slachiewicz opened a new pull request, #539: URL: https://github.com/apache/maven-build-cache-extension/pull/539
## Problem `javax.annotation:javax.annotation-api` has `net.java:jvnet-parent` as its parent, which declares the long-shut-down `https://maven.java.net` repositories. Dependency-POM repositories are not used for artifact resolution, but they do leak into the remote repository set used for **metadata** lookups — so every build pays a failing HTTPS round-trip against the dead host. Maven 4's plugin-prefix discovery probes it as well: ``` [WARNING] Could not transfer metadata /.meta/prefixes.txt from/to jvnet-nexus-releases (https://maven.java.net/content/repositories/releases/): (certificate_expired) PKIX path validation failed ``` ## Change `javax.annotation:javax.annotation-api:1.3.2` → `jakarta.annotation:jakarta.annotation-api:1.3.5`. The jakarta artifact is the EE4J continuation of the same JSR-250 API, published under the **same `javax.annotation` package names** (jakarta package rename only happened in 2.x), so this is a drop-in replacement — no source changes needed. The project only uses `@PostConstruct` and `@Priority` from it; the `javax.annotation.Nonnull`/`Nullable` imports resolve from `com.google.code.findbugs:jsr305` (unchanged), not from this artifact. The EE4J parent declares no active resolution repositories. ## Verification - `mvn test-compile` — clean - `mvn test -Dtest=LifecyclePhasesHelperTest,BuildInfoTest,BuildCacheMojosExecutionStrategyTest` — 35/35 pass (covers the `@PostConstruct` and `@Priority` usages) -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
