The POM parses
maven/pom-parses@v1
The root pom.xml is well-formed XML, so the build it describes can be read at all.
| Id | maven/pom-parses |
| Version | v1 |
| Category | maven |
| Default severity | error |
| Interpreter | python3 |
| Timeout | 30 seconds |
| Violations tolerated | 0 |
| Collects | maven |
Collectors
This guardrail doesn't gather anything itself. It relies on the collectors below, which the CLI runs once per build before any check, and reads what they found from GUARDRAIL_FACTS. If a collector collects nothing, this guardrail is skipped, not failed.
| Collector | Gathers | Inputs it is given |
|---|---|---|
maven | The Maven build in the project directory: the root pom.xml coordinates, its modules, its properties and every dependency it and its modules declare, with the versions its imported BOMs supply. | projectDir |
The inputs above are this guardrail's own inputs, passed straight through to the collector. Setting one in buildnote.json changes what is collected, and two guardrails configured the same way share a single collection.
Configuration
{
"guardrails": {
"failOn": "error",
"checks": [
{
"use": "maven/pom-parses@v1",
"severity": "error",
"with": {
"projectDir": "."
},
"exemptions": []
}
]
}
}Inputs
| Input | Description | Default | Environment variable |
|---|---|---|---|
projectDir | Directory holding the project, relative to the directory the CLI runs in. | . | GUARDRAIL_INPUT_PROJECTDIR |
How to fix
Fix the XML. Maven itself will tell you where it stops parsing:
mvn -q validateMaven refuses to build a POM it can't parse, and tools that read the build get nothing from it. The coordinates, properties, modules and dependency list all fall back to their defaults, so every other Maven guardrail passes on a project it never actually saw.
More in maven
maven/coordinates-declared. The root POM names the group, artifact and version it publishes, either declaring them itself or inheriting the group and version from a<parent>.maven/dependencies-versioned. Every dependency declared by the POM and its modules gets its version from the checkout: from the entry itself, from<dependencyManagement>, from an imported BOM or from a property. A parent POM published elsewhere isn't read, so a version managed only by that parent shows as unresolved.maven/no-snapshot-dependencies. No dependency declared by the POM and its modules, and no BOM they import, uses a-SNAPSHOTversion.