GoogleCloudPlatform / GoogleCloudPlatform/cloud-opensource-java

Libraries BOM to check version range constraints

Aberta
#863 0 comentários 0 reações 0 responsáveis Ver no GitHub
enhancement p3
Linguagem predominante
Java
Estrelas
163
Forks
80
Métricas de merge de PRs
Nenhum PR com merge em 30d

Descrição

Does Google Libraries BOM detects version range constraints violation?

Maven's version range constraints might throw error when building a project

https://github.com/GoogleCloudPlatform/cloud-opensource-java/issues/862#issuecomment-526640587 shows following error:

```
[ERROR] Failed to execute goal on project spike-metrics: Could not resolve dependencies for project com.google.igorbernstein:spike-metrics:jar:1.0-SNAPSHOT: Failed to collect dependencies for com.google.igorbernstein:spike-metrics:jar:1.0-SNAPSHOT:
Could not resolve version conflict among
...
com.google.cloud:google-cloud-bigtable:jar:0.107.0
-> com.google.cloud:google-cloud-core-grpc:jar:1.89.0
-> com.google.api:gax-grpc:jar:1.48.0
-> io.grpc:grpc-alts:jar:1.23.0
-> io.grpc:grpc-core:jar:[1.23.0,1.23.0],

io.opencensus:opencensus-exporter-stats-stackdriver:jar:0.23.0
-> io.grpc:grpc-auth:jar:1.19.0
-> io.grpc:grpc-core:jar:[1.19.0,1.19.0],
```

As of now opencensus-exporter-stats-stackdriver is not included in the BOM, but are there any other libraries that fails at this version constraints? Should we have a tool to verify this?

# Consideration

- Not many libraries use version range constraints. We have JLBP saying they should be avoided.
- Grpc uses verison range constraint. Because the BOM contains grpc-bom, grpc's constraints are not problem.

Guia de contribuição

Abrir o guia de contribuição

Avaliação

Esta issue ainda não foi avaliada.

Receba novas issues na sua caixa de entrada

Um resumo curto de issues do GitHub para quem está começando.