slachiewicz opened a new issue, #1795:
URL: https://github.com/apache/maven-mvnd/issues/1795

   ### Affected version
   
   mvnd 1.x (`mvnd-agent` module, javassist 3.33.0-GA)
   
   ### Problem
   
   `mvnd-agent` depends on `org.javassist:javassist` and bundles it into the 
agent jar via maven-shade-plugin without any relocation (the only configured 
filter excludes `META-INF/MANIFEST.MF`). During a reactor build the shade 
plugin warns:
   
   ```
   [WARNING] javassist-3.33.0-GA.jar, mvnd-agent-1.0.7-SNAPSHOT.jar define 409 
overlapping classes and resources
   ```
   
   Because the agent is attached to the user's JVM (helper agent on the boot 
classpath), unrelocated `javassist.*` classes can clash with javassist versions 
used by builds or plugins, making behavior dependent on classpath order.
   
   ### Suggestion
   
   Add a relocation `javassist` -> e.g. `org.mvndaemon.mvnd.shaded.javassist` 
to the shade configuration, as is standard practice for instrumentation agents 
that embed bytecode libraries.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to