Skip to content

Guardrails / maven

Maven dependencies are versioned ​

maven/dependencies-versioned@v1

Every dependency declared by the POM and its modules gets its version from the checkout: from the entry itself, from <dependencyManagement>, from an imported BOM or from a property. A parent POM published elsewhere isn't read, so a version managed only by that parent shows as unresolved.

Idmaven/dependencies-versioned
Versionv1
Categorymaven
Default severitywarning
Interpreterpython3
Timeout30 seconds
Violations tolerated0
Collectsmaven

Collectors ​

This guardrail doesn't gather anything itself. It relies on the collectors below, which the CLI runs once per build before any check, and reads what they found from GUARDRAIL_FACTS. If a collector collects nothing, this guardrail is skipped, not failed.

CollectorGathersInputs it is given
mavenThe Maven build in the project directory: the root pom.xml coordinates, its modules, its properties and every dependency it and its modules declare, with the versions its imported BOMs supply.projectDir

The inputs above are this guardrail's own inputs, passed straight through to the collector. Setting one in buildnote.json changes what is collected, and two guardrails configured the same way share a single collection.

Configuration ​

json
{
  "guardrails": {
      "failOn": "error",
      "checks": [
          {
              "use": "maven/dependencies-versioned@v1",
              "severity": "warning",
              "with": {
                  "projectDir": "."
              },
              "exemptions": []
          }
      ]
  }
}

Inputs ​

InputDescriptionDefaultEnvironment variable
projectDirDirectory holding the project, relative to the directory the CLI runs in..GUARDRAIL_INPUT_PROJECTDIR

How to fix ​

Set the version where the build already manages versions. For a dependency several modules share, that is <dependencyManagement> in the root POM:

xml
<dependencyManagement>
  <dependencies>
    <dependency>
      <groupId>org.junit</groupId>
      <artifactId>junit-bom</artifactId>
      <version>5.10.2</version>
      <type>pom</type>
      <scope>import</scope>
    </dependency>
  </dependencies>
</dependencyManagement>

If nothing in the checkout sets a dependency's version, either something outside the checkout sets it, or nothing does and the build fails to resolve it. Either way, this commit doesn't decide the code that gets compiled in, so reading the diff doesn't tell you what changed.

The usual outside source is a <parent> published elsewhere, most often spring-boot-starter-parent. That build resolves fine; the dependency only shows as unversioned here because the parent isn't in the checkout to be read. That is why this guardrail is a warning and not a gate.

More in maven ​

  • maven/coordinates-declared. The root POM names the group, artifact and version it publishes, either declaring them itself or inheriting the group and version from a <parent>.
  • maven/no-snapshot-dependencies. No dependency declared by the POM and its modules, and no BOM they import, uses a -SNAPSHOT version.
  • maven/pom-parses. The root pom.xml is well-formed XML, so the build it describes can be read at all.

All 4 maven guardrails

Buildnote Limited
Registered in England and Wales, Reg: 16140412