This is an automated email from the ASF dual-hosted git repository.
gnodet pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/camel.git
The following commit(s) were added to refs/heads/main by this push:
new abff56356bb8 CAMEL-22967: Add dep-check profile using
pilot:dependencies
abff56356bb8 is described below
commit abff56356bb86c9a16458ebd2bb0ccc2f5c151bf
Author: Guillaume Nodet <[email protected]>
AuthorDate: Wed Sep 23 14:28:44 2026 +0200
CAMEL-22967: Add dep-check profile using pilot:dependencies
- Add opt-in `-Pdep-check` Maven profile in root pom.xml configuring
pilot-plugin 0.3.0 in pluginManagement with ignore-lists for known
intentional noise (log4j runtime deps, JUnit aggregator)
- Add GitHub Actions workflow dep-check.yml: test-compile then
pilot:dependencies, non-blocking (continue-on-error: true), report
uploaded as artifact
- Update building.adoc docs with new usage pattern and examples
---
.github/workflows/dep-check.yml | 313 +++++++++++++++++++++
core/camel-java-io/pom.xml | 27 ++
core/camel-xml-io/pom.xml | 29 +-
core/camel-yaml-io/pom.xml | 27 ++
docs/main/modules/contributing/pages/building.adoc | 37 ++-
.../camel-yaml-dsl-deserializers/pom.xml | 27 ++
dsl/camel-yaml-dsl/camel-yaml-dsl/pom.xml | 36 +++
pom.xml | 37 +++
tests/test-bundles/pom.xml | 2 +-
9 files changed, 532 insertions(+), 3 deletions(-)
diff --git a/.github/workflows/dep-check.yml b/.github/workflows/dep-check.yml
new file mode 100644
index 000000000000..ac52fbeaf68f
--- /dev/null
+++ b/.github/workflows/dep-check.yml
@@ -0,0 +1,313 @@
+#
+# Licensed to the Apache Software Foundation (ASF) under one or more
+# contributor license agreements. See the NOTICE file distributed with
+# this work for additional information regarding copyright ownership.
+# The ASF licenses this file to You under the Apache License, Version 2.0
+# (the "License"); you may not use this file except in compliance with
+# the License. You may obtain a copy of the License at
+#
+# http://www.apache.org/licenses/LICENSE-2.0
+#
+# Unless required by applicable law or agreed to in writing, software
+# distributed under the License is distributed on an "AS IS" BASIS,
+# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+# See the License for the specific language governing permissions and
+# limitations under the License.
+#
+
+name: 'Dependency Analysis'
+
+on:
+ pull_request:
+ branches:
+ - main
+ paths-ignore:
+ - .claude-plugin/**
+ - .idea/**
+ - .github/**
+ - .oss-ai-helper-rules/**
+ - AGENTS.md
+ - README.md
+ - SECURITY.md
+ - Jenkinsfile
+ - Jenkinsfile.*
+ - NOTICE.txt
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.event.pull_request.number ||
github.ref }}
+ cancel-in-progress: true
+
+permissions:
+ contents: read
+
+jobs:
+ dep-check:
+ if: github.repository == 'apache/camel'
+ name: Dependency Analysis (non-blocking)
+ runs-on: ubuntu-latest
+ continue-on-error: true
+ env:
+ # Modules excluded from analysis — kept in one place so both the compile
and analysis steps stay in sync.
+ # See comments in the compile step below for the exclusion rationale.
+ # Also update pom.xml <pluginManagement> and
docs/main/modules/contributing/pages/building.adoc
+ # when changing the pilot-plugin version (0.4.0 below).
