gnodet opened a new pull request, #13197:
URL: https://github.com/apache/maven/pull/13197

   ## Problem
   
   When `mvnup` (or any tooling using `BUILD_EFFECTIVE` with `recursive=false`) 
analyzes a POM that imports a BOM from a reactor sibling, the BOM cannot be 
resolved because:
   
   1. `mappedSources` is empty — `BUILD_EFFECTIVE` does not trigger a reactor 
scan
   2. The BOM snapshot is not available in any remote repo configured in 
`mvnup`'s standalone session
   
   When the BOM import fails, its managed versions are absent. 
`validateEffectiveModel` then fires at `VALIDATION_LEVEL_STRICT` (the same 
level as a regular build), reporting `dependencies.dependency.version is 
missing` for every dependency that relied on the BOM — noise that obscures the 
real root cause.
   
   Observed in the **apache/maven4-testing** run on cassandra-java-driver (6 
false-positive errors per submodule that imports a sibling BOM).
   
   ## Root Cause
   
   `buildEffectiveModel` chooses `VALIDATION_LEVEL_STRICT` for all 
`isBuildRequest()` modes, which includes `BUILD_EFFECTIVE`. But 
`BUILD_EFFECTIVE` is a tooling-only mode with no reactor context, so it can 
never satisfy the invariants that strict validation assumes.
   
   ## Fix
   
   Exclude `BUILD_EFFECTIVE` from strict validation — treat it like other 
non-build request types (e.g. `CONSUMER_DEPENDENCY`), which already use 
`VALIDATION_LEVEL_MINIMAL`:
   
   ```java
   boolean strictValidation =
           isBuildRequest() && request.getRequestType() != 
ModelBuilderRequest.RequestType.BUILD_EFFECTIVE;
   modelValidator.validateEffectiveModel(
           session,
           resultModel,
           strictValidation ? ModelValidator.VALIDATION_LEVEL_STRICT : 
ModelValidator.VALIDATION_LEVEL_MINIMAL,
           this);
   ```
   
   The real root cause (Non-resolvable import POM) is still reported as an 
error by `importDependencyManagement` — this change only suppresses the cascade 
of version-missing false positives that follow.
   
   ## Testing
   
   - Unit tests: `mvn verify -pl impl/maven-impl -am` passes (38s)
   - Manual: `mvnup check` on a project with a reactor-sibling BOM import no 
longer reports `version is missing` errors when the BOM snapshot is unavailable 
remotely
   
   Fixes #13190


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to