dependabot[bot] opened a new pull request, #27086:
URL: https://github.com/apache/camel/pull/27086

   Bumps 
[eu.maveniverse.maven.plugins:pilot-plugin](https://github.com/maveniverse/pilot)
 from 0.4.0 to 0.5.0.
   <details>
   <summary>Release notes</summary>
   <p><em>Sourced from <a 
href="https://github.com/maveniverse/pilot/releases";>eu.maveniverse.maven.plugins:pilot-plugin's
 releases</a>.</em></p>
   <blockquote>
   <h2>Pilot 0.5.0</h2>
   <h2>🌟 Overview</h2>
   <p>Pilot 0.5.0 expands the accuracy and breadth of dependency classification 
across several fronts. Previous releases focused on getting the core detection 
right for standard Java projects; this release pushes into harder cases — 
polyglot builds, native images, framework-specific extension points, and 
multi-module fix propagation — where earlier heuristics produced false 
positives or missed scope mismatches entirely.</p>
   <p><strong>GraalVM native-image support</strong> processes 
<code>META-INF/native-image/**/*.json</code> resource files to discover classes 
referenced via GraalVM's reflection, proxy, serialization, and JNI 
configurations, preventing UNUSED false positives for dependencies that 
contribute only native-image metadata. This matters for any project building a 
native executable where dependencies are invisible to bytecode scanning.</p>
   <p><strong>DiscoveryConvention SPI</strong> replaces the hard-coded 
source-detection logic with a pluggable strategy pattern. The built-in 
conventions cover Maven standard layout, Groovy, Kotlin, Scala, and 
annotation-processor outputs — and the SPI lets future extensions add project 
types without touching core. The immediate fix eliminates false positives in 
Groovy/Kotlin/Scala projects where <code>hasMainSources()</code> / 
<code>hasTestSources()</code> previously returned <code>false</code> on 
legitimate builds.</p>
   <p><strong>Camel SPI detection</strong> classifies Apache Camel extension 
providers (services registered under <code>META-INF/services/</code>) as 
UNDETERMINED rather than UNUSED, since their usage is resolved at runtime 
through Camel's service-loader mechanism and cannot be proven statically.</p>
   <p><strong>Test-scope narrowing</strong> identifies compile-scope 
dependencies whose classes appear only in test source trees and automatically 
suggests narrowing them to <code>test</code>. The fix action now converges with 
<code>pilot.maxIterations</code> (default 5) to handle cascading scope changes 
across multi-module reactors.</p>
   <p>On top of that, six correctness fixes address type-resolution edge cases, 
aggregator POM false positives, managed-dependency propagation to the right 
ancestor, and guard conditions for projects with no test sources.</p>
   <hr />
   <h2>🚀 New Features &amp; Improvements</h2>
   <ul>
   <li>Refactor runtime-discovery into pluggable DiscoveryConvention strategies 
(<a href="https://redirect.github.com/maveniverse/pilot/pull/196";>#196</a>) <a 
href="https://github.com/gnodet";><code>@​gnodet</code></a></li>
   <li>feat: GraalVM native-image metadata support to fix false-positive UNUSED 
dependency reports (<a 
href="https://redirect.github.com/maveniverse/pilot/pull/195";>#195</a>) <a 
href="https://github.com/gnodet";><code>@​gnodet</code></a></li>
   <li>feat: converge fix action with pilot.maxIterations (default 5) (<a 
href="https://redirect.github.com/maveniverse/pilot/pull/194";>#194</a>) <a 
href="https://github.com/gnodet";><code>@​gnodet</code></a></li>
   <li>feat: detect Apache Camel SPI providers and classify them as 
UNDETERMINED (<a 
