gnodet opened a new issue, #13190: URL: https://github.com/apache/maven/issues/13190
## Summary Maven 4 raises `[ERROR] 'dependencies.dependency.version' for ... is missing` during model validation for dependencies whose version is managed via a BOM (`<scope>import</scope>` in `<dependencyManagement>`). Maven 3 accepted these without error. This causes build failures for projects that correctly rely on BOM-managed versions and omit explicit `<version>` declarations in their `<dependencies>` section. ## Reproduction Affected projects (found in maven4-testing rc-6 run): - [cassandra-java-driver](https://github.com/gnodet/maven4-testing/issues/40001) — multiple `org.apache.cassandra:*` artifacts with BOM-managed versions - [incubator-kie-optaplanner-quickstarts](https://github.com/gnodet/maven4-testing/issues/39850) — similar pattern ## Error (from mvnup / Maven 4 model validation) ``` [ERROR] 'dependencies.dependency.version' for groupId='org.apache.cassandra', artifactId='java-driver-test-infra', type='jar' is missing. @ line 42, column 5 [ERROR] 'dependencies.dependency.version' for groupId='org.apache.cassandra', artifactId='java-driver-query-builder', type='jar' is missing. @ line 47, column 5 [ERROR] 'dependencies.dependency.version' for groupId='org.apache.cassandra', artifactId='java-driver-mapper-processor', type='jar' is missing. @ line 52, column 5 ``` ## Expected behavior Dependencies whose version is managed by an imported BOM should not trigger validation errors. The BOM provides the version; the child POM correctly omits `<version>` per Maven best practice. Maven 3 accepted this pattern without error. ## Notes This may be a validation timing issue: the error occurs before the BOM import has been resolved and applied to `dependencyManagement`. If so, the fix would be to defer or suppress this validation until after BOM imports are resolved. Alternatively, this could be intended stricter behavior — in which case the error message should clarify that the version must be provided in `dependencyManagement` (not necessarily inline), and the severity should be WARNING rather than ERROR for BOM-managed cases. ## Maven version Maven 4.0.0-rc-6 / maven-4.0.x branch -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
