← All tasks
javaapache/maven #6673Not a task: not reproduced

[MNG-5255] Dependency with 'provided' scope has its transitive dependency included in final artifact

envgap__apache__maven-6673

Original GitHub issue ↗Opened 2012-02-28

01 / FAILURE SIGNATURE

As reported upstream

|  +- (commons-logging:commons-logging:jar:1.1:compile - omitted for conflict with 1.0.4)
Not a benchmark task.
  • No curated issue-specific recipe or verified environment fix is available.

02 / ENVIRONMENT RECIPE

Base commit
Not freshly verified
Manifest
pom.xml
Reproduce
Awaiting issue-specific recipe
Run under trace
Awaiting a meaningful runtime command

03 / ORIGINAL ISSUE TEXT

apache/maven #6673 · read the original issue
**[Bart Skondin](https://issues.apache.org/jira/secure/ViewProfile.jspa?name=groovin101)** opened **[MNG-5255](https://issues.apache.org/jira/browse/MNG-5255?redirect=false)** and commented

Expected: A dependency declared with a scope of 'provided', along with any transitive dependencies, should not be included in the final artifact.

Actual: I have a dependency, jsp-api, declared with 'provided' scope. This dependency has a dependency of its own, servlet-api. The servlet-api.jar is being included in the web-inf/lib folder of the resultant war file.

Background: We recently upgraded from Maven 2.2.1 to Maven 3.0.4. The problem was not witnessed until after the upgrade.

Steps to Reproduce: Run mvn install, then have a look at the web-inf/lib folder. Notice that the servlet-api.jar has been included.

Additional Info: It seems that I can only reproduce this behavior when declaring a specific dependency in my pom, spring-ldap. Here is the dependency tree for the given pared-down project (attached):

--- maven-dependency-plugin:2.1:tree (default-cli) @ provided-scope-not-working ---
com.bug.example:provided-scope-not-working:war:0.0.1-SNAPSHOT
+- javax.servlet:jsp-api:jar:2.0:provided
|  \- javax.servlet:servlet-api:jar:2.4:provided
\- org.springframework.ldap:spring-ldap:jar:1.2.1:compile
+- commons-logging:commons-logging:jar:1.0.4:compile
+- commons-lang:commons-lang:jar:2.1:compile
+- org.springframework:spring-beans:jar:2.0.6:compile
|  +- (commons-logging:commons-logging:jar:1.1:compile - omitted for conflict with 1.0.4)
|  \- (org.springframework:spring-core:jar:2.0.6:compile - omitted for duplicate)
\- org.springframework:spring-core:jar:2.0.6:compile
\- (commons-logging:commons-logging:jar:1.1:compile - omitted for conflict with 1.0.4)


---

**Affects:** 3.0.4

**Attachments:**
- [provided-scope-not-working.zip](https://issues.apache.org/jira/secure/attachment/12713270/provided-scope-not-working.zip) (_1.17 kB_)
- [provided-scope-not-working-jar-only.tgz2](https://issues.apache.org/jira/secure/attachment/12713333/provided-scope-not-working-jar-only.tgz2) (_966 bytes_)
- [provided-scope-not-working-shaded.tgz2](https://issues.apache.org/jira/secure/attachment/12713411/provided-scope-not-working-shaded.tgz2) (_1.14 kB_)

**Issue Links:**
- [MNG-5273](https://issues.apache.org/jira/browse/MNG-5273) Transitive dependencies with scope provided ending up in the final artifact
 (_**"is duplicated by"**_)
- [MWAR-111](https://issues.apache.org/jira/browse/MWAR-111) Transitive dependencies of optional dependencies are included in WEB-INF/lib


13 votes, 14 watchers
Continue on GitHub ↗

04 / LABELS

Labels from the report text only; not yet run

conflict
Label rules and the text that matched
[
  {
    "category": "conflict",
    "rule": "signature.incompatible_declared_requirements",
    "source": "failure_signature",
    "excerpt": "|  +- (commons-logging:commons-logging:jar:1.1:compile - omitted for conflict with 1.0.4)"
  }
]

Issue-specific recipe and runtime smoke command require review against the complete issue and repository.

Legacy reproduction is generic install-only; match the actual issue failure before admission.