ppkarwasz opened a new pull request, #4281:
URL: https://github.com/apache/logging-log4j2/pull/4281
`log4j-api-test` declared `maven-core`, `maven-model` and `plexus-utils` at
compile scope, and `log4j-core-test` and `log4j-core-java9` declared
`maven-core` at test scope. The only code using them was `BundleTestInfo`, a
helper that read `pom.xml` to expose the artifact ID and version. Its last
caller went away in LOG4J2-3546 in 2022, and the class was already dropped on
`main`.
This PR removes the class, the dependency declarations, the corresponding
bnd import-package and module options, and the managed versions in
`log4j-parent`.
**User-visible effect:** consumers of `log4j-api-test` no longer receive
about 25 transitive jars, among them `slf4j-api` 1.7.36, Guice, Sisu and the
Maven resolver. Code that relied on those coming in transitively will need to
declare them directly. `BundleTestInfo` is removed from a public package, but
`log4j-api-test` carries no backward compatibility guarantees. The removal is
annotated with `@BaselineIgnore("2.27.0")` for the bnd baseline check, as done
for the `jvmrunargs` removal in #3874.
**Transitive pins.** As a follow-up, the second commit drops the transitive
dependency pins from `log4j-parent` (`asm`, `byte-buddy`, `commons-pool2`,
`guava`, `httpclient`, `httpcore`, `jna`). Log4j is a library. Maven consults
the `dependencyManagement` of the project being built only. When an application
depends on a Log4j module, the management section inherited from `log4j-parent`
is not consulted while resolving that module's transitive dependencies, so
these pins never reached users. They only changed the versions resolved in our
own build and gave a misleading picture of what consumers get.
`requireUpperBoundDeps` passes without them. The `guava` pin moves to
`log4j-cassandra`, the one module that needs it, because `cassandra-all` breaks
with anything newer than 25.1-jre. The guava exclusions in that module guarded
against the compile-scope guava that arrived through `maven-core`, and are
removed as well.
Dependabot will also stop filing update PRs for the removed artifacts.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]