GoogleCloudPlatform / GoogleCloudPlatform/cloud-opensource-java

Libraries BOM to check version range constraints

オープン
#863 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る
enhancement p3
主要言語
Java
スター
163
フォーク
80
PR マージ指標
30日以内にマージされた PR はありません

説明

Does Google Libraries BOM detects version range constraints violation?

Maven's version range constraints might throw error when building a project

https://github.com/GoogleCloudPlatform/cloud-opensource-java/issues/862#issuecomment-526640587 shows following error:

```
[ERROR] Failed to execute goal on project spike-metrics: Could not resolve dependencies for project com.google.igorbernstein:spike-metrics:jar:1.0-SNAPSHOT: Failed to collect dependencies for com.google.igorbernstein:spike-metrics:jar:1.0-SNAPSHOT:
Could not resolve version conflict among
...
com.google.cloud:google-cloud-bigtable:jar:0.107.0
-> com.google.cloud:google-cloud-core-grpc:jar:1.89.0
-> com.google.api:gax-grpc:jar:1.48.0
-> io.grpc:grpc-alts:jar:1.23.0
-> io.grpc:grpc-core:jar:[1.23.0,1.23.0],

io.opencensus:opencensus-exporter-stats-stackdriver:jar:0.23.0
-> io.grpc:grpc-auth:jar:1.19.0
-> io.grpc:grpc-core:jar:[1.19.0,1.19.0],
```

As of now opencensus-exporter-stats-stackdriver is not included in the BOM, but are there any other libraries that fails at this version constraints? Should we have a tool to verify this?

# Consideration

- Not many libraries use version range constraints. We have JLBP saying they should be avoided.
- Grpc uses verison range constraint. Because the BOM contains grpc-bom, grpc's constraints are not problem.

コントリビューションガイド

コントリビューションガイドを開く

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。