davsclaus commented on code in PR #27506:
URL: https://github.com/apache/camel/pull/27506#discussion_r4210389719


##########
pom.xml:
##########
@@ -996,21 +996,35 @@
         <profile>
             <!--
                 Opt-in dependency analysis profile.
-                Usage: mvn compile pilot:dependencies -Pdep-check 
-Dpilot.skipTestScope=true [-Dpilot.action=check]
+                Usage: mvn verify -Pdep-check [-Dpilot.action=check]
                 Leverages 
eu.maveniverse.maven.plugins:pilot-plugin:dependencies for
                 bytecode-level analysis: detects unused declared and used 
transitive deps.
                 Non-blocking by default (report mode); use 
-Dpilot.action=check to fail
                 the build on findings, or -Dpilot.action=fix to apply fixes to 
pom.xml.
-                Use -Dpilot.skipTestScope=true to skip test-scoped dependency 
analysis.
             -->
             <id>dep-check</id>
             <build>
+                <plugins>
+                    <plugin>
+                        <groupId>eu.maveniverse.maven.plugins</groupId>
+                        <artifactId>pilot-plugin</artifactId>
+                        <executions>
+                            <execution>
+                                <id>dep-check</id>
+                                <goals>
+                                    <goal>dependencies</goal>
+                                </goals>
+                                <phase>verify</phase>
+                            </execution>
+                        </executions>
+                    </plugin>
+                </plugins>
                 <pluginManagement>
                     <plugins>
                         <plugin>
                             <groupId>eu.maveniverse.maven.plugins</groupId>
                             <artifactId>pilot-plugin</artifactId>
-                            <version>0.5.0</version>
+                            <version>0.9.0</version>

Review Comment:
   `pilot-plugin:0.9.0` does not resolve from Central (latest there is 0.5.0), 
and the JDK 25 job on this PR failed this step with `Could not find artifact 
eu.maveniverse.maven.plugins:pilot-plugin:jar:0.9.0`. Is the release still 
pending?



##########
.github/workflows/pr-build-main.yml:
##########
@@ -205,6 +205,24 @@ jobs:
         with:
           name: incremental-test-java-${{ matrix.java }}.log
           path: incremental-test.log
+      - name: Dependency analysis
+        # Run only on JDK 25 (the primary matrix entry) to avoid duplicating 
the
+        # 20-minute run. Runs after mvn test so that target/test-classes 
exists.
+        # Non-blocking for now (report mode); switch to -Dpilot.action=check 
once
+        # the report is clean.
+        if: matrix.java == '25'
+        continue-on-error: true
+        run: |
+          ./mvnw verify -Pdep-check -DskipTests -Dlicense.skip \
+            --no-transfer-progress --batch-mode \
+            2>&1 | tee dep-check-output.txt

Review Comment:
   Without `set -o pipefail`, this step's exit status is `tee`'s, so a failing 
`-Dpilot.action=check` would be reported as success later on.
   
   ```suggestion
               2>&1 | tee dep-check-output.txt; exit ${PIPESTATUS[0]}
   ```



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to