI_EXPOSE_REP2: theVoyageAIModelsJackson DTO accessors expose mutable list/array fields. Annotated the individual getters/setters/constructor with@SuppressFBWarnings, matching the existing pattern in the HuggingFace/OpenAI/Google DTOs. (This surfaced only after the first fix let the build reach the VoyageAI module.)upstream/main(which advanced the repo to1.5.1-SNAPSHOT); the VoyageAI module still pinned1.4.4-RC3-SNAPSHOT, which made thesemantickernel-bomimport unresolvable. Bumped the module's parent version to match.Validation
Full reactor build with the CI command
./mvnw -Pbug-check -DskipTests -Pcompile-jdk17 clean installpasses thesemantickernel-apiandaiservices/voyageaimodules (SpotBugs clean). The VoyageAI unit tests pass (33 run; 6 live-API integration tests skipped without credentials).Diff scope vs
upstream/mainis limited to the VoyageAI module, the two new reranking API files,PACKAGES.md, and the rootpom.xmlmodule entry.