Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(deps): bump org.apache.maven.plugins:maven-compiler-plugin from 3.11.0 to 3.12.1 #5674

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Dec 25, 2023

Bumps org.apache.maven.plugins:maven-compiler-plugin from 3.11.0 to 3.12.1.

Release notes

Sourced from org.apache.maven.plugins:maven-compiler-plugin's releases.

3.12.1

🐛 Bug Fixes

📦 Dependency updates

3.12.0

🚀 New features and improvements

🐛 Bug Fixes

📦 Dependency updates

👻 Maintenance

Commits
  • 736da68 [maven-release-plugin] prepare release maven-compiler-plugin-3.12.1
  • ef93f3d [MCOMPILER-568] Bump plexusCompilerVersion from 2.14.1 to 2.14.2 (#220)
  • eb7840c [MCOMPILER-567] - Fail to compile if the "generated-sources/annotations" does...
  • 2a7a73b [maven-release-plugin] prepare for next development iteration
  • c08b0fd [maven-release-plugin] prepare release maven-compiler-plugin-3.12.0
  • a1c5b13 [MCOMPILER-565] Allow project build by Maven 4
  • 4855773 Bump plexusCompilerVersion from 2.13.0 to 2.14.1
  • 1d05342 [MCOMPILER-562] Add property maven.compiler.outputDirectory to CompilerMojo (...
  • ea74978 [MCOMPILER-381] - Refactor incremental detection (#181)
  • fd37f09 [MCOMPILER-333] Cleanup generated source files (#214)
  • Additional commits viewable in compare view

Dependabot compatibility score

You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabot dependabot bot requested a review from manusa as a code owner December 25, 2023 11:51
@dependabot dependabot bot added dependencies Pull requests that update a dependency file java Pull requests that update Java code labels Dec 25, 2023
@dependabot dependabot bot force-pushed the dependabot/maven/org.apache.maven.plugins-maven-compiler-plugin-3.12.1 branch from 0c6f327 to 655396b Compare January 3, 2024 08:55
Copy link

sonarqubecloud bot commented Jan 3, 2024

Quality Gate Passed Quality Gate passed

Kudos, no new issues were introduced!

0 New issues
0 Security Hotspots
No data about Coverage
0.0% Duplication on New Code

See analysis details on SonarCloud

@rohanKanojia
Copy link
Member

rohanKanojia commented Feb 5, 2024

strange, I'm not able to reproduce this locally

Edit: I'm able to reproduce once I delete .m2 cache

@rohanKanojia
Copy link
Member

@dependabot rebase

@dependabot dependabot bot force-pushed the dependabot/maven/org.apache.maven.plugins-maven-compiler-plugin-3.12.1 branch from 655396b to 453263c Compare February 5, 2024 06:27
@rohanKanojia rohanKanojia force-pushed the dependabot/maven/org.apache.maven.plugins-maven-compiler-plugin-3.12.1 branch from 453263c to 70162a1 Compare February 5, 2024 20:24
pom.xml Outdated
Comment on lines 851 to 857
<dependency>
<groupId>org.junit</groupId>
<artifactId>junit-bom</artifactId>
<version>${junit.version}</version>
<type>pom</type>
<scope>import</scope>
</dependency>
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Any explanation for this?

Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm not really sure why it's working. I tried changing various things in Istio model pom and Makefile but none of them seem to fix the issue.

During model generation process, only during Istio model compilation maven-compiler-plugin throws these warnings:

[INFO] Artifact org.junit:junit-bom:pom:5.10.1 is present in the local repository, but cached from a remote repository ID that is unavailable in current build context, ver
ifying that is downloadable from [central (https://repo.maven.apache.org/maven2, default, releases), plexus.snapshots (https://oss.sonatype.org/content/repositories/plexus
-snapshots, default, snapshots), apache.snapshots (https://repository.apache.org/snapshots, default, snapshots)]

and fails with this error:

[ERROR] Failed to execute goal org.apache.maven.plugins:maven-compiler-plugin:3.12.1:compile (default-compile) on project istio-model-v1alpha3: Execution default-compile of goal org.apache.maven.plugins:maven-compiler-plugin:3.12.1:compile failed: Plugin org.apache.maven.plugins:maven-compiler-plugin:3.12.1 or one of its dependencies could not be resolved: Failed to collect dependencies at org.apache.maven.plugins:maven-compiler-plugin:jar:3.12.1 -> org.codehaus.plexus:plexus-compiler-api:jar:2.14.2: Failed to read artifact descriptor for org.codehaus.plexus:plexus-compiler-api:jar:2.14.2: Cannot access central (https://repo.maven.apache.org/maven2) in offline mode and the artifact org.junit:junit-bom:pom:5.10.1 has not been downloaded from it before.

Following the error message, I saw that Junit5 bom is added in plexus-compiler-api/pom.xml . When I added same bom in our pom.xml, it started working.

Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We should try to align versions with plexus-compiler-api then, or try to figure out the dependency convergence issue.

@rohanKanojia rohanKanojia force-pushed the dependabot/maven/org.apache.maven.plugins-maven-compiler-plugin-3.12.1 branch from 70162a1 to 653c468 Compare February 6, 2024 10:02
@rohanKanojia rohanKanojia force-pushed the dependabot/maven/org.apache.maven.plugins-maven-compiler-plugin-3.12.1 branch from 653c468 to b06803d Compare February 7, 2024 06:06
@manusa manusa added this to the 6.11.0 milestone Feb 7, 2024
Bumps [org.apache.maven.plugins:maven-compiler-plugin](https://github.com/apache/maven-compiler-plugin) from 3.11.0 to 3.12.1.
- [Release notes](https://github.com/apache/maven-compiler-plugin/releases)
- [Commits](apache/maven-compiler-plugin@maven-compiler-plugin-3.11.0...maven-compiler-plugin-3.12.1)

---
updated-dependencies:
- dependency-name: org.apache.maven.plugins:maven-compiler-plugin
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>
@rohanKanojia rohanKanojia force-pushed the dependabot/maven/org.apache.maven.plugins-maven-compiler-plugin-3.12.1 branch from b06803d to b33dee3 Compare February 7, 2024 08:55
Copy link

sonarqubecloud bot commented Feb 7, 2024

Quality Gate Passed Quality Gate passed

Kudos, no new issues were introduced!

0 New issues
0 Security Hotspots
No data about Coverage
0.0% Duplication on New Code

See analysis details on SonarCloud

@manusa manusa merged commit ab17dcd into main Feb 7, 2024
17 of 19 checks passed
@manusa manusa deleted the dependabot/maven/org.apache.maven.plugins-maven-compiler-plugin-3.12.1 branch February 7, 2024 10:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file java Pull requests that update Java code
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants