GoogleCloudPlatform / GoogleCloudPlatform/cloud-opensource-java

Discussion: tool for noticing difference between BOM and explicit dependencies

未关闭
#1,078 2 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
blocked documentation enhancement good first issue help wanted
主要语言
Java
星标
163
派生
80
PR 合并指标
30 天内没有已合并 PR

描述

Customer issues in b/146130570 are making me think it might be too hard in large projects that extend past GCP to tell which versions can and cannot be set by the BOM. Two ideas:

1. Docs listing what's covered in the BOM.
2. An automated tool to suggest changes to a pom.xml when a dependency has an explicit version that is also set by the BOM.

Perhaps an enforcer rule could warn about #2?

**DO NOT START IMPLEMENTING THIS. IT HAS NOT BEEN PRIORITIZED OR PLANNED. THIS IS FOR DISCUSSION ONLY**

贡献指南

打开贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。