slachiewicz commented on issue #8177:
URL: https://github.com/apache/maven/issues/8177#issuecomment-5738913085

   Measured what the 3.x line needs from `maven-compat` at runtime, by deleting 
`lib/maven-compat-*.jar` from the stock 3.9.16 and 3.10.0-rc-1 distributions 
and running a reactor that exercises toolchains, compiler 3.16.0 with a JDK 
toolchain, surefire 3.5.4, jar, javadoc jar and report, source, enforcer 
`requirePluginVersions`, dependency analyze/tree, plugin-plugin 3.15.1 
descriptor and metadata, install, file deploy, and site 3.21.0 with six 
project-info reports.
   
   **Core needs nothing.** Both stripped distributions run the full `clean 
deploy site` green (16 goals, 22 reports), same as stock 3.9.16.
   
   **What breaks is a fixed set of released plugins**, always with the same 
shape: a maven-core interface whose only implementation is in maven-compat, so 
Guice injects null (`null returned by binding at LocatorWiring … is not 
@Nullable`). On 3.9.x those interfaces are 
`org.apache.maven.repository.RepositorySystem`, `RepositoryMetadataManager` and 
`project.path.PathTranslator`. Scanning the latest release tag of 81 
apache/maven-* repos for those and for every compat class:
   
   | Plugin, latest release | Injects | Fix |
   |---|---|---|
   | project-info-reports 3.9.0 | legacy `RepositorySystem`, every report fails 
| on master, MPIR-477, unreleased |
   | dependency-plugin 3.11.0 | legacy `RepositorySystem` in `GetMojo`, 
`dependency:get` fails | on master, MDEP-858, unreleased |
   | doap-plugin 3.0.0-M1 | `ArtifactResolver`, `MavenProjectBuilder`, 
`RepositoryMetadataManager` | on master, unreleased |
   | plugin-tools 3.16.0 | `PathTranslator` referenced by `maven-script-ant`; 
never looked up at runtime (the requirement never reached `plugin.xml`, 
MPLUGIN-160), so no effect on 3.9 | apache/maven-plugin-tools#1200 removes the 
class link, which matters only on Maven 4 |
   
   Nothing else in the estate at its latest release touches compat. So for the 
3.x line the work is three releases (tracked in #13085), after which the only 
consumers of the jar are third-party plugins that still inject the Maven 2 API, 
which `Maven3CompatDependenciesValidator` already warns about. The test-scope 
declarations in plugin POMs are a separate matter (plugin-testing-harness on 
maven-core < 3.9.12) and do not affect users.
   
   Method note: the earlier master scan missed all three because releases lag 
master; only a scan of release tags finds them.
   
   *This comment was created with AI assistance.*
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to