[ 
https://issues.apache.org/jira/browse/MASSEMBLY-675?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Robert Scholte updated MASSEMBLY-675:
-------------------------------------
    Description: 
Version 2.4 ignores wildcard exclusions in POM dependencies

Example (perhaps contrived - but easy to setup):

When a pom declares a dependency such as closure-compiler and for some reason 
we do not want to pull its dependencies in we could declare this in our POM, 
without having to know what those dependencies are:

{code:xml}
<dependencies>
 <dependency>
 <groupId>com.google.javascript</groupId>
 <artifactId>closure-compiler</artifactId>
 <version>v20131014</version>
 <exclusions>
 <exclusion>
 <artifactId>*</artifactId>
 <groupId>*</groupId>
 </exclusion>
 </exclusions>
 </dependency>
 </dependencies>
{code}

This is a valid use of the exclusion feature as per [Maven 
Confluence|http://docs.codehaus.org/display/MAVENUSER/wildcard+exclusion+for+artifact+dependencies],
 MNG-3832. False warning about wildcards were 
[fixed|https://git-wip-us.apache.org/repos/asf?p=maven.git;a=commitdiff;h=65c135d5]
 in Git about 10 days ago 
 Here is the assembly descriptor:

{code:xml}
<assembly>
 <id>bin</id>
 <formats>
 <format>dir</format>
 </formats>
 <includeBaseDirectory>false</includeBaseDirectory>
 <dependencySets>
 <dependencySet/>
 </dependencySets>
 </assembly>
{code}
We expect to only find the current project artifact and the closure-compiler 
JAR in our directory assembly. However the assembly plugin ignores our POM 
directive and includes the closure-compilers dependencies anyway!

Steps to reproduce are:
{noformat}
$ unzip massembly-675.zip
 $ cd massembly-675
 $ mvn clean install
 $ ls target/massembly-675-1-bin
 args4j-2.0.16.jar json-20090211.jar protobuf-java-2.4.1.jar
 closure-compiler-v20131014.jar jsr305-1.3.9.jar
 guava-15.0.jar massembly-675-1.jar
{noformat}
*Notice that the excluded jars are included in the assembly*

I would expect to only see the following JARs.
 * closure-compiler-v20131014.jar
 * massembly-675-1.jar

  was:
Version 2.4 ignores wildcard exclusions in POM dependencies

Example (perhaps contrived - but easy to setup):

When a pom declares a dependency such as closure-compiler and for some reason 
we do not want to pull its dependencies in we could declare this in our POM, 
without having to know what those dependencies are:

  <dependencies>
    <dependency>
      <groupId>com.google.javascript</groupId>
      <artifactId>closure-compiler</artifactId>
      <version>v20131014</version>
      <exclusions>
        <exclusion>
          <artifactId>*</artifactId>
          <groupId>*</groupId>
        </exclusion>
      </exclusions>
    </dependency>
  </dependencies>

This is a valid use of the exclusion feature as per [Maven 
Confluence|http://docs.codehaus.org/display/MAVENUSER/wildcard+exclusion+for+artifact+dependencies],
 [MNG-3832|https://jira.codehaus.org/browse/MNG-3832]. False warning about 
wildcards were 
[fixed|https://git-wip-us.apache.org/repos/asf?p=maven.git;a=commitdiff;h=65c135d5]
 in Git about 10 days ago  
Here is the assembly descriptor:

<assembly>
  <id>bin</id>
  <formats>
    <format>dir</format>
  </formats>
  <includeBaseDirectory>false</includeBaseDirectory>
  <dependencySets>
    <dependencySet/>
  </dependencySets>
</assembly>

We expect to only find the current project artifact and the closure-compiler 
JAR in our directory assembly. However the assembly plugin ignores our POM 
directive and includes the closure-compilers dependencies anyway!

Steps to reproduce are:

$ unzip massembly-675.zip
$ cd massembly-675
$ mvn clean install
$ ls target/massembly-675-1-bin
args4j-2.0.16.jar              json-20090211.jar              
protobuf-java-2.4.1.jar
closure-compiler-v20131014.jar jsr305-1.3.9.jar
guava-15.0.jar                 massembly-675-1.jar

*Notice that the excluded jars are included in the assembly*

I would expect to only see the following JARs.

* closure-compiler-v20131014.jar
* massembly-675-1.jar


> Maven Assembly packaging wildcard-excluded dependencies
> -------------------------------------------------------
>
>                 Key: MASSEMBLY-675
>                 URL: https://issues.apache.org/jira/browse/MASSEMBLY-675
>             Project: Maven Assembly Plugin
>          Issue Type: Bug
>    Affects Versions: 2.4
>         Environment: Apache Maven 3.1.1
> Java version: 1.7.0_45, vendor: Oracle Corporation
> OS name: "mac os x", version: "10.8.4", arch: "x86_64", family: "mac"
>            Reporter: Frank Wilson
>            Assignee: Guillaume Boué
>            Priority: Major
>             Fix For: 3.1.1
>
>         Attachments: massembly-675.zip
>
>
> Version 2.4 ignores wildcard exclusions in POM dependencies
> Example (perhaps contrived - but easy to setup):
> When a pom declares a dependency such as closure-compiler and for some reason 
> we do not want to pull its dependencies in we could declare this in our POM, 
> without having to know what those dependencies are:
> {code:xml}
> <dependencies>
>  <dependency>
>  <groupId>com.google.javascript</groupId>
>  <artifactId>closure-compiler</artifactId>
>  <version>v20131014</version>
>  <exclusions>
>  <exclusion>
>  <artifactId>*</artifactId>
>  <groupId>*</groupId>
>  </exclusion>
>  </exclusions>
>  </dependency>
>  </dependencies>
> {code}
> This is a valid use of the exclusion feature as per [Maven 
> Confluence|http://docs.codehaus.org/display/MAVENUSER/wildcard+exclusion+for+artifact+dependencies],
>  MNG-3832. False warning about wildcards were 
> [fixed|https://git-wip-us.apache.org/repos/asf?p=maven.git;a=commitdiff;h=65c135d5]
>  in Git about 10 days ago 
>  Here is the assembly descriptor:
> {code:xml}
> <assembly>
>  <id>bin</id>
>  <formats>
>  <format>dir</format>
>  </formats>
>  <includeBaseDirectory>false</includeBaseDirectory>
>  <dependencySets>
>  <dependencySet/>
>  </dependencySets>
>  </assembly>
> {code}
> We expect to only find the current project artifact and the closure-compiler 
> JAR in our directory assembly. However the assembly plugin ignores our POM 
> directive and includes the closure-compilers dependencies anyway!
> Steps to reproduce are:
> {noformat}
> $ unzip massembly-675.zip
>  $ cd massembly-675
>  $ mvn clean install
>  $ ls target/massembly-675-1-bin
>  args4j-2.0.16.jar json-20090211.jar protobuf-java-2.4.1.jar
>  closure-compiler-v20131014.jar jsr305-1.3.9.jar
>  guava-15.0.jar massembly-675-1.jar
> {noformat}
> *Notice that the excluded jars are included in the assembly*
> I would expect to only see the following JARs.
>  * closure-compiler-v20131014.jar
>  * massembly-675-1.jar



--
This message was sent by Atlassian JIRA
(v7.6.3#76005)

Reply via email to