ppkarwasz opened a new pull request, #4282: URL: https://github.com/apache/logging-log4j2/pull/4282
Port of #4281 to `main`. `main` no longer has `BundleTestInfo`, `log4j-api-test`, `log4j-cassandra` or `log4j-core-java9`, so the change reduces to `log4j-parent`: - Removed the managed `maven-core`, `maven-model` and `plexus-utils` entries and their properties. No module on `main` declares them. - Removed the `guava`, `guava-testlib`, `commons-pool2` and `jna` pins and their properties. `guava-testlib` has no declaring module either, since `log4j-to-jul` is not on `main`. - Removed the dead `asm`, `httpclient` and `httpcore` properties, which had no managed entry at all. - Kept `byte-buddy` pinned, with a comment. Without it `requireUpperBoundDeps` fails: AssertJ 3.27.3 requests byte-buddy 1.15.11 and Mockito 5.18.0 requests 1.17.5, and the lower one wins. **Why.** Log4j is a library. Maven consults the `dependencyManagement` of the project being built only. When an application depends on a Log4j module, the management section inherited from `log4j-parent` is not consulted while resolving that module's transitive dependencies, so these pins never reached users. They only changed the versions resolved in our own build and gave a misleading picture of what consumers get. The property block's header now states that pins are kept only when the enforcer fails without them. **Notes.** `log4j-core-test` on `main` depends on the released `log4j-api-test` 2.24.3, which still pulls `maven-core` and guava at compile scope; that path goes away once a 2.x release containing #4281 is used here. Without the guava pin, `log4j-core-test` resolves `failureaccess` 1.0.2 while guava 33.4.8-jre requests 1.0.3; the enforcer does not report it. No changelog entry, since nothing here is visible to users. 🤖 Generated with [Claude Code](https://claude.com/claude-code) -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
