GoogleCloudPlatform / GoogleCloudPlatform/cloud-opensource-java

Avoid unactionable dependency update suggestions

オープン
#133 コメント 1 件 リアクション 0 件 担当者 0 名 GitHub で見る
bug p2
主要言語
Java
スター
163
フォーク
80
PR マージ指標
30日以内にマージされた PR はありません

説明

For example, in the grpc-auth report:

```
https://storage.googleapis.com/cloud-opensource-java-dashboard/dashboard/target/dashboard/io.grpc_grpc-auth_1.15.1.html
```

It makes this recommendation:

```
com.google.guava:guava:20.0 needs to upgrade com.google.code.findbugs:jsr305:1.3.9 to 3.0.1
```

But, Guava has already upgraded to 3.0.2: https://github.com/google/guava/blob/95521f78d442084e2d9ebd6e2d096a834caccdad/pom.xml#L220

Basically, if a direct dependency is old (Guava 20.0 is pretty far behind 26.0-android), telling people to update its transitive dependencies is unhelpful.

We can probably call out sources of old transitive dependencies, but as for recommendations, they need to be made with respect to the most recent versions.

コントリビューションガイド

コントリビューションガイドを開く

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。