No snapshot dependencies
maven/no-snapshot-dependencies@v1
No dependency declared by the POM and its modules, and no BOM they import, uses a -SNAPSHOT version.
| Id | maven/no-snapshot-dependencies |
| Version | v1 |
| Category | maven |
| Default severity | error |
| Interpreter | python3 |
| Timeout | 30 seconds |
| Violations tolerated | 0 |
| Collects | maven |
Collectors
This guardrail doesn't gather anything itself. It relies on the collectors below, which the CLI runs once per build before any check, and reads what they found from GUARDRAIL_FACTS. If a collector collects nothing, this guardrail is skipped, not failed.
| Collector | Gathers | Inputs it is given |
|---|---|---|
maven | The Maven build in the project directory: the root pom.xml coordinates, its modules, its properties and every dependency it and its modules declare, with the versions its imported BOMs supply. | projectDir |
The inputs above are this guardrail's own inputs, passed straight through to the collector. Setting one in buildnote.json changes what is collected, and two guardrails configured the same way share a single collection.
Configuration
{
"guardrails": {
"failOn": "error",
"checks": [
{
"use": "maven/no-snapshot-dependencies@v1",
"severity": "error",
"with": {
"projectDir": "."
},
"exemptions": []
}
]
}
}Inputs
| Input | Description | Default | Environment variable |
|---|---|---|---|
projectDir | Directory holding the project, relative to the directory the CLI runs in. | . | GUARDRAIL_INPUT_PROJECTDIR |
How to fix
Depend on a released version. If the library doesn't have one yet, cut a release upstream:
<dependency>
<groupId>com.company</groupId>
<artifactId>queue</artifactId>
<version>1.4.0</version>
</dependency>A snapshot is republished under the same coordinates, so whatever 1.4.0-SNAPSHOT resolved to on the day the build shipped is gone, and you can't rebuild this commit into the artifact that was released from it. A snapshot that mvn install put in a local repository is worse: it exists on one machine and nowhere a rebuild can reach.
More in maven
maven/coordinates-declared. The root POM names the group, artifact and version it publishes, either declaring them itself or inheriting the group and version from a<parent>.maven/dependencies-versioned. Every dependency declared by the POM and its modules gets its version from the checkout: from the entry itself, from<dependencyManagement>, from an imported BOM or from a property. A parent POM published elsewhere isn't read, so a version managed only by that parent shows as unresolved.maven/pom-parses. The rootpom.xmlis well-formed XML, so the build it describes can be read at all.