+ EXCLUDED_MODULES: >-
+ !bom,
+ !components/camel-spring-parent/camel-spring-xml,
+ !components/camel-test/camel-test-spring-junit5,
+ !components/camel-test/camel-test-spring-junit6,
+ !components/camel-cxf/camel-cxf-soap,
+ !components/camel-cxf/camel-cxf-rest,
+ !components/camel-cxf/camel-cxf-spring-common,
+ !components/camel-cxf/camel-cxf-spring-soap,
+ !components/camel-cxf/camel-cxf-spring-rest,
+ !components/camel-cxf/camel-cxf-spring-transport,
+ !components/camel-micrometer-observability,
+ !components/camel-telemetry-dev,
+ !components/camel-opentelemetry,
+ !components/camel-telemetry,
+ !components/camel-opentelemetry2,
+ !components/camel-ai/camel-ai-observability,
+ !components/camel-observability-services,
+ !components/camel-asn1,
+ !components/camel-debezium,
+
!components/camel-debezium/camel-debezium-common/camel-debezium-maven-plugin,
+ !tooling/maven/sync-properties-maven-plugin,
+ !dsl/camel-yaml-dsl/camel-yaml-dsl-maven-plugin,
+ !dsl/camel-endpointdsl-support
+ steps:
+ - name: Checkout
+ uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 #
v7.0.1
+ with:
+ ref: ${{ github.event.pull_request.head.sha }}
+ fetch-depth: 1
+
+ - name: Set up JDK 21
+ uses: actions/setup-java@dd06d9cba3e5552c54d9f8ea23572deb30010f7c #
v6.0.0
+ with:
+ distribution: 'temurin'
+ java-version: '21'
+ cache: 'maven'
+
+ - name: Install SNAPSHOT build plugins
+ run: |
+ # camel-package-maven-plugin is a SNAPSHOT reactor artifact used as
a build plugin
+ # by dozens of modules (core, dsl, components, catalog…). Maven
cannot parse its
+ # plugin descriptor in a clean CI checkout because the plugin has
not been compiled yet.
+ # Installing it (and its SNAPSHOT dependencies) before the main
compile step makes the
+ # descriptor available in the local repository for the rest of the
build.
+ # camel-api-component-maven-plugin is a SNAPSHOT reactor artifact
used as a build plugin
+ # by camel-fhir, camel-olingo4, camel-braintree, camel-google-*,
camel-twilio and
+ # other API-component modules. It shares the camel-tooling-util
dependency with
+ # camel-package-maven-plugin, so --also-make covers both in a single
reactor walk.
+ # camel-debezium-maven-plugin is a SNAPSHOT reactor artifact used as
a build plugin
+ # by the debezium connector modules (camel-debezium-mysql,
-postgres, etc.).
+ # Maven's --pl ! notation excludes a module by its exact path — it
does NOT
+ # recursively exclude submodules discovered through the parent's
<modules>.
+ # camel-debezium-maven-plugin lives at a 4-level path and remains in
the reactor
+ # even when !components/camel-debezium is specified. Maven then
picks it up from
+ # target/classes, where META-INF/maven/plugin.xml has not yet been
generated
+ # (that happens at process-classes, not compile). Installing it here
and excluding
+ # it via EXCLUDED_MODULES causes Maven to use the .m2 version (with
correct
+ # plugin.xml) instead of the reactor target/classes version.
+ # camel-yaml-dsl-maven-plugin is a SNAPSHOT reactor artifact used as
a build plugin
+ # by camel-yaml-dsl and camel-yaml-dsl-deserializers at
generate-sources phase.
+ # Same root cause as camel-debezium-maven-plugin — installed here
and excluded via
+ # EXCLUDED_MODULES so Maven uses the .m2 version (with correct
plugin.xml).
+ # sync-properties-maven-plugin is a SNAPSHOT reactor artifact used
by camel-dependencies
+ # at generate-resources phase. Same root cause as
camel-debezium-maven-plugin — installed
+ # here and excluded via EXCLUDED_MODULES so Maven uses the .m2
version.
+ mvn install \
+ -pl
tooling/maven/camel-package-maven-plugin,tooling/maven/camel-api-component-maven-plugin,components/camel-debezium/camel-debezium-common/camel-debezium-maven-plugin,tooling/maven/sync-properties-maven-plugin,dsl/camel-yaml-dsl/camel-yaml-dsl-maven-plugin
\
+ --also-make \
+ -DskipTests -Dlicense.skip -Dquickly \
+ --no-transfer-progress --batch-mode -q
+
+ - name: Install SNAPSHOT stubs
+ run: |
+ # Maven resolves ALL declared dependency scopes (including
test-scope and provided) even
+ # during 'mvn compile', because it builds the complete dependency
graph upfront. Several
+ # SNAPSHOT artifacts that are excluded from the reactor are declared
as dependencies in
+ # modules throughout the reactor. These SNAPSHATs are not published
to Maven Central and
+ # cannot be built in a clean checkout without installing a large
portion of camel-core first.
