slachiewicz opened a new issue, #541: URL: https://github.com/apache/maven-build-cache-extension/issues/541
### Affected version 1.3.1-SNAPSHOT (current master) ### Problem 1: dead repository pulled into the build `pom.xml` declares `javax.annotation:javax.annotation-api:1.3.2`, whose parent is `net.java:jvnet-parent` (v3). jvnet-parent declares `<repositories>`/`<pluginRepositories>` pointing at the shut-down `https://maven.java.net` host: - `jvnet-nexus-releases` → `https://maven.java.net/content/repositories/releases/` - `jvnet-nexus-snapshots` → `https://maven.java.net/content/repositories/snapshots/` Dependency-POM repositories are not used for artifact resolution, but they leak into the remote repository set used for **metadata** lookups, so every build pays failing HTTPS round-trips against the dead host (expired certificate). Maven 4's plugin-prefix discovery probes it too: ``` [WARNING] Could not transfer metadata /.meta/prefixes.txt from/to jvnet-nexus-releases (https://maven.java.net/content/repositories/releases/): (certificate_expired) PKIX path validation failed: java.security.cert.CertPathValidatorException: validity check failed ``` **Suggested fix:** replace with `jakarta.annotation:jakarta.annotation-api:1.3.5` — the EE4J continuation of the same JSR-250 API under the **same `javax.annotation` package names** (the jakarta package rename only happened in 2.x), so it is a drop-in replacement with no source changes. The code only uses `@PostConstruct` and `@Priority` from it; note the `javax.annotation.Nonnull`/`Nullable` imports elsewhere resolve from `com.google.code.findbugs:jsr305`, not from this artifact. The EE4J parent declares no active resolution repositories. ### Problem 2: unused declared dependencies `mvn dependency:analyze` plus source inspection finds: - `org.apache.maven.resolver:maven-resolver-util` (provided) — no compile-time usage - `org.apache.maven.resolver:maven-resolver-transport-http` (provided) — the `aether.transport.http.supportWebDav` usages are string literals; the transport itself is supplied by Maven at runtime via `TransporterProvider`, and provided-scope artifacts are never packaged - `org.slf4j:log4j-over-slf4j`, `jcl-over-slf4j`, `jul-to-slf4j` (test) — never referenced (no code, no `logback-test.xml` configuring them) - `org.apache.maven.shared:maven-verifier` — used only from test sources (`org.apache.maven.it.Verifier` in `its/remote` tests), so it should be test scope instead of compile `org.openjdk.jmh:jmh-generator-annprocess` is reported as unused but is a false positive: it performs the `@Benchmark` annotation processing for `src/test/.../hash/PerfTest.java` and must stay. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
