Skip to content

Guardrails / maven

Maven coordinates are declared ​

maven/coordinates-declared@v1

The root POM names the group, artifact and version it publishes, either declaring them itself or inheriting the group and version from a <parent>.

Idmaven/coordinates-declared
Versionv1
Categorymaven
Default severitywarning
Interpreterpython3
Timeout30 seconds
Violations tolerated0
Collectsmaven

Collectors ​

This guardrail doesn't gather anything itself. It relies on the collectors below, which the CLI runs once per build before any check, and reads what they found from GUARDRAIL_FACTS. If a collector collects nothing, this guardrail is skipped, not failed.

CollectorGathersInputs it is given
mavenThe Maven build in the project directory: the root pom.xml coordinates, its modules, its properties and every dependency it and its modules declare, with the versions its imported BOMs supply.projectDir

The inputs above are this guardrail's own inputs, passed straight through to the collector. Setting one in buildnote.json changes what is collected, and two guardrails configured the same way share a single collection.

Configuration ​

json
{
  "guardrails": {
      "failOn": "error",
      "checks": [
          {
              "use": "maven/coordinates-declared@v1",
              "severity": "warning",
              "with": {
                  "projectDir": "."
              },
              "exemptions": []
          }
      ]
  }
}

Inputs ​

InputDescriptionDefaultEnvironment variable
projectDirDirectory holding the project, relative to the directory the CLI runs in..GUARDRAIL_INPUT_PROJECTDIR

How to fix ​

Name the artifact in the POM, or inherit the group and version from the <parent> that already declares them:

xml
<groupId>io.company</groupId>
<artifactId>widget</artifactId>
<version>1.4.0</version>

Without all three, the build publishes something nobody can name. Consumers have no coordinates to depend on, and a jar found in a repository or a running service can't be traced back to the commit that produced it.

More in maven ​

  • maven/dependencies-versioned. Every dependency declared by the POM and its modules gets its version from the checkout: from the entry itself, from <dependencyManagement>, from an imported BOM or from a property. A parent POM published elsewhere isn't read, so a version managed only by that parent shows as unresolved.
  • maven/no-snapshot-dependencies. No dependency declared by the POM and its modules, and no BOM they import, uses a -SNAPSHOT version.
  • maven/pom-parses. The root pom.xml is well-formed XML, so the build it describes can be read at all.

All 4 maven guardrails

Buildnote Limited
Registered in England and Wales, Reg: 16140412