slachiewicz commented on issue #13302:
URL: https://github.com/apache/maven/issues/13302#issuecomment-5914067962

   ### maven-dependency-analyzer
   PR: apache/maven-dependency-analyzer#305. Status: **ported**, 
2.0.0-SNAPSHOT, Java 17.
   
   Verified locally: `mvn verify` with Maven 4.0.0-rc-7, JDK 21 → 134 unit 
tests before, 133 after, 0 failures. The removed test covered the null-session 
fallback, which no longer exists. ITs (`-P run-its`): 23 of 23 pass before and 
after; the IT mock plugin is now a Maven 4 API mojo. Spotless clean.
   
   **Public API changes**
   - `ProjectDependencyAnalyzer.analyze(MavenProject[, Collection])` → 
`analyze(Session, Project[, Collection])`. The analyzer resolves the classpath 
itself with `DependencyResolver.resolve(..., TEST_RUNTIME)` instead of reading 
`MavenProject.getArtifacts()`, so callers no longer need 
`requiresDependencyResolution`.
   - `ProjectDependencyAnalysis`: `org.apache.maven.artifact.Artifact` → 
`org.apache.maven.api.Dependency` everywhere.
   - `DependencyClassesProvider` and its implementations take `Project`; 
`getOutputClassesDirectory` returns `Path`.
   - Injection moves from `javax.inject`/Sisu to `org.apache.maven.api.di`, 
with a hand-written index because the parent sets `<proc>none</proc>`.
   
   **Gaps**
   - No factory for a `Dependency` from `DependencyCoordinates`. Declared but 
unresolved dependencies (relocations) need one, so the port has a small 
package-private `DeclaredDependency`, its only shim.
   - `DependencyResolverRequest.build()` requires a `pathScope` even for 
`RequestType.COLLECT` (NPE "pathScope cannot be null").
   - `Type.getClassifier()` returns null for `jar`, and `Artifact.key()` then 
throws an NPE inside `hashCode`; the `jarWithRelocatedDependency` IT found it.
   - `api.model.Build` has no `getPluginsAsMap()` (minor).
   - IT plugins need maven-plugin-tools 4.0.0-beta-1 to build a v4 mojo.
   
   **Consumers that break:** maven-dependency-plugin (`AbstractAnalyzeMojo`, 
`AnalyzeReport`, `AnalyzeReportRenderer`). It must become a Maven 4 API mojo to 
pass a `Session`. Its Plexus role-hint lookup of custom analyzers has no v4 DI 
equivalent.
   
   **Improvements:** drops maven-core, maven-artifact, maven-model, resolver, 
plexus-xml and `javax.inject`. Replaces the `DependencyGraphProject extends 
MavenProject` hack with an explicit dependency list in the resolver request. 
`src/main` +680/-605 lines.
   
   **Recommendation:** port as 2.0.0 and keep 1.17.x for 
maven-dependency-plugin 3.x.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to