slachiewicz opened a new pull request, #1695:
URL: https://github.com/apache/maven-dependency-plugin/pull/1695

   Supersedes #1692. The bump alone turns 
`analyze-testDependencyWithNonTestScope` red: the IT declares an unused 
`maven-project:2.0.6`, which reaches `junit:3.8.1` at compile scope through 
`plexus-container-default`, and analyzer 1.17.2 
(apache/maven-dependency-analyzer#294) no longer recommends test scope for a 
candidate that stays on the compile graph. This PR drops that leftover so the 
IT again covers the MDEP-708 case; the assertion is unchanged. The asm 9.10.1 
override stays, since maven-core 3.9.16 still wins mediation with 9.9.1.
   
   Verified: `mvn -Prun-its verify -Dinvoker.test='analyze*'` → 15 ITs pass, 
including `analyze-testDependencyWithNonTestScope`. Spotless not run locally 
(palantir-java-format does not start on the only installed JDK, 27).


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to