Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Exclusions defined in dependencyManagement don't apply transitively #853

Open
dansanduleac opened this issue May 4, 2018 · 2 comments
Open

Comments

@dansanduleac
Copy link

dansanduleac commented May 4, 2018

Example: getting maven dependencies for the dist dependency in palantir/spark:

./build/mvn -DskipTests -Phadoop-cloud -Phadoop-palantir -Pkinesis-asl -Pkubernetes -Pyarn -Psparkr -pl "org.apache.spark:spark-dist_2.11-hadoop-palantir" dependency:tree
[INFO] org.apache.spark:spark-dist_2.11-hadoop-palantir:pom:2.4.0-SNAPSHOT
[INFO] +- org.apache.spark:spark-core_2.11:jar:2.4.0-SNAPSHOT:compile
[INFO] |  +- org.apache.avro:avro:jar:1.8.1:compile
[INFO] |  |  +- org.codehaus.jackson:jackson-core-asl:jar:1.9.13:compile
[INFO] |  |  +- org.codehaus.jackson:jackson-mapper-asl:jar:1.9.13:compile
[INFO] |  |  +- com.thoughtworks.paranamer:paranamer:jar:2.8:compile
[INFO] |  |  +- org.apache.commons:commons-compress:jar:1.8.1:compile
[INFO] |  |  \- org.tukaani:xz:jar:1.5:compile
[INFO] |  +- org.apache.avro:avro-mapred:jar:hadoop2:1.8.1:compile
[INFO] |  |  +- org.apache.avro:avro-ipc:jar:1.8.1:compile
[INFO] |  |  \- commons-codec:commons-codec:jar:1.10:compile
[INFO] |  +- com.twitter:chill_2.11:jar:0.8.4:compile
[INFO] |  |  \- com.esotericsoftware:kryo-shaded:jar:3.0.3:compile
[INFO] |  |     +- com.esotericsoftware:minlog:jar:1.3.0:compile
[INFO] |  |     \- org.objenesis:objenesis:jar:2.5.1:compile
[INFO] |  +- com.twitter:chill-java:jar:0.8.4:compile
[INFO] |  +- org.apache.xbean:xbean-asm5-shaded:jar:4.4:compile
[INFO] |  +- org.apache.hadoop:hadoop-client:jar:2.8.2-palantir.2:compile
[INFO] |  |  +- org.apache.hadoop:hadoop-hdfs-client:jar:2.8.2-palantir.2:compile
[INFO] |  |  +- org.apache.hadoop:hadoop-mapreduce-client-app:jar:2.8.2-palantir.2:compile
[INFO] |  |  |  +- org.apache.hadoop:hadoop-mapreduce-client-common:jar:2.8.2-palantir.2:compile
[INFO] |  |  |  \- org.apache.hadoop:hadoop-mapreduce-client-shuffle:jar:2.8.2-palantir.2:compile
[INFO] |  |  +- org.apache.hadoop:hadoop-mapreduce-client-core:jar:2.8.2-palantir.2:compile
[INFO] |  |  +- org.apache.hadoop:hadoop-mapreduce-client-jobclient:jar:2.8.2-palantir.2:compile
[INFO] |  |  \- org.apache.hadoop:hadoop-annotations:jar:2.8.2-palantir.2:compile
[INFO] |  +- org.apache.spark:spark-launcher_2.11:jar:2.4.0-SNAPSHOT:compile
[INFO] |  +- org.apache.spark:spark-kvstore_2.11:jar:2.4.0-SNAPSHOT:compile
[INFO] |  |  +- org.fusesource.leveldbjni:leveldbjni-all:jar:1.8:compile
[INFO] |  |  \- com.fasterxml.jackson.core:jackson-core:jar:2.6.7:compile
[INFO] |  +- org.apache.spark:spark-network-common_2.11:jar:2.4.0-SNAPSHOT:compile
[INFO] |  +- org.apache.spark:spark-network-shuffle_2.11:jar:2.4.0-SNAPSHOT:compile
[INFO] |  +- org.apache.spark:spark-unsafe_2.11:jar:2.4.0-SNAPSHOT:compile
[INFO] |  +- net.java.dev.jets3t:jets3t:jar:0.9.4:compile
[INFO] |  |  +- javax.activation:activation:jar:1.1.1:compile
[INFO] |  |  +- org.bouncycastle:bcprov-jdk15on:jar:1.58:compile
[INFO] |  |  \- com.jamesmurty.utils:java-xmlbuilder:jar:1.1:compile
[INFO] |  |     \- net.iharder:base64:jar:2.3.8:compile
[INFO] |  +- org.apache.curator:curator-recipes:jar:2.7.1:compile
[INFO] |  |  \- org.apache.curator:curator-framework:jar:2.7.1:compile
[INFO] |  +- org.apache.zookeeper:zookeeper:jar:3.4.6:compile
[INFO] |  +- javax.servlet:javax.servlet-api:jar:3.1.0:compile
