This is an automated email from the ASF dual-hosted git repository.

robertlazarski pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/axis-axis2-java-rampart.git

commit 72675276dc95fd8069e6cc806338c762e6bf65f0
Author: Robert Lazarski <[email protected]>
AuthorDate: Thu Oct 8 18:14:51 2026 -1000

    Ship guava in rampart-dist now that Axis2 2.0.2 no longer bundles it
    
    bin.xml excluded guava, failureaccess and jspecify as provided by Axis2, but
    Axis2 2.0.2 dropped them with google-java-format and OpenSAML's parser pool
    needs guava, so every sample failed when rahas deployed. Guava is pinned to
    33.6.0-jre, the version Axis2 2.0.1 shipped, so installs there do not 
duplicate it.
    
    Co-Authored-By: Claude Opus 5.5 <[email protected]>
---
 modules/distribution/bin.xml | 6 +++---
 pom.xml                      | 9 +++++++++
 2 files changed, 12 insertions(+), 3 deletions(-)

diff --git a/modules/distribution/bin.xml b/modules/distribution/bin.xml
index 81a998fd..c3b768b6 100644
--- a/modules/distribution/bin.xml
+++ b/modules/distribution/bin.xml
@@ -48,8 +48,9 @@
                      Including them here would put duplicate versions on the 
classpath. -->
                 <exclude>com.fasterxml.woodstox:woodstox-core</exclude>
                 <exclude>com.google.code.findbugs:jsr305</exclude>
-                <exclude>com.google.guava:failureaccess</exclude>
-                <exclude>com.google.guava:guava</exclude>
+                <!-- guava, failureaccess and jspecify are deliberately NOT 
excluded:
+                     Axis2 2.0.2 stopped shipping them, and without guava 
OpenSAML
+                     initialisation fails when the rahas module deploys. -->
                 <exclude>com.sun.istack:istack-commons-runtime</exclude>
                 <exclude>commons-io:commons-io</exclude>
                 <exclude>commons-logging:commons-logging</exclude>
@@ -83,7 +84,6 @@
                 <exclude>org.glassfish.jaxb:jaxb-core</exclude>
                 <exclude>org.glassfish.jaxb:jaxb-runtime</exclude>
                 <exclude>org.glassfish.jaxb:txw2</exclude>
-                <exclude>org.jspecify:jspecify</exclude>
                 <exclude>org.slf4j:slf4j-api</exclude>
                 <exclude>wsdl4j:wsdl4j</exclude>
             </excludes>
diff --git a/pom.xml b/pom.xml
index aa0abeb8..35b9dbda 100644
--- a/pom.xml
+++ b/pom.xml
@@ -458,6 +458,15 @@
                 <artifactId>commons-fileupload</artifactId>
                 <version>1.6.0</version>
             </dependency>
+            <!-- Required at runtime by Shibboleth's BasicParserPool (via 
WSS4J), and
+                 shipped in rampart-dist lib/ because Axis2 2.0.2 no longer 
bundles it.
+                 Pinned to the version Axis2 2.0.1 shipped, so installing into 
2.0.1
+                 overwrites that jar rather than adding a second guava. -->
+            <dependency>
+                <groupId>com.google.guava</groupId>
+                <artifactId>guava</artifactId>
+                <version>33.6.0-jre</version>
+            </dependency>
             <dependency>
                 <groupId>org.apache.axis2</groupId>
                 <artifactId>axis2-mtompolicy</artifactId>

Reply via email to