Maven dependencies are versioned
maven/dependencies-versioned@v1
Every dependency declared by the POM and its modules gets its version from the checkout: from the entry itself, from <dependencyManagement>, from an imported BOM or from a property. A parent POM published elsewhere isn't read, so a version managed only by that parent shows as unresolved.
| Id | maven/dependencies-versioned |
| Version | v1 |
| Category | maven |
| Default severity | warning |
| Interpreter | python3 |
| Timeout | 30 seconds |
| Violations tolerated | 0 |
| Collects | maven |
Collectors
This guardrail doesn't gather anything itself. It relies on the collectors below, which the CLI runs once per build before any check, and reads what they found from GUARDRAIL_FACTS. If a collector collects nothing, this guardrail is skipped, not failed.
| Collector | Gathers | Inputs it is given |
|---|---|---|
maven | The Maven build in the project directory: the root pom.xml coordinates, its modules, its properties and every dependency it and its modules declare, with the versions its imported BOMs supply. | projectDir |
The inputs above are this guardrail's own inputs, passed straight through to the collector. Setting one in buildnote.json changes what is collected, and two guardrails configured the same way share a single collection.
Configuration
{
"guardrails": {
"failOn": "error",
"checks": [
{
"use": "maven/dependencies-versioned@v1",
"severity": "warning",
"with": {
"projectDir": "."
},
"exemptions": []
}
]
}
}Inputs
| Input | Description | Default | Environment variable |
|---|---|---|---|
projectDir | Directory holding the project, relative to the directory the CLI runs in. | . | GUARDRAIL_INPUT_PROJECTDIR |
How to fix
Set the version where the build already manages versions. For a dependency several modules share, that is <dependencyManagement> in the root POM:
<dependencyManagement>
<dependencies>
<dependency>
<groupId>org.junit</groupId>
<artifactId>junit-bom</artifactId>
<version>5.10.2</version>
<type>pom</type>
<scope>import</scope>
</dependency>
</dependencies>
</dependencyManagement>If nothing in the checkout sets a dependency's version, either something outside the checkout sets it, or nothing does and the build fails to resolve it. Either way, this commit doesn't decide the code that gets compiled in, so reading the diff doesn't tell you what changed.
The usual outside source is a <parent> published elsewhere, most often spring-boot-starter-parent. That build resolves fine; the dependency only shows as unversioned here because the parent isn't in the checkout to be read. That is why this guardrail is a warning and not a gate.
More in maven
maven/coordinates-declared. The root POM names the group, artifact and version it publishes, either declaring them itself or inheriting the group and version from a<parent>.maven/no-snapshot-dependencies. No dependency declared by the POM and its modules, and no BOM they import, uses a-SNAPSHOTversion.maven/pom-parses. The rootpom.xmlis well-formed XML, so the build it describes can be read at all.