maven
4 guardrails, all at version v1.
| Guardrail | Default severity | What it checks |
|---|---|---|
maven/coordinates-declared | warning | The root POM names the group, artifact and version it publishes, either declaring them itself or inheriting the group and version from a <parent>. |
maven/dependencies-versioned | warning | Every dependency declared by the POM and its modules gets its version from the checkout: from the entry itself, from <dependencyManagement>, from an imported BOM or from a property. A parent POM published elsewhere isn't read, so a version managed only by that parent shows as unresolved. |
maven/no-snapshot-dependencies | error | No dependency declared by the POM and its modules, and no BOM they import, uses a -SNAPSHOT version. |
maven/pom-parses | error | The root pom.xml is well-formed XML, so the build it describes can be read at all. |
Shared inputs
Every maven guardrail declares these inputs. Individual guardrails can add their own.
| Input | Description | Default |
|---|---|---|
projectDir | Directory holding the project, relative to the directory the CLI runs in. | . |
Shared collectors
Every maven guardrail receives the facts these collectors gather. Individual guardrails can ask for more collectors of their own.
| Collector | Gathers |
|---|---|
maven | The Maven build in the project directory: the root pom.xml coordinates, its modules, its properties and every dependency it and its modules declare, with the versions its imported BOMs supply. |
You configure every guardrail in this category the same way, in the guardrails.checks array of buildnote.json. Configuring guardrails lists every option, and Guardrails lets you search the whole library.