slachiewicz opened a new pull request, #610: URL: https://github.com/apache/maven-parent/pull/610
## Motivation While migrating the Maven project repositories to parent 50 (42 red dependabot parent-bump PRs triaged on 2026-09-24/25), four recurring migration traps showed up across ~40 repositories: 1. **apache-rat 0.18 ignores child `<excludes>`** once the parent sets `inputExcludes` → `Counter(s) UNAPPROVED` failures. Children must rename the parameter (keeping `combine.children="append"`). 2. **rat 0.18 requires JDK 17.** Children that declare the plugin unconditionally in `<build><plugins>` re-activate it on jdk-8 CI cells (`unmet prerequisites`). The declaration belongs in a `java17+` profile, merging with the parent's. 3. **rat 0.18 matches patterns root-anchored** — previously working entries like `src/test/resources/**` silently stop matching in multi-module builds; entries need a `**/` prefix. Additionally binary test fixtures are now counted as unapproved. 4. **`version.maven-surefire` was removed** (apache-parent 40): invoker `@version.maven-surefire@` tokens and archetype templates emit unresolved versions; use `version.maven-surefire-plugin` / `-failsafe-` / `-report-plugin`. This PR documents all of them (plus the spotless `check` mode on CI) on a new site page linked from the "Maven Parent POMs" menu, so consumers upgrading don't have to rediscover them. Fixes verified on the affected repositories; the page renders with `mvn site:site` in `docs/`. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
