Skip to content
BETAGuardrails are in beta. The library, the configuration format and the CLI command can still change.

Guardrails / maven

Maven coordinates are declared

maven/coordinates-declared@v1

The root POM names the group, the artifact and the version it publishes, declaring them itself or inheriting the group and the version from a <parent>.

Idmaven/coordinates-declared
Versionv1
Categorymaven
Default severitywarning
Interpreterpython3
Timeout30 seconds
Violations tolerated0
Collectsmaven

Collectors

This guardrail gathers nothing itself. It depends on the collectors below, which the CLI runs once per build before any check, and reads what they found out of GUARDRAIL_FACTS. A collector that collects nothing skips this guardrail rather than failing it.

CollectorGathersInputs it is given
mavenThe Maven build in the project directory: the root pom.xml coordinates, its modules, its properties and every dependency it and its modules declare, with the versions its imported BOMs supply.projectDir

The inputs above are this guardrail's own, passed straight through. Configuring one in buildnote.json changes what is collected, and two guardrails configured the same way share the one collection.

Configuration

json
{
  "guardrails": {
      "failOn": "error",
      "comment": true,
      "checks": [
          {
              "use": "maven/coordinates-declared@v1",
              "severity": "warning",
              "with": {
                  "projectDir": "."
              },
              "exemptions": []
          }
      ]
  }
}

Inputs

InputDescriptionDefaultEnvironment variable
projectDirDirectory holding the project, relative to the directory the CLI runs in..GUARDRAIL_INPUT_PROJECTDIR

How to fix

Name the artifact in the POM, or inherit the group and the version from the <parent> that already declares them:

xml
<groupId>io.acme</groupId>
<artifactId>widget</artifactId>
<version>1.4.0</version>

Without all three the build publishes something nobody can name: a consumer has no coordinates to depend on, and a jar found in a repository or in a running service cannot be traced back to the commit that produced it.

More in maven

  • maven/dependencies-versioned. Every dependency the POM and its modules declare takes a version from the checkout, whether from the entry itself, from <dependencyManagement>, from an imported BOM or from a property. A parent POM published elsewhere is not read here, so a version only that parent manages reads as unresolved.
  • maven/no-snapshot-dependencies. No dependency the POM and its modules declare, and no BOM they import, is at a -SNAPSHOT version.
  • maven/pom-parses. The root pom.xml is well formed XML, so the build it describes can be read at all.

All 4 maven guardrails

Buildnote Limited
Registered in England and Wales, Reg: 16140412