GoogleCloudPlatform / GoogleCloudPlatform/cloud-opensource-java

Avoid unactionable dependency update suggestions

Offen
#133 1 Kommentar 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
bug p2
Vorherrschende Sprache
Java
Sterne
163
Forks
80
PR-Merge-Kennzahlen
Keine gemergten PRs in 30 T.

Beschreibung

For example, in the grpc-auth report:

```
https://storage.googleapis.com/cloud-opensource-java-dashboard/dashboard/target/dashboard/io.grpc_grpc-auth_1.15.1.html
```

It makes this recommendation:

```
com.google.guava:guava:20.0 needs to upgrade com.google.code.findbugs:jsr305:1.3.9 to 3.0.1
```

But, Guava has already upgraded to 3.0.2: https://github.com/google/guava/blob/95521f78d442084e2d9ebd6e2d096a834caccdad/pom.xml#L220

Basically, if a direct dependency is old (Guava 20.0 is pretty far behind 26.0-android), telling people to update its transitive dependencies is unhelpful.

We can probably call out sources of old transitive dependencies, but as for recommendations, they need to be made with respect to the most recent versions.

Beitragsleitfaden

Beitragsleitfaden öffnen

Bewertung

Dieses Issue wurde noch nicht bewertet.

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.