pavelhoral opened a new issue, #13390: URL: https://github.com/apache/maven/issues/13390
### Affected version 3.10.0 ### Bug description Disclamer: I got help from ChatGPT with generating the issue description bellow. Our builds started failing on https://repo1.maven.org/maven2/org/jruby/jruby-base/9.4.2.0/jruby-base-9.4.2.0.pom dependency that uses `tzdata.version` property profile activation and it is getting activated by its own property with Maven 3.10.0. --- Maven 3.10.0 activates property-based profiles in dependency POMs when the activation property is declared in that POM’s own `<properties>` section. According to the [profile activation documentation](https://maven.apache.org/guides/introduction/introduction-to-profiles.html#properties), property activation uses system or CLI user properties. The documentation additionally mentions properties from active settings.xml profiles and the special packaging property. POM-defined properties should not themselves activate profiles. ## Reproduction Publish or install an artifact with this POM: ```xml <project xmlns="http://maven.apache.org/POM/4.0.0"> <modelVersion>4.0.0</modelVersion> <groupId>example</groupId> <artifactId>profiled-dependency</artifactId> <version>1.0</version> <packaging>pom</packaging> <properties> <example.enable.extra>true</example.enable.extra> </properties> <profiles> <profile> <id>extra-dependency</id> <activation> <property> <name>example.enable.extra</name> </property> </activation> <dependencies> <dependency> <groupId>org.apache.commons</groupId> <artifactId>commons-lang3</artifactId> <version>3.12.0</version> </dependency> </dependencies> </profile> </profiles> </project> ``` Reference it from a separate consumer project: ```xml <project xmlns="http://maven.apache.org/POM/4.0.0"> <modelVersion>4.0.0</modelVersion> <groupId>example</groupId> <artifactId>consumer</artifactId> <version>1.0</version> <dependencies> <dependency> <groupId>example</groupId> <artifactId>profiled-dependency</artifactId> <version>1.0</version> <type>pom</type> </dependency> </dependencies> </project> ``` Run `mvn dependency:tree` with Maven 3.9.16 and 3.10.0. ## Expected behavior The extra-dependency profile remains inactive. Declaring `example.enable.extra` inside the dependency POM should not activate it. ### Actual behavior Maven 3.10.0 makes POM-local properties available to the profile activator, causing the profile to activate and contribute dependencies. ### Potential cause The change appears related to the fix for [#13084](https://github.com/apache/maven/issues/13084), backported through [#13114](https://github.com/apache/maven/pull/13114). In [DefaultModelBuilder.externalActivationContext()](https://github.com/apache/maven/blob/maven-3.10.0/maven-model-builder/src/main/java/org/apache/maven/model/building/DefaultModelBuilder.java#L539-L551), the POM’s project properties are merged into the system properties exposed to the profile activator. This appears to introduce an additional activation source that conflicts with the documented semantics. The behavior is still present in maven-3.10.x. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