[INFO] |  +- org.apache.commons:commons-lang3:jar:3.5:compile
[INFO] |  +- org.apache.commons:commons-math3:jar:3.4.1:compile
[INFO] |  +- com.google.code.findbugs:jsr305:jar:3.0.1:compile
[INFO] |  +- org.slf4j:slf4j-api:jar:1.7.25:compile
[INFO] |  +- org.slf4j:jul-to-slf4j:jar:1.7.25:compile
[INFO] |  +- org.slf4j:jcl-over-slf4j:jar:1.7.25:compile
[INFO] |  +- log4j:log4j:jar:1.2.17:compile
[INFO] |  +- org.slf4j:slf4j-log4j12:jar:1.7.25:compile
[INFO] |  +- com.ning:compress-lzf:jar:1.0.3:compile
[INFO] |  +- org.xerial.snappy:snappy-java:jar:1.1.7.1:compile
[INFO] |  +- org.lz4:lz4-java:jar:1.4.0:compile
[INFO] |  +- com.github.luben:zstd-jni:jar:1.3.2-2:compile
[INFO] |  +- org.roaringbitmap:RoaringBitmap:jar:0.6.43:compile
[INFO] |  +- commons-net:commons-net:jar:3.1:compile
[INFO] |  +- org.scala-lang:scala-library:jar:2.11.8:compile
[INFO] |  +- org.json4s:json4s-jackson_2.11:jar:3.5.3:compile
[INFO] |  |  \- org.json4s:json4s-core_2.11:jar:3.5.3:compile
[INFO] |  |     +- org.json4s:json4s-ast_2.11:jar:3.5.3:compile
[INFO] |  |     \- org.json4s:json4s-scalap_2.11:jar:3.5.3:compile
[INFO] |  +- org.glassfish.jersey.core:jersey-client:jar:2.25.1:compile
[INFO] |  |  +- javax.ws.rs:javax.ws.rs-api:jar:2.0.1:compile
[INFO] |  |  +- org.glassfish.hk2:hk2-api:jar:2.5.0-b32:compile
[INFO] |  |  |  +- org.glassfish.hk2:hk2-utils:jar:2.5.0-b32:compile
[INFO] |  |  |  \- org.glassfish.hk2.external:aopalliance-repackaged:jar:2.5.0-b32:compile
[INFO] |  |  +- org.glassfish.hk2.external:javax.inject:jar:2.5.0-b32:compile
[INFO] |  |  \- org.glassfish.hk2:hk2-locator:jar:2.5.0-b32:compile
[INFO] |  |     \- org.javassist:javassist:jar:3.20.0-GA:compile
[INFO] |  +- org.glassfish.jersey.core:jersey-common:jar:2.25.1:compile
[INFO] |  |  +- javax.annotation:javax.annotation-api:jar:1.2:compile
[INFO] |  |  +- org.glassfish.jersey.bundles.repackaged:jersey-guava:jar:2.25.1:compile
[INFO] |  |  \- org.glassfish.hk2:osgi-resource-locator:jar:1.0.1:compile
[INFO] |  +- org.glassfish.jersey.core:jersey-server:jar:2.25.1:compile
[INFO] |  |  +- org.glassfish.jersey.media:jersey-media-jaxb:jar:2.25.1:compile
[INFO] |  |  \- javax.validation:validation-api:jar:1.1.0.Final:compile
[INFO] |  +- org.glassfish.jersey.containers:jersey-container-servlet:jar:2.25.1:compile
[INFO] |  +- org.glassfish.jersey.containers:jersey-container-servlet-core:jar:2.25.1:compile
[INFO] |  +- io.netty:netty-all:jar:4.1.17.Final:compile
[INFO] |  +- io.netty:netty:jar:3.10.6.Final:compile
[INFO] |  +- com.clearspring.analytics:stream:jar:2.7.0:compile
[INFO] |  +- io.dropwizard.metrics:metrics-core:jar:3.2.5:compile
[INFO] |  +- io.dropwizard.metrics:metrics-jvm:jar:3.2.5:compile
[INFO] |  +- io.dropwizard.metrics:metrics-json:jar:3.2.5:compile
[INFO] |  +- io.dropwizard.metrics:metrics-graphite:jar:3.2.5:compile
[INFO] |  +- com.fasterxml.jackson.core:jackson-databind:jar:2.6.7.1:compile
[INFO] |  +- com.fasterxml.jackson.module:jackson-module-scala_2.11:jar:2.6.7.1:compile
[INFO] |  |  \- com.fasterxml.jackson.module:jackson-module-paranamer:jar:2.7.9:compile
[INFO] |  +- org.apache.ivy:ivy:jar:2.4.0:compile
[INFO] |  +- oro:oro:jar:2.0.8:compile
[INFO] |  +- net.razorvine:pyrolite:jar:4.13:compile
[INFO] |  +- net.sf.py4j:py4j:jar:0.10.6:compile
[INFO] |  +- org.apache.spark:spark-tags_2.11:jar:2.4.0-SNAPSHOT:compile
[INFO] |  \- org.apache.commons:commons-crypto:jar:1.0.0:compile
[INFO] +- org.apache.spark:spark-mllib_2.11:jar:2.4.0-SNAPSHOT:compile
