Skip to content

Guardrails / maven

No snapshot dependencies ​

maven/no-snapshot-dependencies@v1

No dependency declared by the POM and its modules, and no BOM they import, uses a -SNAPSHOT version.

Idmaven/no-snapshot-dependencies
Versionv1
Categorymaven
Default severityerror
Interpreterpython3
Timeout30 seconds
Violations tolerated0
Collectsmaven

Collectors ​

This guardrail doesn't gather anything itself. It relies on the collectors below, which the CLI runs once per build before any check, and reads what they found from GUARDRAIL_FACTS. If a collector collects nothing, this guardrail is skipped, not failed.

CollectorGathersInputs it is given
mavenThe Maven build in the project directory: the root pom.xml coordinates, its modules, its properties and every dependency it and its modules declare, with the versions its imported BOMs supply.projectDir

The inputs above are this guardrail's own inputs, passed straight through to the collector. Setting one in buildnote.json changes what is collected, and two guardrails configured the same way share a single collection.

Configuration ​

json
{
  "guardrails": {
      "failOn": "error",
      "checks": [
          {
              "use": "maven/no-snapshot-dependencies@v1",
              "severity": "error",
              "with": {
                  "projectDir": "."
              },
              "exemptions": []
          }
      ]
  }
}

Inputs ​

InputDescriptionDefaultEnvironment variable
projectDirDirectory holding the project, relative to the directory the CLI runs in..GUARDRAIL_INPUT_PROJECTDIR

How to fix ​

Depend on a released version. If the library doesn't have one yet, cut a release upstream:

xml
<dependency>
  <groupId>com.company</groupId>
  <artifactId>queue</artifactId>
  <version>1.4.0</version>
</dependency>

A snapshot is republished under the same coordinates, so whatever 1.4.0-SNAPSHOT resolved to on the day the build shipped is gone, and you can't rebuild this commit into the artifact that was released from it. A snapshot that mvn install put in a local repository is worse: it exists on one machine and nowhere a rebuild can reach.

More in maven ​

  • maven/coordinates-declared. The root POM names the group, artifact and version it publishes, either declaring them itself or inheriting the group and version from a <parent>.
  • maven/dependencies-versioned. Every dependency declared by the POM and its modules gets its version from the checkout: from the entry itself, from <dependencyManagement>, from an imported BOM or from a property. A parent POM published elsewhere isn't read, so a version managed only by that parent shows as unresolved.
  • maven/pom-parses. The root pom.xml is well-formed XML, so the build it describes can be read at all.

All 4 maven guardrails

Buildnote Limited
Registered in England and Wales, Reg: 16140412