slachiewicz opened a new pull request, #1225: URL: https://github.com/apache/maven-plugin-tools/pull/1225
`JavaAnnotationsMojoDescriptorExtractor` unpacked dependency `*-sources.jar` files through plexus-archiver's `ArchiverManager`, which the Maven 4 API line cannot inject. It now uses `java.util.zip` with a guard that rejects entries resolving outside the target directory; the layout and the extracted files are the same. plexus-archiver goes from maven-plugin-tools-annotations and from dependency management. The `ArchiverManager` was field-injected, so the extractor's constructor is unchanged. Ported to `maven-plugin-tools-3.x` in a separate PR. Part of apache/maven#13309. Verified: `mvn verify -Prun-its` → annotations 39 tests (2 new: extraction and a `../` entry), plugin ITs 32 passed, report ITs 12 passed. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
