elharo opened a new pull request, #261:
URL: https://github.com/apache/maven-artifact-plugin/pull/261

   ## What
   
   `ReproducibleCentralReport` triggers a javac deprecation warning:
   
   ```
   [WARNING] .../ReproducibleCentralReport.java:[30,44] 
org.apache.maven.plugins.annotations.Component
             in org.apache.maven.plugins.annotations has been deprecated
   [WARNING] .../ReproducibleCentralReport.java:[55,6]  
org.apache.maven.plugins.annotations.Component
             in org.apache.maven.plugins.annotations has been deprecated
   ```
   
   `org.apache.maven.plugins.annotations.Component` was deprecated in 
maven-plugin-annotations 3.15.2 with the message:
   
   > Use JSR 330 annotations or Parameter with according default expressions 
instead.
   
   The project builds against `maven-plugin-annotations` 3.16.0 (inherited from 
`apache:40`), which is where the warning now shows up.
   
   ## Why remove the field rather than switch to `@Inject`
   
   The `MavenSession` field is **never read** anywhere in the report — it has 
been dead since the report was added in 
[b82943b](https://github.com/apache/maven-artifact-plugin/commit/b82943b22c7b561c1d70c10d485a50e78a999aa3)
 (MARTIFACT-81). It only serves to have Plexus inject a component that is then 
thrown away.
   
   So rather than rewriting `@Component` to `javax.inject.Inject` (the JSR 330 
replacement, already used by `DescribeBuildOutputMojo`, `CheckBuildPlanMojo` 
and `RangesUtil` in this plugin), the field is dropped entirely, along with the 
now-unused `MavenSession` import. Nothing in the report depends on the session, 
and the report's dependency resolution is already declared by 
`requiresDependencyResolution = ResolutionScope.RUNTIME` on the `@Mojo` 
annotation.
   
   ## Effects
   
   * The two javac deprecation warnings are gone.
   * `META-INF/maven/plugin.xml` no longer contains a `<requirement>` for 
`org.apache.maven.execution.MavenSession`.
   * The related `maven-plugin-plugin` warning loses one field:
   
   ```
   - Mojo reproducible-central uses Plexus Component requirements (@Component 
annotation) for fields: [container, session, siteRenderer, siteTool]
   + Mojo reproducible-central uses Plexus Component requirements (@Component 
annotation) for fields: [container, siteRenderer, siteTool]
   ```
   
     The three remaining fields (`container`, `siteRenderer`, `siteTool`) are 
declared with `@Component` inside `AbstractMavenReport` in 
`maven-reporting-impl`, so they are inherited rather than defined here. 
`maven-reporting-impl:4.0.0` is already the latest release, so clearing those 
would be an upstream change and is out of scope here. That is why this PR fixes 
the javac warning but the plugin-level advisory remains.
   
   ## Verification
   
   * `mvn clean compile -Dmaven.compiler.showDeprecation=true` — no deprecation 
warnings; on `master` the two warnings above are reported.
   * `mvn clean verify -DskipITs` — BUILD SUCCESS, 0 Checkstyle violations, 
Spotless clean, 2/2 unit tests pass.
   * Smoke-tested the report end-to-end against a throwaway project with both 
paths:
     * standalone goal `mvn artifact:reproducible-central`
     * via the site lifecycle, `mvn site -DgenerateReports=true` with the 
report declared in `src/site/site.xml` → `Detected 1 report for 
maven-artifact-plugin: reproducible-central`, `Generating "Reproducible 
Central" report`, BUILD SUCCESS
   
     Both render the project badge, the per-scope dependency badge groups (e.g. 
`compile`, `runtime`) and the Reproducible Builds footnote, i.e. output is 
unchanged.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to