href="https://redirect.github.com/maveniverse/pilot/pull/193";>#193</a>) <a 
href="https://github.com/gnodet";><code>@​gnodet</code></a></li>
   <li>feat: detect compile-scope deps used only in tests and narrow scope (<a 
href="https://redirect.github.com/maveniverse/pilot/pull/191";>#191</a>) <a 
href="https://github.com/gnodet";><code>@​gnodet</code></a></li>
   </ul>
   <h2>🐛 Bug Fixes</h2>
   <ul>
   <li>fix: add property= bindings to bare <a 
href="https://github.com/Parameter";><code>@​Parameter</code></a> annotations so 
list/map params work as -D flags (<a 
href="https://redirect.github.com/maveniverse/pilot/pull/192";>#192</a>) <a 
href="https://github.com/gnodet";><code>@​gnodet</code></a></li>
   <li>fix: detect Groovy/Kotlin/Scala sources by convention in 
hasTestSources() and hasMainSources() (<a 
href="https://redirect.github.com/maveniverse/pilot/pull/181";>#181</a>) <a 
href="https://github.com/gnodet";><code>@​gnodet</code></a></li>
   <li>fix: suppress used-transitive false positives for type=pom aggregator 
dependencies (<a 
href="https://redirect.github.com/maveniverse/pilot/pull/184";>#184</a>) <a 
href="https://github.com/gnodet";><code>@​gnodet</code></a></li>
   <li>fix: propagate managed dep to ancestor with most dependencyManagement 
entries (<a 
href="https://redirect.github.com/maveniverse/pilot/pull/185";>#185</a>) <a 
href="https://github.com/gnodet";><code>@​gnodet</code></a></li>
   <li>fix: resolve Maven type (e.g. test-jar) via ArtifactTypeRegistry in 
buildCollectRequest (<a 
href="https://redirect.github.com/maveniverse/pilot/pull/180";>#180</a>) <a 
href="https://github.com/gnodet";><code>@​gnodet</code></a></li>
   <li>fix: skip test-classes guard when project has no test sources (<a 
href="https://redirect.github.com/maveniverse/pilot/pull/179";>#179</a>) <a 
href="https://github.com/gnodet";><code>@​gnodet</code></a></li>
   </ul>
   <h2>📦 Dependency Updates</h2>
   <ul>
   <li>build(deps): bump tamboui.version from 0.4.0 to 0.5.0 (<a 
href="https://redirect.github.com/maveniverse/pilot/pull/186";>#186</a>) <a 
href="https://github.com/dependabot";><code>@​dependabot</code></a></li>
   <li>build(deps-dev): bump 
org.apache.maven.resolver:maven-resolver-connector-basic from 1.9.27 to 2.0.23 
(<a href="https://redirect.github.com/maveniverse/pilot/pull/187";>#187</a>) <a 
href="https://github.com/dependabot";><code>@​dependabot</code></a></li>
   <li>build(deps): bump jline.version from 4.4.3 to 4.4.5 (<a 
href="https://redirect.github.com/maveniverse/pilot/pull/188";>#188</a>) <a 
href="https://github.com/dependabot";><code>@​dependabot</code></a></li>
   <li>build(deps-dev): bump 
org.apache.maven.resolver:maven-resolver-transport-file from 1.9.27 to 2.0.23 
(<a href="https://redirect.github.com/maveniverse/pilot/pull/189";>#189</a>) <a 
href="https://github.com/dependabot";><code>@​dependabot</code></a></li>
   </ul>
   <h2>👻 Maintenance</h2>
   <ul>
   <li>ci: remove redundant =true from -Dnjord.waitForStates (<a 
href="https://redirect.github.com/maveniverse/pilot/pull/178";>#178</a>) <a 
href="https://github.com/gnodet";><code>@​gnodet</code></a></li>
   </ul>
   <p><strong>Full Changelog</strong>: <a 
href="https://github.com/maveniverse/pilot/compare/0.4.0...0.5.0";>https://github.com/maveniverse/pilot/compare/0.4.0...0.5.0</a></p>
   </blockquote>
   </details>
   <details>
   <summary>Commits</summary>
   <ul>
   <li><a 
href="https://github.com/maveniverse/pilot/commit/e234879a9a313cb7470e53631c41f5c1712eadcb";><code>e234879</code></a>
 Refactor runtime-discovery into pluggable DiscoveryConvention strategies (<a 