+ #
+ # Fix: install empty stub JARs (no classes, no transitive
dependencies) for each such
+ # artifact so Maven finds them in the local repository and does not
attempt remote
+ # resolution. The stubs are safe because:
+ # • 'mvn compile' does not compile test sources, so test-scope
JARs are never on
+ # the compile classpath and empty stubs cause no compilation
errors.
+ # • pilot:dependencies with -Dpilot.skipTestScope=true ignores
test-scope artifacts
+ # entirely, so the stubs do not affect the analysis results.
+ # • provided-scope stubs (camel-allcomponents transitive deps in
camel-endpointdsl):
+ # camel-endpointdsl uses camel-allcomponents as a provided pom
to make all component
+ # endpoints available for DSL generation (the regen profile).
With -Dquickly, regen is
+ # inactive, so none of the excluded components' classes are
actually imported by
+ # camel-endpointdsl's own sources. Empty stubs satisfy Maven's
dependency resolution
+ # without introducing false positives in the pilot analysis.
+ # • camel-endpointdsl itself: its default-compile execution is
disabled (phase:none) so
+ # mvn compile produces no JAR for it. camel-endpointdsl-support
has a compile-scope
+ # dependency on camel-endpointdsl and needs to resolve it during
Maven's dependency
+ # graph construction. An empty stub satisfies that requirement
without triggering
+ # compilation of the generated CXF-referencing sources.
+ # • camel-endpointdsl-support: it is excluded from the reactor
(see EXCLUDED_MODULES)
+ # because it has a compile-scope dependency on
camel-endpointdsl, which produces no
+ # class files (default-compile is bound to phase:none). javac
cannot compile
+ # EndpointRouteBuilderLoaderSupport.java against an empty
target/classes directory.
+ # An empty stub installed here lets any downstream module that
declares
+ # camel-endpointdsl-support as a dependency resolve it during
graph construction.
+ VERSION=$(mvn help:evaluate -Dexpression=project.version -q
-DforceStdout)
+ mkdir -p /tmp/stub-classes
+ jar cf /tmp/stub.jar -C /tmp/stub-classes .
+ for ARTIFACT in \
+ camel-spring-xml \
+ camel-test-spring-junit6 \
+ camel-endpointdsl \
+ camel-endpointdsl-support \
+ "camel-cxf/camel-cxf-soap:camel-cxf-soap" \
+
"camel-cxf/camel-cxf-spring-transport:camel-cxf-spring-transport" \
+ "camel-ai/camel-ai-observability:camel-ai-observability" \
+ camel-asn1 \
+ "camel-cxf/camel-cxf-rest:camel-cxf-rest" \
+ "camel-cxf/camel-cxf-spring-common:camel-cxf-spring-common" \
+ "camel-cxf/camel-cxf-spring-rest:camel-cxf-spring-rest" \
+ "camel-cxf/camel-cxf-spring-soap:camel-cxf-spring-soap" \
+ camel-micrometer-observability \
+ camel-observability-services \
+ camel-opentelemetry \
+ camel-opentelemetry2 \
+ camel-telemetry \
+ camel-telemetry-dev \
+ "camel-test/camel-test-spring-junit5:camel-test-spring-junit5";
do
+ # Split "path:artifactId" or use artifact as both path and id
+ ARTIFACT_ID="${ARTIFACT##*:}"
+ cat > /tmp/stub.pom << EOF
+ <project>
+ <modelVersion>4.0.0</modelVersion>
+ <groupId>org.apache.camel</groupId>
+ <artifactId>${ARTIFACT_ID}</artifactId>
+ <version>${VERSION}</version>
+ </project>
+ EOF
+ mvn install:install-file \
+ -Dfile=/tmp/stub.jar \
+ -DpomFile=/tmp/stub.pom \
+ -DgroupId=org.apache.camel \
+ -DartifactId="${ARTIFACT_ID}" \
+ -Dversion="${VERSION}" \
+ -Dpackaging=jar \
+ --no-transfer-progress --batch-mode -q
+ done
+
+ - name: Compile
+ run: |
+ # bom is excluded: bom/pom.xml uses bom-generator-maven-plugin (a
SNAPSHOT reactor artifact)
+ # as a build plugin. Maven cannot parse its plugin descriptor in a
clean CI checkout
+ # (the plugin has not been compiled yet). BOM modules have no Java
sources to analyze anyway.
