slachiewicz opened a new pull request, #610:
URL: https://github.com/apache/maven-parent/pull/610

   ## Motivation
   
   While migrating the Maven project repositories to parent 50 (42 red 
dependabot parent-bump PRs triaged on 2026-09-24/25), four recurring migration 
traps showed up across ~40 repositories:
   
   1. **apache-rat 0.18 ignores child `<excludes>`** once the parent sets 
`inputExcludes` → `Counter(s) UNAPPROVED` failures. Children must rename the 
parameter (keeping `combine.children="append"`).
   2. **rat 0.18 requires JDK 17.** Children that declare the plugin 
unconditionally in `<build><plugins>` re-activate it on jdk-8 CI cells (`unmet 
prerequisites`). The declaration belongs in a `java17+` profile, merging with 
the parent's.
   3. **rat 0.18 matches patterns root-anchored** — previously working entries 
like `src/test/resources/**` silently stop matching in multi-module builds; 
entries need a `**/` prefix. Additionally binary test fixtures are now counted 
as unapproved.
   4. **`version.maven-surefire` was removed** (apache-parent 40): invoker 
`@version.maven-surefire@` tokens and archetype templates emit unresolved 
versions; use `version.maven-surefire-plugin` / `-failsafe-` / `-report-plugin`.
   
   This PR documents all of them (plus the spotless `check` mode on CI) on a 
new site page linked from the "Maven Parent POMs" menu, so consumers upgrading 
don't have to rediscover them.
   
   Fixes verified on the affected repositories; the page renders with `mvn 
site:site` in `docs/`.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to