ppkarwasz opened a new pull request, #4281:
URL: https://github.com/apache/logging-log4j2/pull/4281

   `log4j-api-test` declared `maven-core`, `maven-model` and `plexus-utils` at 
compile scope, and `log4j-core-test` and `log4j-core-java9` declared 
`maven-core` at test scope. The only code using them was `BundleTestInfo`, a 
helper that read `pom.xml` to expose the artifact ID and version. Its last 
caller went away in LOG4J2-3546 in 2022, and the class was already dropped on 
`main`.
   
   This PR removes the class, the dependency declarations, the corresponding 
bnd import-package and module options, and the managed versions in 
`log4j-parent`.
   
   **User-visible effect:** consumers of `log4j-api-test` no longer receive 
about 25 transitive jars, among them `slf4j-api` 1.7.36, Guice, Sisu and the 
Maven resolver. Code that relied on those coming in transitively will need to 
declare them directly. `BundleTestInfo` is removed from a public package, but 
`log4j-api-test` carries no backward compatibility guarantees. The removal is 
annotated with `@BaselineIgnore("2.27.0")` for the bnd baseline check, as done 
for the `jvmrunargs` removal in #3874.
   
   **Transitive pins.** As a follow-up, the second commit drops the transitive 
dependency pins from `log4j-parent` (`asm`, `byte-buddy`, `commons-pool2`, 
`guava`, `httpclient`, `httpcore`, `jna`). Log4j is a library. Maven consults 
the `dependencyManagement` of the project being built only. When an application 
depends on a Log4j module, the management section inherited from `log4j-parent` 
is not consulted while resolving that module's transitive dependencies, so 
these pins never reached users. They only changed the versions resolved in our 
own build and gave a misleading picture of what consumers get. 
`requireUpperBoundDeps` passes without them. The `guava` pin moves to 
`log4j-cassandra`, the one module that needs it, because `cassandra-all` breaks 
with anything newer than 25.1-jre. The guava exclusions in that module guarded 
against the compile-scope guava that arrived through `maven-core`, and are 
removed as well.
   
   Dependabot will also stop filing update PRs for the removed artifacts.
   
   🤖 Generated with [Claude Code](https://claude.com/claude-code)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to