+ # camel-xml-io: its camel-package-maven-plugin
'generate-xml-sources' execution
+ # runs at generate-sources phase and reads
camel-core-model/target/classes/META-INF/jandex.idx,
+ # which is produced at process-classes phase — not available in a
clean CI checkout.
+ # The dep-check profile in camel-xml-io/pom.xml binds that execution
to phase=none,
+ # letting the pre-committed sources in src/generated/java be used
directly.
+ # camel-spring-xml is excluded: it unpacks SNAPSHOT source JARs
(camel-api:sources, etc.)
+ # during process-resources, which are not available in a clean CI
checkout without a
+ # prior mvn install. The XSD it generates is pre-committed, so
skipping it here is safe.
+ # Modules that declare camel-spring-xml as a test dependency are
handled by the
+ # "Install SNAPSHOT stubs" step above.
+ # camel-test-spring-junit5 is excluded: it has a compile dependency
on camel-spring-xml.
+ # camel-test-spring-junit6 is excluded: it has a compile dependency
on camel-spring-xml.
+ # Modules that declare camel-test-spring-junit6 as a test dependency
(94+ modules) are
+ # handled by the "Install SNAPSHOT stubs" step above.
+ # camel-yaml-io: its 'generate-sources' execution reads jandex.idx
(same root cause as
+ # camel-xml-io). The dep-check profile in camel-yaml-io/pom.xml
binds that execution
+ # to phase=none, letting the pre-committed YamlModelWriter.java be
used directly
+ # without regeneration.
+ # camel-java-io: its 'generate-sources' execution reads jandex.idx
(same root cause as
+ # camel-xml-io). The dep-check profile in camel-java-io/pom.xml
binds that execution
+ # to phase=none, letting the pre-committed JavaDslModelWriter.java
be used directly
+ # without regeneration.
+ # camel-cxf-soap, camel-cxf-rest, camel-cxf-spring-soap,
camel-cxf-spring-rest are excluded:
+ # they all declare a test-scope dependency on
camel-cxf-common:test-jar, which Maven resolves
+ # even during mvn compile. The test-jar is produced at the 'package'
phase and is not
+ # available in the local repository in a clean CI checkout (only mvn
install would put it
+ # there, and running --also-make for camel-cxf-common would require
compiling all of
+ # camel-core, making CI prohibitively slow).
+ # camel-soap declares camel-cxf-soap and camel-cxf-spring-transport
as test-scope
+ # dependencies; these are handled by the "Install SNAPSHOT stubs"
step above.
+ # camel-cxf-spring-common is excluded: it has a compile-scope
dependency on camel-spring-xml,
+ # which is itself excluded (see above). Maven cannot resolve
camel-spring-xml's jar during
+ # compile when camel-spring-xml is not part of the reactor subset.
+ # camel-cxf-spring-transport is excluded: it has a compile-scope
dependency on
+ # camel-cxf-spring-common, which is itself excluded (see above).
+ # camel-micrometer-observability, camel-telemetry-dev,
camel-opentelemetry, camel-telemetry,
+ # camel-opentelemetry2 are excluded for the same reason: they also
declare test-scope deps
+ # on camel-cxf-common:test-jar.
+ # camel-observability-services is excluded: it has a compile-scope
dependency on
+ # camel-opentelemetry2, which is itself excluded (see above).
+ # camel-ai-observability is excluded: it has a compile-scope
dependency on camel-telemetry,
+ # which is itself excluded (see above). Maven cannot resolve
camel-telemetry's jar during
+ # compile when camel-telemetry is not part of the reactor subset.
+ # camel-asn1 is excluded: it declares test-scope dependencies on
camel-spring-xml and
+ # camel-test-spring-junit6, both of which are excluded from the
reactor (see above).
+ # Maven resolves test-scope dependencies even during mvn compile
when those artifacts are
+ # not available in the local repository.
