gnodet opened a new issue, #13190:
URL: https://github.com/apache/maven/issues/13190

   ## Summary
   
   Maven 4 raises `[ERROR] 'dependencies.dependency.version' for ... is 
missing` during model validation for dependencies whose version is managed via 
a BOM (`<scope>import</scope>` in `<dependencyManagement>`). Maven 3 accepted 
these without error.
   
   This causes build failures for projects that correctly rely on BOM-managed 
versions and omit explicit `<version>` declarations in their `<dependencies>` 
section.
   
   ## Reproduction
   
   Affected projects (found in maven4-testing rc-6 run):
   - 
[cassandra-java-driver](https://github.com/gnodet/maven4-testing/issues/40001) 
— multiple `org.apache.cassandra:*` artifacts with BOM-managed versions
   - 
[incubator-kie-optaplanner-quickstarts](https://github.com/gnodet/maven4-testing/issues/39850)
 — similar pattern
   
   ## Error (from mvnup / Maven 4 model validation)
   
   ```
   [ERROR] 'dependencies.dependency.version' for 
groupId='org.apache.cassandra', artifactId='java-driver-test-infra', type='jar' 
is missing. @ line 42, column 5
   [ERROR] 'dependencies.dependency.version' for 
groupId='org.apache.cassandra', artifactId='java-driver-query-builder', 
type='jar' is missing. @ line 47, column 5
   [ERROR] 'dependencies.dependency.version' for 
groupId='org.apache.cassandra', artifactId='java-driver-mapper-processor', 
type='jar' is missing. @ line 52, column 5
   ```
   
   ## Expected behavior
   
   Dependencies whose version is managed by an imported BOM should not trigger 
validation errors. The BOM provides the version; the child POM correctly omits 
`<version>` per Maven best practice. Maven 3 accepted this pattern without 
error.
   
   ## Notes
   
   This may be a validation timing issue: the error occurs before the BOM 
import has been resolved and applied to `dependencyManagement`. If so, the fix 
would be to defer or suppress this validation until after BOM imports are 
resolved.
   
   Alternatively, this could be intended stricter behavior — in which case the 
error message should clarify that the version must be provided in 
`dependencyManagement` (not necessarily inline), and the severity should be 
WARNING rather than ERROR for BOM-managed cases.
   
   ## Maven version
   
   Maven 4.0.0-rc-6 / maven-4.0.x branch
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to