dependabot[bot] opened a new pull request, #27086: URL: https://github.com/apache/camel/pull/27086
Bumps [eu.maveniverse.maven.plugins:pilot-plugin](https://github.com/maveniverse/pilot) from 0.4.0 to 0.5.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/maveniverse/pilot/releases">eu.maveniverse.maven.plugins:pilot-plugin's releases</a>.</em></p> <blockquote> <h2>Pilot 0.5.0</h2> <h2>🌟 Overview</h2> <p>Pilot 0.5.0 expands the accuracy and breadth of dependency classification across several fronts. Previous releases focused on getting the core detection right for standard Java projects; this release pushes into harder cases — polyglot builds, native images, framework-specific extension points, and multi-module fix propagation — where earlier heuristics produced false positives or missed scope mismatches entirely.</p> <p><strong>GraalVM native-image support</strong> processes <code>META-INF/native-image/**/*.json</code> resource files to discover classes referenced via GraalVM's reflection, proxy, serialization, and JNI configurations, preventing UNUSED false positives for dependencies that contribute only native-image metadata. This matters for any project building a native executable where dependencies are invisible to bytecode scanning.</p> <p><strong>DiscoveryConvention SPI</strong> replaces the hard-coded source-detection logic with a pluggable strategy pattern. The built-in conventions cover Maven standard layout, Groovy, Kotlin, Scala, and annotation-processor outputs — and the SPI lets future extensions add project types without touching core. The immediate fix eliminates false positives in Groovy/Kotlin/Scala projects where <code>hasMainSources()</code> / <code>hasTestSources()</code> previously returned <code>false</code> on legitimate builds.</p> <p><strong>Camel SPI detection</strong> classifies Apache Camel extension providers (services registered under <code>META-INF/services/</code>) as UNDETERMINED rather than UNUSED, since their usage is resolved at runtime through Camel's service-loader mechanism and cannot be proven statically.</p> <p><strong>Test-scope narrowing</strong> identifies compile-scope dependencies whose classes appear only in test source trees and automatically suggests narrowing them to <code>test</code>. The fix action now converges with <code>pilot.maxIterations</code> (default 5) to handle cascading scope changes across multi-module reactors.</p> <p>On top of that, six correctness fixes address type-resolution edge cases, aggregator POM false positives, managed-dependency propagation to the right ancestor, and guard conditions for projects with no test sources.</p> <hr /> <h2>🚀 New Features & Improvements</h2> <ul> <li>Refactor runtime-discovery into pluggable DiscoveryConvention strategies (<a href="https://redirect.github.com/maveniverse/pilot/pull/196">#196</a>) <a href="https://github.com/gnodet"><code>@gnodet</code></a></li> <li>feat: GraalVM native-image metadata support to fix false-positive UNUSED dependency reports (<a href="https://redirect.github.com/maveniverse/pilot/pull/195">#195</a>) <a href="https://github.com/gnodet"><code>@gnodet</code></a></li> <li>feat: converge fix action with pilot.maxIterations (default 5) (<a href="https://redirect.github.com/maveniverse/pilot/pull/194">#194</a>) <a href="https://github.com/gnodet"><code>@gnodet</code></a></li> <li>feat: detect Apache Camel SPI providers and classify them as UNDETERMINED (<a href="https://redirect.github.com/maveniverse/pilot/pull/193">#193</a>) <a href="https://github.com/gnodet"><code>@gnodet</code></a></li> <li>feat: detect compile-scope deps used only in tests and narrow scope (<a href="https://redirect.github.com/maveniverse/pilot/pull/191">#191</a>) <a href="https://github.com/gnodet"><code>@gnodet</code></a></li> </ul> <h2>🐛 Bug Fixes</h2> <ul> <li>fix: add property= bindings to bare <a href="https://github.com/Parameter"><code>@Parameter</code></a> annotations so list/map params work as -D flags (<a href="https://redirect.github.com/maveniverse/pilot/pull/192">#192</a>) <a href="https://github.com/gnodet"><code>@gnodet</code></a></li> <li>fix: detect Groovy/Kotlin/Scala sources by convention in hasTestSources() and hasMainSources() (<a href="https://redirect.github.com/maveniverse/pilot/pull/181">#181</a>) <a href="https://github.com/gnodet"><code>@gnodet</code></a></li> <li>fix: suppress used-transitive false positives for type=pom aggregator dependencies (<a