Maven Central Replication / Broken BOM Deps
envgap__micronaut-projects__micronaut-core-785
Original GitHub issue ↗Opened 2018-10-25
01 / FAILURE SIGNATURE
As reported upstream
It would appear that some of the artifacts that are specified in the maven BOM are not replicated out to jcenter/maven/etc. I copied all the BOM deps to a POM file, removed their version, and included the BOM. Then there were several errors of items that are included but not plublished and appear to be build/dev/etc that should be cleaned up. I have also included at the bottom a list of conflicting dependency versions that should be addressed and potentially pinned in the BOM file to ensure version interop long term. Most of these conflicts appear to be minor version, however there is a few that are major version conflicts.
Not a benchmark task.
- No curated issue-specific recipe or verified environment fix is available.
02 / ENVIRONMENT RECIPE
- Base commit
Not freshly verified- Manifest
pom.xml- Reproduce
Awaiting issue-specific recipe- Run under trace
Awaiting a meaningful runtime command
03 / ORIGINAL ISSUE TEXT
micronaut-projects/micronaut-core #785 · read the original issue
It would appear that some of the artifacts that are specified in the maven BOM are not replicated out to jcenter/maven/etc. I copied all the BOM deps to a POM file, removed their version, and included the BOM. Then there were several errors of items that are included but not plublished and appear to be build/dev/etc that should be cleaned up. I have also included at the bottom a list of conflicting dependency versions that should be addressed and potentially pinned in the BOM file to ensure version interop long term. Most of these conflicts appear to be minor version, however there is a few that are major version conflicts.
Using the Pom below and running `mvn dependency:resolve` or other maven target the following is produced.
```
Could not resolve dependencies for project io.micronaut:micronaut-test-pom:jar:1.0.0:
The following artifacts could not be resolved: io.micronaut:micronaut-build-projects:jar:1.0.0, io.micronaut:micronaut-test-utils:jar:1.0.0, io.micronaut:micronaut-asciidoc-config-props:jar:1.0.0, io.netty:netty-tcnative:jar:${os.detected.classifier}:2.0.15.Final, com.oracle.substratevm:svm:jar:GraalVM-1.0.0-rc7: Failure to find io.micronaut:micronaut-build-projects:jar:1.0.0 in [clone maven central] was cached in the local repository, resolution will not be reattempted until the update interval of artifactory has elapsed or updates are forced
```
Looking at jcenter http://jcenter.bintray.com/io/micronaut/ and maven central these are clearly not published.
Pom used
```xml
<?xml version="1.0" encoding="UTF-8"?>
<project xmlns="http://maven.apache.org/POM/4.0.0"
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 http://maven.apache.org/maven-v4_0_0.xsd">
<modelVersion>4.0.0</modelVersion>
<artifactId>micronaut-test-pom</artifactId>
<packaging>jar</packaging>
<groupId>io.micronaut</groupId>
<version>1.0.0</version>
<name>Micronaut Test POM</name>
<description>Test POM for micronaut-bom</description>
<dependencyManagement>
<dependencies>
<dependency>
<groupId>io.micronaut</groupId>
<artifactId>micronaut-bom</artifactId>
<version>1.0.0</version>
<type>pom</type>
<scope>import</scope>
</dependency>
</dependencies>
</dependencyManagement>
<dependencies>
<!-- MICRONAUT DEPS FROM BOM WITH VERSION REMOVED -->
<dependency>
<groupId>io.micronaut.profiles</groupId>
<artifactId>function</artifactId>
</dependency>
<dependency>
<groupId>io.micronaut.profiles</groupId>
<artifactId>cli</artifactId>
</dependency>
<dependency>
<groupId>io.micronaut.profiles</groupId>
<artifactId>service</artifactId>
</dependency>
<depen04 / LABELS
Labels from the report text only; not yet run
conflictsecurityLabel rules and the text that matched
[
{
"category": "conflict",
"rule": "signature.incompatible_declared_requirements",
"source": "failure_signature",
"excerpt": "It would appear that some of the artifacts that are specified in the maven BOM are not replicated out to jcenter/maven/etc. I copied all the BOM deps to a POM file, removed their version, and included the BOM. Then there were several errors of items that are included but not plublished and appear to be build/dev/etc that should be cleaned up. I have also included at the bottom a list of conflicting dependency versions that should be addressed and potentially pinned in the BOM file to ensure version interop long term. Most of these conflicts appear to be minor version, however there is a few that are major version conflicts."
},
{
"category": "security",
"rule": "issue.security_keyword",
"source": "issue_body",
"excerpt": "d out to jcenter/maven/etc. I copied all the BOM deps to a POM file, removed their version, and included the BOM. Then there were several errors of items that are included but"
}
]Issue-specific recipe and runtime smoke command require review against the complete issue and repository.
Legacy reproduction is generic install-only; match the actual issue failure before admission.