+ # camel-debezium is excluded: camel-debezium-maven-plugin is a
SNAPSHOT Maven plugin that
+ # lives inside the reactor. The connector modules
(camel-debezium-mysql, -postgres, etc.)
+ # use it as a build plugin at generate-sources phase. Maven's --pl !
notation excludes a
+ # module by its exact relative path — it does NOT recursively
exclude submodules discovered
+ # through the parent's <modules>. !components/camel-debezium
excludes the parent pom, but
+ # the plugin at the 4-level path
components/camel-debezium/camel-debezium-common/
+ # camel-debezium-maven-plugin remains in the reactor and is picked
up from target/classes.
+ # At compile phase, maven-plugin-plugin has not yet generated
META-INF/maven/plugin.xml
+ # (that happens at process-classes), so Maven cannot parse the
plugin descriptor and the
+ # build fails. The plugin is pre-installed by the "Install SNAPSHOT
build plugins" step
+ # and also excluded from the reactor via EXCLUDED_MODULES so Maven
uses the .m2 version.
+ # sync-properties-maven-plugin is excluded for the same reason: it
is a SNAPSHOT reactor
+ # plugin used by camel-dependencies at generate-resources phase.
Pre-installing it and
+ # excluding it via EXCLUDED_MODULES lets Maven use the .m2 version
(with correct plugin.xml).
+ # camel-yaml-dsl-maven-plugin is excluded for the same reason: it is
a SNAPSHOT reactor
+ # plugin used by camel-yaml-dsl and camel-yaml-dsl-deserializers at
generate-sources phase.
+ # Pre-installing it and excluding it via EXCLUDED_MODULES lets Maven
use the .m2 version.
+ # camel-yaml-dsl and camel-yaml-dsl-deserializers each have a
dep-check profile that binds
+ # the camel-yaml-dsl-maven-plugin executions to phase=none (the
mojos read jandex.idx,
+ # which is not available in a clean CI checkout). The generated
sources/resources are
+ # pre-committed, so skipping regeneration is safe.
+ # camel-endpointdsl: its main build disables default-compile
(phase:none); there is no
+ # dep-check profile to re-enable it (unlike
camel-endpointdsl-support). This means the
+ # compile step is a no-op for this module (same as
camel-componentdsl). The reason we
+ # do NOT re-enable compilation is that the pre-committed generated
sources in
+ # src/generated/java (CxfEndpointBuilderFactory.java,
CxfRsEndpointBuilderFactory.java,
+ # etc.) import types from camel-cxf-soap
(org.apache.camel.component.cxf.jaxws) and
+ # camel-cxf-rest (org.apache.camel.component.cxf.jaxrs), which are
excluded from the
+ # reactor. The "Install SNAPSHOT stubs" step installs empty JARs for
those artifacts,
+ # which satisfies Maven's dependency resolution, but empty JARs
contain no class files —
+ # the javac compiler would fail with "package does not exist".
Keeping default-compile
+ # disabled avoids this problem; the "Install SNAPSHOT stubs" step
still installs stubs
+ # for all transitive provided/test deps so Maven's dependency graph
resolution succeeds.
+ # camel-endpointdsl-support is excluded: it has a compile-scope
dependency on
+ # camel-endpointdsl, whose default-compile is bound to phase:none
(see above). Maven
+ # includes camel-endpointdsl in the reactor but produces no class
files for it, so
+ # javac fails when compiling camel-endpointdsl-support's sources
against an empty
+ # target/classes directory. Excluding it from the reactor and
installing an empty stub
+ # (see "Install SNAPSHOT stubs") is the simplest fix; no other
included module depends
+ # on camel-endpointdsl-support at compile scope.
+ # Test-scope analysis is skipped (pilot.skipTestScope=true):
compile-scope analysis alone
+ # is sufficient for detecting missing or unused deps.
