elharo opened a new pull request, #261:
URL: https://github.com/apache/maven-artifact-plugin/pull/261
## What
`ReproducibleCentralReport` triggers a javac deprecation warning:
```
[WARNING] .../ReproducibleCentralReport.java:[30,44]
org.apache.maven.plugins.annotations.Component
in org.apache.maven.plugins.annotations has been deprecated
[WARNING] .../ReproducibleCentralReport.java:[55,6]
org.apache.maven.plugins.annotations.Component
in org.apache.maven.plugins.annotations has been deprecated
```
`org.apache.maven.plugins.annotations.Component` was deprecated in
maven-plugin-annotations 3.15.2 with the message:
> Use JSR 330 annotations or Parameter with according default expressions
instead.
The project builds against `maven-plugin-annotations` 3.16.0 (inherited from
`apache:40`), which is where the warning now shows up.
## Why remove the field rather than switch to `@Inject`
The `MavenSession` field is **never read** anywhere in the report — it has
been dead since the report was added in
[b82943b](https://github.com/apache/maven-artifact-plugin/commit/b82943b22c7b561c1d70c10d485a50e78a999aa3)
(MARTIFACT-81). It only serves to have Plexus inject a component that is then
thrown away.
So rather than rewriting `@Component` to `javax.inject.Inject` (the JSR 330
replacement, already used by `DescribeBuildOutputMojo`, `CheckBuildPlanMojo`
and `RangesUtil` in this plugin), the field is dropped entirely, along with the
now-unused `MavenSession` import. Nothing in the report depends on the session,
and the report's dependency resolution is already declared by
`requiresDependencyResolution = ResolutionScope.RUNTIME` on the `@Mojo`
annotation.
## Effects
* The two javac deprecation warnings are gone.
* `META-INF/maven/plugin.xml` no longer contains a `<requirement>` for
`org.apache.maven.execution.MavenSession`.
* The related `maven-plugin-plugin` warning loses one field:
```
- Mojo reproducible-central uses Plexus Component requirements (@Component
annotation) for fields: [container, session, siteRenderer, siteTool]
+ Mojo reproducible-central uses Plexus Component requirements (@Component
annotation) for fields: [container, siteRenderer, siteTool]
```
The three remaining fields (`container`, `siteRenderer`, `siteTool`) are
declared with `@Component` inside `AbstractMavenReport` in
`maven-reporting-impl`, so they are inherited rather than defined here.
`maven-reporting-impl:4.0.0` is already the latest release, so clearing those
would be an upstream change and is out of scope here. That is why this PR fixes
the javac warning but the plugin-level advisory remains.
## Verification
* `mvn clean compile -Dmaven.compiler.showDeprecation=true` — no deprecation
warnings; on `master` the two warnings above are reported.
* `mvn clean verify -DskipITs` — BUILD SUCCESS, 0 Checkstyle violations,
Spotless clean, 2/2 unit tests pass.
* Smoke-tested the report end-to-end against a throwaway project with both
paths:
* standalone goal `mvn artifact:reproducible-central`
* via the site lifecycle, `mvn site -DgenerateReports=true` with the
report declared in `src/site/site.xml` → `Detected 1 report for
maven-artifact-plugin: reproducible-central`, `Generating "Reproducible
Central" report`, BUILD SUCCESS
Both render the project badge, the per-scope dependency badge groups (e.g.
`compile`, `runtime`) and the Reproducible Builds footnote, i.e. output is
unchanged.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]