href="https://redirect.github.com/maveniverse/pilot/issues/196";>#196</a>)</li>
   <li><a 
href="https://github.com/maveniverse/pilot/commit/0e92bbc163f433237306919a8bc38bf88e3b6c2e";><code>0e92bbc</code></a>
 feat: GraalVM native-image metadata support to fix false-positive UNUSED 
depe...</li>
   <li><a 
href="https://github.com/maveniverse/pilot/commit/07d50483a16f29c300b69e3798d9043d0cfe06b7";><code>07d5048</code></a>
 feat: converge fix action with pilot.maxIterations (default 5)</li>
   <li><a 
href="https://github.com/maveniverse/pilot/commit/a02dbdf551b85441f36ee372bbf5e102b84f79de";><code>a02dbdf</code></a>
 build(deps): bump tamboui.version from 0.4.0 to 0.5.0</li>
   <li><a 
href="https://github.com/maveniverse/pilot/commit/d3b36e7a88769d3ceedb39077874276d1c81f004";><code>d3b36e7</code></a>
 build(deps-dev): bump 
org.apache.maven.resolver:maven-resolver-connector-basi...</li>
   <li><a 
href="https://github.com/maveniverse/pilot/commit/d8d2c06dc237cafb84feef010b927a01eae6e4ec";><code>d8d2c06</code></a>
 build(deps): bump jline.version from 4.4.3 to 4.4.5</li>
   <li><a 
href="https://github.com/maveniverse/pilot/commit/d1f05a1c6454853724690a83d5020067d0c20c1d";><code>d1f05a1</code></a>
 build(deps-dev): bump 
org.apache.maven.resolver:maven-resolver-transport-file...</li>
   <li><a 
href="https://github.com/maveniverse/pilot/commit/ebb679e447fd125e772195c15d0f937837ed6342";><code>ebb679e</code></a>
 feat: detect Apache Camel SPI providers and classify them as UNDETERMINED</li>
   <li><a 
href="https://github.com/maveniverse/pilot/commit/c594b1e4223d82373853fa04a1f8160d5e38c026";><code>c594b1e</code></a>
 fix: add property= bindings to bare <a 
href="https://github.com/Parameter";><code>@​Parameter</code></a> annotations so 
list/map params...</li>
   <li><a 
href="https://github.com/maveniverse/pilot/commit/57e3148d3d1ba5d58c717afc0a632619ae46389e";><code>57e3148</code></a>
 feat: detect compile-scope deps used only in tests and narrow scope</li>
   <li>Additional commits viewable in <a 
href="https://github.com/maveniverse/pilot/compare/0.4.0...0.5.0";>compare 
view</a></li>
   </ul>
   </details>
   <br />
   
   
   [![Dependabot compatibility 
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=eu.maveniverse.maven.plugins:pilot-plugin&package-manager=maven&previous-version=0.4.0&new-version=0.5.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
   
   Dependabot will resolve any conflicts with this PR as long as you don't 
alter it yourself. You can also trigger a rebase manually by commenting 
`@dependabot rebase`.
   
   [//]: # (dependabot-automerge-start)
   [//]: # (dependabot-automerge-end)
   
   ---
   
   <details>
   <summary>Dependabot commands and options</summary>
   <br />
   
   You can trigger Dependabot actions by commenting on this PR:
   - `@dependabot rebase` will rebase this PR
   - `@dependabot recreate` will recreate this PR, overwriting any edits that 
have been made to it
   - `@dependabot show <dependency name> ignore conditions` will show all of 
the ignore conditions of the specified dependency
   - `@dependabot ignore this major version` will close this PR and stop 
Dependabot creating any more for this major version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this minor version` will close this PR and stop 
Dependabot creating any more for this minor version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this dependency` will close this PR and stop 
Dependabot creating any more for this dependency (unless you reopen the PR or 
upgrade to it yourself)
   
   
   </details>


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to