+ mvn compile -Pdep-check -Dlicense.skip -Dquickly \
+ --pl "$EXCLUDED_MODULES" \
+ --no-transfer-progress --batch-mode -q
+
+ - name: Run dependency analysis
+ run: |
+ mvn eu.maveniverse.maven.plugins:pilot-plugin:0.4.0:dependencies \
+ -Pdep-check -Dpilot.skipTestScope=true -Dlicense.skip \
+ --pl "$EXCLUDED_MODULES" \
+ --no-transfer-progress --batch-mode \
+ 2>&1 | tee dep-check-output.txt
+
+ - name: Upload dependency analysis report
+ if: always()
+ uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a
# v7.0.1
+ with:
+ name: dep-check-report
+ path: dep-check-output.txt
+ retention-days: 7
diff --git a/core/camel-java-io/pom.xml b/core/camel-java-io/pom.xml
index 43d6f8758832..929e930007ff 100644
--- a/core/camel-java-io/pom.xml
+++ b/core/camel-java-io/pom.xml
@@ -90,4 +90,31 @@
</plugins>
</build>
+ <profiles>
+ <profile>
+ <!--
+ dep-check profile: disable generate-java-dsl-writer at
generate-sources phase.
+ The mojo reads
camel-core-model/target/classes/META-INF/jandex.idx, which is
+ produced at process-classes phase and is not available in a
clean CI checkout
+ when only compile phase is run. The generated
JavaDslModelWriter.java is
+ pre-committed in src/generated/java, so skipping generation
here is safe.
+ -->
+ <id>dep-check</id>
+ <build>
+ <plugins>
+ <plugin>
+ <groupId>org.apache.camel</groupId>
+ <artifactId>camel-package-maven-plugin</artifactId>
+ <executions>
+ <execution>
+ <id>generate-sources</id>
+ <phase>none</phase>
+ </execution>
+ </executions>
+ </plugin>
+ </plugins>
+ </build>
+ </profile>
+ </profiles>
+
</project>
diff --git a/core/camel-xml-io/pom.xml b/core/camel-xml-io/pom.xml
index ec85b4972015..db065ba8d070 100644
--- a/core/camel-xml-io/pom.xml
+++ b/core/camel-xml-io/pom.xml
@@ -96,7 +96,7 @@
<artifactId>camel-package-maven-plugin</artifactId>
<executions>
<execution>
- <id>generate-sources</id>
+ <id>generate-xml-sources</id>
<phase>generate-sources</phase>
<goals>
<goal>generate-xml-parser</goal>
@@ -281,4 +281,31 @@
</plugins>
</build>
+ <profiles>
+ <profile>
+ <!--
+ dep-check profile: disable generate-xml-sources at
generate-sources phase.
+ The mojo reads
camel-core-model/target/classes/META-INF/jandex.idx, which is
+ produced at process-classes phase and is not available in a
clean CI checkout
+ when only compile phase is run. The generated XML
parser/writer sources are
+ pre-committed in src/generated/java, so skipping generation
here is safe.
+ -->
+ <id>dep-check</id>
+ <build>
+ <plugins>
+ <plugin>
+ <groupId>org.apache.camel</groupId>
+ <artifactId>camel-package-maven-plugin</artifactId>
+ <executions>
+ <execution>
+ <id>generate-xml-sources</id>
+ <phase>none</phase>
+ </execution>
+ </executions>
+ </plugin>
+ </plugins>
+ </build>
+ </profile>
+ </profiles>
+
</project>
diff --git a/core/camel-yaml-io/pom.xml b/core/camel-yaml-io/pom.xml
index 121305e9bac4..4ee47044c1a6 100644
--- a/core/camel-yaml-io/pom.xml
+++ b/core/camel-yaml-io/pom.xml
@@ -107,4 +107,31 @@
</plugins>
</build>
+ <profiles>
+ <profile>
+ <!--
+ dep-check profile: disable generate-yaml-writer at
generate-sources phase.
+ The mojo reads
camel-core-model/target/classes/META-INF/jandex.idx, which is
+ produced at process-classes phase and is not available in a
clean CI checkout
+ when only compile phase is run. The generated
YamlModelWriter.java is
+ pre-committed in src/generated/java, so skipping generation
here is safe.
