GoogleCloudPlatform / GoogleCloudPlatform/cloud-opensource-java
Dashboard and Linkage Checker to take option to resolve dependency graphs with Gradle's way
- 主要語言
- Java
- 星號
- 163
- 分支
- 80
- PR 合併指標
- 30 天內沒有已合併 PR
描述
Dashboard (and Linkage Checker's ClassPathBuilder) to take an option to resolve dependency graphs with Gradle's way.
While reading errors in https://github.com/GoogleCloudPlatform/cloud-opensource-java/pull/1982#issuecomment-812277520, I noticed that the dependency conflicts (due to picking up old library versions) do not occur to Gradle users.
# Where is this affected?
The `LtsCompatibilityTestRunner` resolves the dependencies of the BOM:
```
ImmutableList bomManagedDependencies = bom.getManagedDependencies();
ClassPathBuilder classPathBuilder = new ClassPathBuilder();
ClassPathResult resolvedDependencies = classPathBuilder.resolve(bomManagedDependencies, false);
```
This resolves the dependencies in Maven's closest-win strategy. This strategy is prone to getting old dependencies which cause dependency conflicts. For Gradle users, the resolution is different; it uses highest-win strategy. Therefore, the current result shown in the pull request contain false positives and false negatives.
# GradleDependencyMediation?
We already have `MavenDependencyMediation`. I think the implementation would be creating GradleDependencyMediation.
貢獻指南
評估
這個 Issue 還沒有評估資料。