apache / apache/druid

Track 3rd party libs used in the dist package

Open
#17,208 3 comments 0 reactions 0 assignees View on GitHub
Contributions Welcome Feature/Change Description
Dominant language
Java
Stars
14.1k
Forks
3.8k
Avg merge
2d 58m
Merged PRs (30d)
233

Description

### Description

It would be great to at least somehow track the 3rd party deps in a way that they need changes to the PR itself if new ones gets added - which will drag attention toward them and could possibly improve the situation.

### Motivation

It seems like there are quite a few versions of the same lib in the distribution build - these might have landed via transitive deps and most likely without being considered.

Contributor guide

Open the contributing guide

Research direction

The issue names no files, tests, or build entry points. Start by locating how the distribution package and its transitive dependencies are assembled, then determine how third-party libraries are currently declared. Done should mean the distribution dependencies are explicitly tracked and adding one requires a visible PR change.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
build-system
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.