+ -->
+ <id>dep-check</id>
+ <build>
+ <plugins>
+ <plugin>
+ <groupId>org.apache.camel</groupId>
+ <artifactId>camel-package-maven-plugin</artifactId>
+ <executions>
+ <execution>
+ <id>generate-sources</id>
+ <phase>none</phase>
+ </execution>
+ </executions>
+ </plugin>
+ </plugins>
+ </build>
+ </profile>
+ </profiles>
+
</project>
diff --git a/docs/main/modules/contributing/pages/building.adoc
b/docs/main/modules/contributing/pages/building.adoc
index b3cba3b169e8..a18c0599cdaf 100644
--- a/docs/main/modules/contributing/pages/building.adoc
+++ b/docs/main/modules/contributing/pages/building.adoc
@@ -159,4 +159,39 @@ For instance, if you do some code changes in the camel-ftp
component, following
----
cd camel-ftp
mvn clean install -Psourcecheck
-----
\ No newline at end of file
+----
+
+== Checking dependency hygiene
+
+The opt-in `-Pdep-check` profile leverages
https://github.com/maveniverse/pilot[`pilot:dependencies`] for bytecode-level
detection of *used-but-undeclared* and *unused-but-declared* dependencies.
+It is non-blocking by default (report mode), so it only prints findings
without failing the build.
+
+The mojo requires compiled classes.
+Run `compile` first (test-scope analysis is skipped by default, since many
modules depend on
+`camel-test-spring-junit6` which is not resolvable in a clean checkout without
a prior install):
+
+[source,bash]
+----
+# Full reactor — report mode (default, compile-scope only)
+mvn compile eu.maveniverse.maven.plugins:pilot-plugin:0.4.0:dependencies
-Pdep-check -Dpilot.skipTestScope=true -Dlicense.skip -Dquickly
+
+# Single module — includes test-scope (camel-test-spring-junit6 is available
after a local install)
+mvn test-compile eu.maveniverse.maven.plugins:pilot-plugin:0.4.0:dependencies
-Pdep-check
+----
+
+Or on a single module:
+
+[source,bash]
+----
+cd components/camel-ftp
+mvn compile eu.maveniverse.maven.plugins:pilot-plugin:0.4.0:dependencies
-Pdep-check -Dpilot.skipTestScope=true
+----
+
+To fail the build on findings:
+
+[source,bash]
+----
+mvn compile eu.maveniverse.maven.plugins:pilot-plugin:0.4.0:dependencies
-Pdep-check -Dpilot.skipTestScope=true -Dpilot.action=check
+----
+
+CI also runs this profile automatically on pull requests targeting `main` (see
the *Dependency Analysis* workflow).
\ No newline at end of file
diff --git a/dsl/camel-yaml-dsl/camel-yaml-dsl-deserializers/pom.xml
b/dsl/camel-yaml-dsl/camel-yaml-dsl-deserializers/pom.xml
index 88ea0e465d68..47afea3a7447 100644
--- a/dsl/camel-yaml-dsl/camel-yaml-dsl-deserializers/pom.xml
+++ b/dsl/camel-yaml-dsl/camel-yaml-dsl-deserializers/pom.xml
@@ -118,4 +118,31 @@
</plugins>
</build>
+ <profiles>
+ <profile>
+ <!--
+ dep-check profile: disable camel-yaml-dsl-maven-plugin
generate-sources execution.
+ The generate-yaml-deserializers mojo reads META-INF/jandex.idx
from the classpath
+ of compiled reactor artifacts, which are not available in a
clean CI checkout when
+ only the compile phase is run. The generated deserializer
sources are pre-committed
+ in src/generated/java, so skipping regeneration here is safe.
+ -->
+ <id>dep-check</id>
+ <build>
+ <plugins>
+ <plugin>
+ <groupId>org.apache.camel</groupId>
+ <artifactId>camel-yaml-dsl-maven-plugin</artifactId>
+ <executions>
+ <execution>
+ <id>default</id>
+ <phase>none</phase>
+ </execution>
+ </executions>
+ </plugin>
+ </plugins>
+ </build>
+ </profile>
+ </profiles>
+
</project>
diff --git a/dsl/camel-yaml-dsl/camel-yaml-dsl/pom.xml
b/dsl/camel-yaml-dsl/camel-yaml-dsl/pom.xml
index 7c9fbb7ba19e..f064d0132cf5 100644
--- a/dsl/camel-yaml-dsl/camel-yaml-dsl/pom.xml
+++ b/dsl/camel-yaml-dsl/camel-yaml-dsl/pom.xml
@@ -307,4 +307,40 @@
</plugins>
</build>
+ <profiles>
+ <profile>
+ <!--
+ dep-check profile: disable camel-yaml-dsl-maven-plugin
generate-sources executions.
