maven-dependency-plugin icon indicating copy to clipboard operation
maven-dependency-plugin copied to clipboard

[MDEP-976] Fix artifact overwrites in copy-dependencies

Open Ndacyayisenga-droid opened this issue 7 months ago • 6 comments

Fixes https://issues.apache.org/jira/browse/MDEP-976

cc @hboutemy

Following this checklist to help us incorporate your contribution quickly and easily:

  • [x] Make sure there is a JIRA issue filed for the change (usually before you start working on it). Trivial changes like typos do not require a JIRA issue. Your pull request should address just this issue, without pulling in other changes.
  • [ ] Each commit in the pull request should have a meaningful subject line and body.
  • [ ] Format the pull request title like [MDEP-XXX] - Fixes bug in ApproximateQuantiles, where you replace MDEP-XXX with the appropriate JIRA issue. Best practice is to use the JIRA issue title in the pull request title and in the first line of the commit message.
  • [ ] Write a pull request description that is detailed enough to understand what the pull request does, how, and why.
  • [ ] Run mvn clean verify to make sure basic checks pass. A more thorough check will be performed on your pull request automatically.
  • [ ] You have run the integration tests successfully (mvn -Prun-its clean verify).

If your pull request is about ~20 lines of code you don't need to sign an Individual Contributor License Agreement if you are unsure please ask on the developers list.

To make clear that you license your contribution under the Apache License Version 2.0, January 2004 you have to acknowledge this by using the following check-box.

Ndacyayisenga-droid avatar Apr 23 '25 03:04 Ndacyayisenga-droid

@Ndacyayisenga-droid please take time to review the checkboxes in the issue description and fill them as necessary: keeping them not checked is not useful

on adding a new option just for copy-dependencies, I'm not clear: why? prependGroupId is the configuration the user did not know about

I'd prefer either we change the default value for prependGroupId, or we add code to detect when conflict happens and WARN with a hint on how to configure prependGroupId

hboutemy avatar Apr 29 '25 07:04 hboutemy

notice: IIUC, the conflict happens only when stripVersion is enable, isn't it? then WARN if not stripVersion, because it warns about 2 groupIds that you can't really differentiate and ERROR if this leads to overwrite, as it is better to fail the build than keep a silent conflicted file overwritten

WDYT of this behaviour poposal?

hboutemy avatar Apr 29 '25 07:04 hboutemy

@hboutemy It's possible for two different artifacts to have the same artifactId and version even though their groupId is different, isn't it?

cowwoc avatar Apr 29 '25 13:04 cowwoc

notice: IIUC, the conflict happens only when stripVersion is enable, isn't it? then WARN if not stripVersion, because it warns about 2 groupIds that you can't really differentiate and ERROR if this leads to overwrite, as it is better to fail the build than keep a silent conflicted file overwritten

WDYT of this behaviour poposal?

@hboutemy this might cause a lot of build failures, especially in cases where two different artifacts share the same artifactId. I'm not sure. Is it actually valid in Maven for two different artifacts to have the same artifactId but different groupIds?.

I tried to reproduce the issue in this projecct https://github.com/Ndacyayisenga-droid/mdep-976 (just execute the script).

results Current version Screenshot 2025-04-30 at 10 24 38

For my snapshot Screenshot 2025-04-30 at 10 22 11

Ndacyayisenga-droid avatar Apr 30 '25 07:04 Ndacyayisenga-droid

It absolutely is valid in Maven for two different artifacts to have the same artifact ID but different group IDs. Artifact IDs are not unique or intended to be. In fact, this is common with forked projects and likely occurs with other common artifact IDs like "utils".

elharo avatar May 05 '25 11:05 elharo

Resolve #1476

jira-importer avatar Jun 18 '25 08:06 jira-importer