apache / apache/maven-dependency-analyzer

[MSHARED-1211] Source-only dependencies are not detected

Open
#216 2 comments 0 reactions 0 assignees View on GitHub
bug priority:major
Dominant language
Java
Stars
43
Forks
54
Avg merge
10h 49m
Merged PRs (30d)
1

Description

**[Richard Eckart de Castilho](https://issues.apache.org/jira/secure/ViewProfile.jspa?name=rec)** opened **[MSHARED-1211](https://issues.apache.org/jira/browse/MSHARED-1211?redirect=false)** and commented

If a class in the `src/main/java` part module A has a source-only dependency on a class in module B, the dependency dependency of A to B is not detected. This can lead to build failures if any class in the `src/main/test` part of module A also has dependencies on module B as the analyzer claims that the dependency of module B should be moved to the `test` scope. Doing so - however - then breaks the build.

One such source-only dependency would be the import of a compile-time constant (e.g. static final String = "XXX") from a class in module B. Such constants are inlined into the class file produced for the class of module A. Thus, the compile-time dependency on module B cannot be determined by inspecting the class file using ASM.

I guess the only way to fix this issue would be introducing another analyzer implementation which would look at the source files. Currently (1.13.0), the only implementation of the `ClassAnalyzer` interface is based on ASM (i.e. on inspecting class files).

---

**Affects:** maven-dependency-analyzer-1.13.0

**Issue Links:**
- [MDEP-846](https://issues.apache.org/jira/browse/MDEP-846) Source-only dependencies are not detected
(_**"is duplicated by"**_)

Contributor guide

No contributing guide indexed for this repository

Research direction

Start with the ClassAnalyzer interface and its ASM-based implementation in maven-dependency-analyzer 1.13.0, then inspect how dependencies from src/main/java and src/main/test are classified. Reproduce the compile-time constant case described in MSHARED-1211. Done means a source-only dependency from module A to module B is detected without incorrectly moving B to test scope.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
build-system
Issue type
Bug
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.