+ The mojos (generate-yaml-schema, generate-yaml-completion) read
+ META-INF/jandex.idx from the classpath of compiled reactor
artifacts, which are
+ not available in a clean CI checkout when only the compile
phase is run.
+ The generated schema/completion JSON files are pre-committed in
+ src/generated/resources/schema/, so skipping regeneration here
is safe.
+ -->
+ <id>dep-check</id>
+ <build>
+ <plugins>
+ <plugin>
+ <groupId>org.apache.camel</groupId>
+ <artifactId>camel-yaml-dsl-maven-plugin</artifactId>
+ <executions>
+ <execution>
+ <id>generate-yaml-schema-camelCase</id>
+ <phase>none</phase>
+ </execution>
+ <execution>
+ <id>generate-yaml-schema-canonical</id>
+ <phase>none</phase>
+ </execution>
+ <execution>
+ <id>generate-yaml-completion</id>
+ <phase>none</phase>
+ </execution>
+ </executions>
+ </plugin>
+ </plugins>
+ </build>
+ </profile>
+ </profiles>
+
</project>
diff --git a/pom.xml b/pom.xml
index a5c14475323c..73d8bb9e5fa2 100644
--- a/pom.xml
+++ b/pom.xml
@@ -992,6 +992,43 @@
</pluginRepository>
</pluginRepositories>
</profile>
+ <profile>
+ <!--
+ Opt-in dependency analysis profile.
+ Usage: mvn compile pilot:dependencies -Pdep-check
-Dpilot.skipTestScope=true [-Dpilot.action=check]
+ Leverages
eu.maveniverse.maven.plugins:pilot-plugin:dependencies for
+ bytecode-level analysis: detects unused declared and used
transitive deps.
+ Non-blocking by default (report mode); use
-Dpilot.action=check to fail
+ the build on findings, or -Dpilot.action=fix to apply fixes to
pom.xml.
+ Use -Dpilot.skipTestScope=true to skip test-scoped dependency
analysis.
+ -->
+ <id>dep-check</id>
+ <build>
+ <pluginManagement>
+ <plugins>
+ <plugin>
+ <groupId>eu.maveniverse.maven.plugins</groupId>
+ <artifactId>pilot-plugin</artifactId>
+ <version>0.4.0</version>
+ <configuration>
+ <ignoredUnusedDeclared>
+ <!-- Logging implementations are runtime
deps intentionally declared at compile scope -->
+
<ignoredUnusedDeclared>org.apache.logging.log4j:log4j-slf4j2-impl</ignoredUnusedDeclared>
+
<ignoredUnusedDeclared>org.apache.logging.log4j:log4j-core</ignoredUnusedDeclared>
+ <!-- JUnit aggregator is declared in
parent; code compiles against junit-jupiter-api -->
+
<ignoredUnusedDeclared>org.junit.jupiter:junit-jupiter</ignoredUnusedDeclared>
+ </ignoredUnusedDeclared>
+ <ignoredUsedTransitive>
+
<ignoredUsedTransitive>org.junit.jupiter:junit-jupiter-api</ignoredUsedTransitive>
+
<ignoredUsedTransitive>org.junit.jupiter:junit-jupiter-params</ignoredUsedTransitive>
+ </ignoredUsedTransitive>
+ </configuration>
+ </plugin>
+ </plugins>
+ </pluginManagement>
+ </build>
+ </profile>
+
<profile>
<!-- The full profile contains mojos *not* essential for the quick
build. -->
<!-- These are typically various source checks and code
generations whose result is stored in git anyway. -->
diff --git a/tests/test-bundles/pom.xml b/tests/test-bundles/pom.xml
index 0be504c4c3ee..7f4903f96af6 100644
--- a/tests/test-bundles/pom.xml
+++ b/tests/test-bundles/pom.xml
@@ -85,7 +85,7 @@
<executions>
<execution>
<id>copy-legal</id>
- <phase>generate-resources</phase>
+ <phase>initialize</phase>
<goals>
<goal>copy</goal>
</goals>