slachiewicz commented on issue #13302: URL: https://github.com/apache/maven/issues/13302#issuecomment-5914067962
### maven-dependency-analyzer PR: apache/maven-dependency-analyzer#305. Status: **ported**, 2.0.0-SNAPSHOT, Java 17. Verified locally: `mvn verify` with Maven 4.0.0-rc-7, JDK 21 → 134 unit tests before, 133 after, 0 failures. The removed test covered the null-session fallback, which no longer exists. ITs (`-P run-its`): 23 of 23 pass before and after; the IT mock plugin is now a Maven 4 API mojo. Spotless clean. **Public API changes** - `ProjectDependencyAnalyzer.analyze(MavenProject[, Collection])` → `analyze(Session, Project[, Collection])`. The analyzer resolves the classpath itself with `DependencyResolver.resolve(..., TEST_RUNTIME)` instead of reading `MavenProject.getArtifacts()`, so callers no longer need `requiresDependencyResolution`. - `ProjectDependencyAnalysis`: `org.apache.maven.artifact.Artifact` → `org.apache.maven.api.Dependency` everywhere. - `DependencyClassesProvider` and its implementations take `Project`; `getOutputClassesDirectory` returns `Path`. - Injection moves from `javax.inject`/Sisu to `org.apache.maven.api.di`, with a hand-written index because the parent sets `<proc>none</proc>`. **Gaps** - No factory for a `Dependency` from `DependencyCoordinates`. Declared but unresolved dependencies (relocations) need one, so the port has a small package-private `DeclaredDependency`, its only shim. - `DependencyResolverRequest.build()` requires a `pathScope` even for `RequestType.COLLECT` (NPE "pathScope cannot be null"). - `Type.getClassifier()` returns null for `jar`, and `Artifact.key()` then throws an NPE inside `hashCode`; the `jarWithRelocatedDependency` IT found it. - `api.model.Build` has no `getPluginsAsMap()` (minor). - IT plugins need maven-plugin-tools 4.0.0-beta-1 to build a v4 mojo. **Consumers that break:** maven-dependency-plugin (`AbstractAnalyzeMojo`, `AnalyzeReport`, `AnalyzeReportRenderer`). It must become a Maven 4 API mojo to pass a `Session`. Its Plexus role-hint lookup of custom analyzers has no v4 DI equivalent. **Improvements:** drops maven-core, maven-artifact, maven-model, resolver, plexus-xml and `javax.inject`. Replaces the `DependencyGraphProject extends MavenProject` hack with an explicit dependency list in the resolver request. `src/main` +680/-605 lines. **Recommendation:** port as 2.0.0 and keep 1.17.x for maven-dependency-plugin 3.x. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
