slachiewicz opened a new issue, #541:
URL: https://github.com/apache/maven-build-cache-extension/issues/541

   ### Affected version
   
   1.3.1-SNAPSHOT (current master)
   
   ### Problem 1: dead repository pulled into the build
   
   `pom.xml` declares `javax.annotation:javax.annotation-api:1.3.2`, whose 
parent is `net.java:jvnet-parent` (v3). jvnet-parent declares 
`<repositories>`/`<pluginRepositories>` pointing at the shut-down 
`https://maven.java.net` host:
   
   - `jvnet-nexus-releases` → 
`https://maven.java.net/content/repositories/releases/`
   - `jvnet-nexus-snapshots` → 
`https://maven.java.net/content/repositories/snapshots/`
   
   Dependency-POM repositories are not used for artifact resolution, but they 
leak into the remote repository set used for **metadata** lookups, so every 
build pays failing HTTPS round-trips against the dead host (expired 
certificate). Maven 4's plugin-prefix discovery probes it too:
   
   ```
   [WARNING] Could not transfer metadata /.meta/prefixes.txt from/to 
jvnet-nexus-releases (https://maven.java.net/content/repositories/releases/): 
(certificate_expired) PKIX path validation failed: 
java.security.cert.CertPathValidatorException: validity check failed
   ```
   
   **Suggested fix:** replace with 
`jakarta.annotation:jakarta.annotation-api:1.3.5` — the EE4J continuation of 
the same JSR-250 API under the **same `javax.annotation` package names** (the 
jakarta package rename only happened in 2.x), so it is a drop-in replacement 
with no source changes. The code only uses `@PostConstruct` and `@Priority` 
from it; note the `javax.annotation.Nonnull`/`Nullable` imports elsewhere 
resolve from `com.google.code.findbugs:jsr305`, not from this artifact. The 
EE4J parent declares no active resolution repositories.
   
   ### Problem 2: unused declared dependencies
   
   `mvn dependency:analyze` plus source inspection finds:
   
   - `org.apache.maven.resolver:maven-resolver-util` (provided) — no 
compile-time usage
   - `org.apache.maven.resolver:maven-resolver-transport-http` (provided) — the 
`aether.transport.http.supportWebDav` usages are string literals; the transport 
itself is supplied by Maven at runtime via `TransporterProvider`, and 
provided-scope artifacts are never packaged
   - `org.slf4j:log4j-over-slf4j`, `jcl-over-slf4j`, `jul-to-slf4j` (test) — 
never referenced (no code, no `logback-test.xml` configuring them)
   - `org.apache.maven.shared:maven-verifier` — used only from test sources 
(`org.apache.maven.it.Verifier` in `its/remote` tests), so it should be test 
scope instead of compile
   
   `org.openjdk.jmh:jmh-generator-annprocess` is reported as unused but is a 
false positive: it performs the `@Benchmark` annotation processing for 
`src/test/.../hash/PerfTest.java` and must stay.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to