ppkarwasz opened a new pull request, #4282:
URL: https://github.com/apache/logging-log4j2/pull/4282

   Port of #4281 to `main`.
   
   `main` no longer has `BundleTestInfo`, `log4j-api-test`, `log4j-cassandra` 
or `log4j-core-java9`, so the change reduces to `log4j-parent`:
   
   - Removed the managed `maven-core`, `maven-model` and `plexus-utils` entries 
and their properties. No module on `main` declares them.
   - Removed the `guava`, `guava-testlib`, `commons-pool2` and `jna` pins and 
their properties. `guava-testlib` has no declaring module either, since 
`log4j-to-jul` is not on `main`.
   - Removed the dead `asm`, `httpclient` and `httpcore` properties, which had 
no managed entry at all.
   - Kept `byte-buddy` pinned, with a comment. Without it 
`requireUpperBoundDeps` fails: AssertJ 3.27.3 requests byte-buddy 1.15.11 and 
Mockito 5.18.0 requests 1.17.5, and the lower one wins.
   
   **Why.** Log4j is a library. Maven consults the `dependencyManagement` of 
the project being built only. When an application depends on a Log4j module, 
the management section inherited from `log4j-parent` is not consulted while 
resolving that module's transitive dependencies, so these pins never reached 
users. They only changed the versions resolved in our own build and gave a 
misleading picture of what consumers get. The property block's header now 
states that pins are kept only when the enforcer fails without them.
   
   **Notes.** `log4j-core-test` on `main` depends on the released 
`log4j-api-test` 2.24.3, which still pulls `maven-core` and guava at compile 
scope; that path goes away once a 2.x release containing #4281 is used here. 
Without the guava pin, `log4j-core-test` resolves `failureaccess` 1.0.2 while 
guava 33.4.8-jre requests 1.0.3; the enforcer does not report it.
   
   No changelog entry, since nothing here is visible to users.
   
   🤖 Generated with [Claude Code](https://claude.com/claude-code)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to