← All tasks
javaapache/maven #8076Not a task: not reproduced

[MNG-6965] Extensions suddenly have org.codehaus.plexus:plexus-utils:jar:1.1 on their classpath

envgap__apache__maven-8076

Original GitHub issue ↗Opened 2020-07-21

01 / FAILURE SIGNATURE

As reported upstream

[DEBUG] Dependency collection stats: {ConflictMarker.analyzeTime=952800, ConflictMarker.markTime=586900, ConflictMarker.nodeCount=1, ConflictIdSorter.graphTime=549200, ConflictIdSorter.topsortTime=586700, ConflictIdSorter.conflictIdCount=1, ConflictIdSorter.conflictIdCycleCount=0, ConflictResolver.totalTime=3313100, ConflictResolver.conflictItemCount=1, DefaultDependencyCollector.collectTime=66890900, DefaultDependencyCollector.transformTime=8523500}
Not a benchmark task.
  • No curated issue-specific recipe or verified environment fix is available.

02 / ENVIRONMENT RECIPE

Base commit
Not freshly verified
Manifest
pom.xml
Reproduce
Awaiting issue-specific recipe
Run under trace
Awaiting a meaningful runtime command

03 / ORIGINAL ISSUE TEXT

apache/maven #8076 · read the original issue
**[Mark Nolan](https://issues.apache.org/jira/secure/ViewProfile.jspa?name=manolan)** opened **[MNG-6965](https://issues.apache.org/jira/browse/MNG-6965?redirect=false)** and commented

A simple minimal archetype pom following the manual pages downloads plexus-utils 1.1, even though it is not (apparently) declared anywhere. This version is banned at my organization (edited to add: due to vulnerabilities), meaning such a pom always fails.

 

```xml
<project xmlns="http://maven.apache.org/POM/4.0.0"
  xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
  xsi:schemaLocation="http://maven.apache.org/POM/4.0.0
  http://maven.apache.org/xsd/maven-4.0.0.xsd">
<modelVersion>4.0.0</modelVersion>
<groupId>test</groupId>
<artifactId>test</artifactId>
<version>0.0.1-SNAPSHOT</version>
<packaging>maven-archetype</packaging>
<name>test</name>

<build>
  <extensions> 
    <extension>
      <groupId>org.apache.maven.archetype</groupId>
      <artifactId>archetype-packaging</artifactId>
      <version>3.1.2</version>
    </extension>
  </extensions>

  <pluginManagement>
    <plugins>
      <plugin>
        <groupId>org.apache.maven.plugins</groupId>
        <artifactId>maven-archetype-plugin</artifactId>
        <version>3.1.2</version>
      </plugin>
    </plugins>
  </pluginManagement>
</build>
</project>
```

Running any goal, such as mvn -X clean, produces the following before the goal is executed:

```
[DEBUG] Dependency collection stats: {ConflictMarker.analyzeTime=952800, ConflictMarker.markTime=586900, ConflictMarker.nodeCount=1, ConflictIdSorter.graphTime=549200, ConflictIdSorter.topsortTime=586700, ConflictIdSorter.conflictIdCount=1, ConflictIdSorter.conflictIdCycleCount=0, ConflictResolver.totalTime=3313100, ConflictResolver.conflictItemCount=1, DefaultDependencyCollector.collectTime=66890900, DefaultDependencyCollector.transformTime=8523500}
[DEBUG] org.apache.maven.archetype:archetype-packaging:jar:3.1.2:
[DEBUG]    org.codehaus.plexus:plexus-utils:jar:1.1:runtime
```

 

As far as I can see, there is no declared dependency on plexus-utils:1.1.

 


---

**Affects:** 3.0-alpha-3, 3.0, 3.6.0, 3.6.3

**Attachments:**
- [pom.xml](https://issues.apache.org/jira/secure/attachment/13008044/pom.xml) (_1.36 kB_)

**Issue Links:**
- [MNG-7115](https://issues.apache.org/jira/browse/MNG-7115) MavenITmng5771CoreExtensionsTest fails on maven-3.8.x branch
 (_**"fixes"**_)
- [MSKINS-220](https://issues.apache.org/jira/browse/MSKINS-220) cannot build with Maven 3.9
 (_**"causes"**_)
- [MNG-7097](https://issues.apache.org/jira/browse/MNG-7097) Plugin Dependency Resolution: don't download Maven-provided artifacts

- [MNG-2892](https://issues.apache.org/jira/browse/MNG-2892) Use shade to hide the use of plexus-utils internally so that plugins can use their own version
 (_**"is broken by"**_)
- [MNG-3819](https://issues.apache.org/jira/browse/MNG-3819) [regression] Plugins that don't declare dependency on plexus-utils no longer get plexus-utils:1.1
 (_**"supercedes
Continue on GitHub ↗

04 / LABELS

Labels from the report text only; not yet run

No supported category has been assigned.

Label rules and the text that matched
[]

Issue-specific recipe and runtime smoke command require review against the complete issue and repository.

Legacy reproduction is generic install-only; match the actual issue failure before admission.