href="https://redirect.github.com/maveniverse/pilot/pull/184">#184</a>) <a href="https://github.com/gnodet"><code>@gnodet</code></a></li> <li>fix: propagate managed dep to ancestor with most dependencyManagement entries (<a href="https://redirect.github.com/maveniverse/pilot/pull/185">#185</a>) <a href="https://github.com/gnodet"><code>@gnodet</code></a></li> <li>fix: resolve Maven type (e.g. test-jar) via ArtifactTypeRegistry in buildCollectRequest (<a href="https://redirect.github.com/maveniverse/pilot/pull/180">#180</a>) <a href="https://github.com/gnodet"><code>@gnodet</code></a></li> <li>fix: skip test-classes guard when project has no test sources (<a href="https://redirect.github.com/maveniverse/pilot/pull/179">#179</a>) <a href="https://github.com/gnodet"><code>@gnodet</code></a></li> </ul> <h2>📦 Dependency Updates</h2> <ul> <li>build(deps): bump tamboui.version from 0.4.0 to 0.5.0 (<a href="https://redirect.github.com/maveniverse/pilot/pull/186">#186</a>) <a href="https://github.com/dependabot"><code>@dependabot</code></a></li> <li>build(deps-dev): bump org.apache.maven.resolver:maven-resolver-connector-basic from 1.9.27 to 2.0.23 (<a href="https://redirect.github.com/maveniverse/pilot/pull/187">#187</a>) <a href="https://github.com/dependabot"><code>@dependabot</code></a></li> <li>build(deps): bump jline.version from 4.4.3 to 4.4.5 (<a href="https://redirect.github.com/maveniverse/pilot/pull/188">#188</a>) <a href="https://github.com/dependabot"><code>@dependabot</code></a></li> <li>build(deps-dev): bump org.apache.maven.resolver:maven-resolver-transport-file from 1.9.27 to 2.0.23 (<a href="https://redirect.github.com/maveniverse/pilot/pull/189">#189</a>) <a href="https://github.com/dependabot"><code>@dependabot</code></a></li> </ul> <h2>👻 Maintenance</h2> <ul> <li>ci: remove redundant =true from -Dnjord.waitForStates (<a href="https://redirect.github.com/maveniverse/pilot/pull/178">#178</a>) <a href="https://github.com/gnodet"><code>@gnodet</code></a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/maveniverse/pilot/compare/0.4.0...0.5.0">https://github.com/maveniverse/pilot/compare/0.4.0...0.5.0</a></p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/maveniverse/pilot/commit/e234879a9a313cb7470e53631c41f5c1712eadcb"><code>e234879</code></a> Refactor runtime-discovery into pluggable DiscoveryConvention strategies (<a href="https://redirect.github.com/maveniverse/pilot/issues/196">#196</a>)</li> <li><a href="https://github.com/maveniverse/pilot/commit/0e92bbc163f433237306919a8bc38bf88e3b6c2e"><code>0e92bbc</code></a> feat: GraalVM native-image metadata support to fix false-positive UNUSED depe...</li> <li><a href="https://github.com/maveniverse/pilot/commit/07d50483a16f29c300b69e3798d9043d0cfe06b7"><code>07d5048</code></a> feat: converge fix action with pilot.maxIterations (default 5)</li> <li><a href="https://github.com/maveniverse/pilot/commit/a02dbdf551b85441f36ee372bbf5e102b84f79de"><code>a02dbdf</code></a> build(deps): bump tamboui.version from 0.4.0 to 0.5.0</li> <li><a href="https://github.com/maveniverse/pilot/commit/d3b36e7a88769d3ceedb39077874276d1c81f004"><code>d3b36e7</code></a> build(deps-dev): bump org.apache.maven.resolver:maven-resolver-connector-basi...</li> <li><a href="https://github.com/maveniverse/pilot/commit/d8d2c06dc237cafb84feef010b927a01eae6e4ec"><code>d8d2c06</code></a> build(deps): bump jline.version from 4.4.3 to 4.4.5</li> <li><a href="https://github.com/maveniverse/pilot/commit/d1f05a1c6454853724690a83d5020067d0c20c1d"><code>d1f05a1</code></a> build(deps-dev): bump org.apache.maven.resolver:maven-resolver-transport-file...</li> <li><a href="https://github.com/maveniverse/pilot/commit/ebb679e447fd125e772195c15d0f937837ed6342"><code>ebb679e</code></a> feat: detect Apache Camel SPI providers and classify them as UNDETERMINED</li> <li><a href="https://github.com/maveniverse/pilot/commit/c594b1e4223d82373853fa04a1f8160d5e38c026"><code>c594b1e</code></a> fix: add property= bindings to bare <a href="https://github.com/Parameter"><code>@Parameter</code></a> annotations so list/map params...</li> <li><a href="https://github.com/maveniverse/pilot/commit/57e3148d3d1ba5d58c717afc0a632619ae46389e"><code>57e3148</code></a> feat: detect compile-scope deps used only in tests and narrow scope</li> <li>Additional commits viewable in <a href="https://github.com/maveniverse/pilot/compare/0.4.0...0.5.0">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
