slachiewicz commented on issue #8177: URL: https://github.com/apache/maven/issues/8177#issuecomment-5738913085
Measured what the 3.x line needs from `maven-compat` at runtime, by deleting `lib/maven-compat-*.jar` from the stock 3.9.16 and 3.10.0-rc-1 distributions and running a reactor that exercises toolchains, compiler 3.16.0 with a JDK toolchain, surefire 3.5.4, jar, javadoc jar and report, source, enforcer `requirePluginVersions`, dependency analyze/tree, plugin-plugin 3.15.1 descriptor and metadata, install, file deploy, and site 3.21.0 with six project-info reports. **Core needs nothing.** Both stripped distributions run the full `clean deploy site` green (16 goals, 22 reports), same as stock 3.9.16. **What breaks is a fixed set of released plugins**, always with the same shape: a maven-core interface whose only implementation is in maven-compat, so Guice injects null (`null returned by binding at LocatorWiring … is not @Nullable`). On 3.9.x those interfaces are `org.apache.maven.repository.RepositorySystem`, `RepositoryMetadataManager` and `project.path.PathTranslator`. Scanning the latest release tag of 81 apache/maven-* repos for those and for every compat class: | Plugin, latest release | Injects | Fix | |---|---|---| | project-info-reports 3.9.0 | legacy `RepositorySystem`, every report fails | on master, MPIR-477, unreleased | | dependency-plugin 3.11.0 | legacy `RepositorySystem` in `GetMojo`, `dependency:get` fails | on master, MDEP-858, unreleased | | doap-plugin 3.0.0-M1 | `ArtifactResolver`, `MavenProjectBuilder`, `RepositoryMetadataManager` | on master, unreleased | | plugin-tools 3.16.0 | `PathTranslator` referenced by `maven-script-ant`; never looked up at runtime (the requirement never reached `plugin.xml`, MPLUGIN-160), so no effect on 3.9 | apache/maven-plugin-tools#1200 removes the class link, which matters only on Maven 4 | Nothing else in the estate at its latest release touches compat. So for the 3.x line the work is three releases (tracked in #13085), after which the only consumers of the jar are third-party plugins that still inject the Maven 2 API, which `Maven3CompatDependenciesValidator` already warns about. The test-scope declarations in plugin POMs are a separate matter (plugin-testing-harness on maven-core < 3.9.12) and do not affect users. Method note: the earlier master scan missed all three because releases lag master; only a scan of release tags finds them. *This comment was created with AI assistance.* -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
