yasithdev opened a new pull request, #677:
URL: https://github.com/apache/airavata/pull/677

   Ten `dependencyManagement` entries and the `selenium-maven-plugin` 
`pluginManagement` entry pinned artifacts that appear **nowhere in the resolved 
dependency tree**, so the pins were inert: `dozer-core`, the four `selenium-*` 
drivers, `json-simple`, `commons-exec`, `mysql-connector-j` (the DB driver is 
`mariadb-java-client`), `keycloak-authz-client` (IAM uses 
`keycloak-admin-client`), and `slf4j-simple`.
   
   `commons-logging` and `jcl-over-slf4j` are **kept** — both are live in the 
resolved tree (verified, correcting an audit note that flagged commons-logging).
   
   ## Test plan
   - `mvn dependency:list` confirms each removed artifact is absent from the 
resolved tree (and commons-logging/jcl-over-slf4j present).
   - `mvn install -DskipTests` (full reactor) green; pom well-formed.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to