GoogleCloudPlatform / GoogleCloudPlatform/cloud-opensource-java

Discussion: tool for noticing difference between BOM and explicit dependencies

Abierto
#1,078 2 comentarios 0 reacciones 0 asignados Ver en GitHub
blocked documentation enhancement good first issue help wanted
Lenguaje dominante
Java
Estrellas
163
Forks
80
Métricas de merge de PR
Sin PR fusionados en 30 d

Descripción

Customer issues in b/146130570 are making me think it might be too hard in large projects that extend past GCP to tell which versions can and cannot be set by the BOM. Two ideas:

1. Docs listing what's covered in the BOM.
2. An automated tool to suggest changes to a pom.xml when a dependency has an explicit version that is also set by the BOM.

Perhaps an enforcer rule could warn about #2?

**DO NOT START IMPLEMENTING THIS. IT HAS NOT BEEN PRIORITIZED OR PLANNED. THIS IS FOR DISCUSSION ONLY**

Guía de contribución

Abrir la guía de contribución

Evaluación

Este issue todavía no se ha evaluado.

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.