GoogleCloudPlatform / GoogleCloudPlatform/cloud-opensource-java

Libraries BOM to check version range constraints

未关闭
#863 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
enhancement p3
主要语言
Java
星标
163
派生
80
PR 合并指标
30 天内没有已合并 PR

描述

Does Google Libraries BOM detects version range constraints violation?

Maven's version range constraints might throw error when building a project

https://github.com/GoogleCloudPlatform/cloud-opensource-java/issues/862#issuecomment-526640587 shows following error:

```
[ERROR] Failed to execute goal on project spike-metrics: Could not resolve dependencies for project com.google.igorbernstein:spike-metrics:jar:1.0-SNAPSHOT: Failed to collect dependencies for com.google.igorbernstein:spike-metrics:jar:1.0-SNAPSHOT:
Could not resolve version conflict among
...
com.google.cloud:google-cloud-bigtable:jar:0.107.0
-> com.google.cloud:google-cloud-core-grpc:jar:1.89.0
-> com.google.api:gax-grpc:jar:1.48.0
-> io.grpc:grpc-alts:jar:1.23.0
-> io.grpc:grpc-core:jar:[1.23.0,1.23.0],

io.opencensus:opencensus-exporter-stats-stackdriver:jar:0.23.0
-> io.grpc:grpc-auth:jar:1.19.0
-> io.grpc:grpc-core:jar:[1.19.0,1.19.0],
```

As of now opencensus-exporter-stats-stackdriver is not included in the BOM, but are there any other libraries that fails at this version constraints? Should we have a tool to verify this?

# Consideration

- Not many libraries use version range constraints. We have JLBP saying they should be avoided.
- Grpc uses verison range constraint. Because the BOM contains grpc-bom, grpc's constraints are not problem.

贡献指南

打开贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。