← All tasks
javaapache/shiro #1352Not a task: already works

[Regression] commons-configuration2 is pulled in as a required dependency

envgap__apache__shiro-1352

01 / FAILURE SIGNATURE

As reported upstream

No identifying execution failure has been captured.
Not a benchmark task.
  • The project already builds and runs before the fix, so there is nothing to repair.

02 / ENVIRONMENT RECIPE

Base commit
9507f2476d6875f1ab07df0fc0155a062c85fb2c
Manifest
core/pom.xml
Reproduce
Awaiting issue-specific recipe
Run under trace
Awaiting a meaningful runtime command

03 / ORIGINAL ISSUE TEXT

apache/shiro #1352 · read the original issue
### Search before asking



- [X] I had searched in the [issues](https://github.com/apache/shiro/issues?q=is%3Aissue) and found no similar issues.





### Environment



This is a dependency of shiro-core, so it's for every environment.



### Shiro version



2.0.0



### Regression from:

1.13.0



### What was the actual outcome?



Observe `commons-configuration2` in the output below:

```papegaaij@papegaaij:~$ mvn -f ~/.m2/repository/org/apache/shiro/shiro-core/2.0.0/shiro-core-2.0.0.pom dependency:tree -Dscope=compile

[INFO] Scanning for projects...

[INFO] 

[INFO] --------------------< org.apache.shiro:shiro-core >---------------------

[INFO] Building Apache Shiro :: Core 2.0.0

[INFO]   from shiro-core-2.0.0.pom

[INFO] -------------------------------[ bundle ]-------------------------------

[INFO] 

[INFO] --- dependency:3.6.1:tree (default-cli) @ shiro-core ---

[INFO] org.apache.shiro:shiro-core:bundle:2.0.0

[INFO] +- org.apache.shiro:shiro-lang:jar:2.0.0:compile

[INFO] |  \- org.slf4j:slf4j-api:jar:2.0.12:compile

[INFO] +- org.apache.shiro:shiro-cache:jar:2.0.0:compile

[INFO] +- org.apache.shiro:shiro-crypto-hash:jar:2.0.0:compile

[INFO] |  +- org.apache.shiro:shiro-crypto-core:jar:2.0.0:compile

[INFO] |  \- org.bouncycastle:bcprov-jdk18on:jar:1.77:compile

[INFO] +- org.apache.shiro:shiro-crypto-cipher:jar:2.0.0:compile

[INFO] +- org.apache.shiro:shiro-config-core:jar:2.0.0:compile

[INFO] +- org.apache.shiro:shiro-config-ogdl:jar:2.0.0:compile

[INFO] |  \- commons-beanutils:commons-beanutils:jar:1.9.4:compile

[INFO] |     \- commons-collections:commons-collections:jar:3.2.2:compile

[INFO] +- org.apache.shiro:shiro-event:jar:2.0.0:compile

[INFO] +- jakarta.annotation:jakarta.annotation-api:jar:1.3.5:provided

[INFO] \- org.apache.commons:commons-configuration2:jar:2.9.0:compile

[INFO]    +- org.apache.commons:commons-lang3:jar:3.12.0:compile

[INFO]    \- org.apache.commons:commons-text:jar:1.10.0:compile

[INFO] ------------------------------------------------------------------------

[INFO] BUILD SUCCESS

[INFO] ------------------------------------------------------------------------

[INFO] Total time:  0.969 s

[INFO] Finished at: 2024-03-11T21:48:45+01:00

[INFO] ------------------------------------------------------------------------

```



### What was the expected outcome?



Commons-configuration2 should be made optional. The code here already supports it being optional:

https://github.com/apache/shiro/blob/36cad481dd1f58f7f0263981d7f4a61dd39dbd8c/config/ogdl/src/main/java/org/apache/shiro/config/ogdl/ReflectionBuilder.java#L782-L789





### How to reproduce



see above



### Debug logs



_No response_
Continue on GitHub ↗

04 / LABELS

Labels from the report text only; not yet run

No supported category has been assigned.

Label rules and the text that matched
[]