[INFO] |  +- org.scala-lang.modules:scala-parser-combinators_2.11:jar:1.0.4:compile
[INFO] |  +- org.apache.spark:spark-mllib-local_2.11:jar:2.4.0-SNAPSHOT:compile
[INFO] |  \- org.scalanlp:breeze_2.11:jar:0.13.2:compile
[INFO] |     +- org.scalanlp:breeze-macros_2.11:jar:0.13.2:compile
[INFO] |     +- net.sf.opencsv:opencsv:jar:2.3:compile
[INFO] |     +- com.github.rwl:jtransforms:jar:2.4.0:compile
[INFO] |     +- org.spire-math:spire_2.11:jar:0.13.0:compile
[INFO] |     |  +- org.spire-math:spire-macros_2.11:jar:0.13.0:compile
[INFO] |     |  \- org.typelevel:machinist_2.11:jar:0.6.1:compile
[INFO] |     \- com.chuusai:shapeless_2.11:jar:2.3.2:compile
[INFO] |        \- org.typelevel:macro-compat_2.11:jar:1.1.1:compile
[INFO] +- org.apache.spark:spark-streaming_2.11:jar:2.4.0-SNAPSHOT:compile
[INFO] +- org.apache.spark:spark-graphx_2.11:jar:2.4.0-SNAPSHOT:compile
[INFO] |  +- com.github.fommil.netlib:core:jar:1.1.2:compile
[INFO] |  \- net.sourceforge.f2j:arpack_combined_all:jar:0.1:compile
[INFO] +- org.apache.spark:spark-sql_2.11:jar:2.4.0-SNAPSHOT:compile
[INFO] |  +- com.univocity:univocity-parsers:jar:2.5.9:compile
[INFO] |  +- org.apache.spark:spark-sketch_2.11:jar:2.4.0-SNAPSHOT:compile
[INFO] |  +- org.apache.spark:spark-catalyst_2.11:jar:2.4.0-SNAPSHOT:compile
[INFO] |  |  +- org.codehaus.janino:janino:jar:3.0.8:compile
[INFO] |  |  +- org.codehaus.janino:commons-compiler:jar:3.0.8:compile
[INFO] |  |  \- org.antlr:antlr4-runtime:jar:4.7:compile
[INFO] |  +- org.apache.orc:orc-core:jar:nohive:1.4.3:compile
[INFO] |  |  +- com.google.protobuf:protobuf-java:jar:2.5.0:compile
[INFO] |  |  +- commons-lang:commons-lang:jar:2.6:compile
[INFO] |  |  \- io.airlift:aircompressor:jar:0.8:compile
[INFO] |  +- org.apache.orc:orc-mapreduce:jar:nohive:1.4.3:compile
[INFO] |  +- org.apache.parquet:parquet-column:jar:1.9.1-palantir3:compile
[INFO] |  |  +- org.apache.parquet:parquet-common:jar:1.9.1-palantir3:compile
[INFO] |  |  +- org.apache.parquet:parquet-encoding:jar:1.9.1-palantir3:compile
[INFO] |  |  \- it.unimi.dsi:fastutil:jar:7.0.13:compile
[INFO] |  +- org.apache.parquet:parquet-hadoop:jar:1.9.1-palantir3:compile
[INFO] |  |  +- org.apache.parquet:parquet-jackson:jar:1.9.1-palantir3:compile
[INFO] |  |  +- org.apache.parquet:parquet-format:jar:2.3.1:compile
[INFO] |  |  \- commons-pool:commons-pool:jar:1.6:compile
[INFO] |  \- org.apache.arrow:arrow-vector:jar:0.8.0:compile
[INFO] |     +- org.apache.arrow:arrow-format:jar:0.8.0:compile
[INFO] |     +- org.apache.arrow:arrow-memory:jar:0.8.0:compile
[INFO] |     +- com.carrotsearch:hppc:jar:0.7.2:compile
[INFO] |     \- com.vlkan:flatbuffers:jar:1.2.0-3f79e055:compile
[INFO] +- org.apache.spark:spark-hadoop-cloud_2.11:jar:2.4.0-SNAPSHOT:compile
[INFO] |  +- org.apache.hadoop:hadoop-aws:jar:2.8.2-palantir.2:compile
[INFO] |  |  \- com.amazonaws:aws-java-sdk-s3:jar:1.11.45:compile
[INFO] |  |     +- com.amazonaws:aws-java-sdk-kms:jar:1.11.45:compile
[INFO] |  |     +- com.amazonaws:aws-java-sdk-core:jar:1.11.45:compile
[INFO] |  |     |  \- software.amazon.ion:ion-java:jar:1.0.1:compile
[INFO] |  |     \- com.amazonaws:jmespath-java:jar:1.0:compile
[INFO] |  +- org.apache.hadoop:hadoop-openstack:jar:2.8.2-palantir.2:compile
[INFO] |  |  \- commons-httpclient:commons-httpclient:jar:3.1:compile
[INFO] |  +- joda-time:joda-time:jar:2.9.9:compile
[INFO] |  +- com.fasterxml.jackson.core:jackson-annotations:jar:2.6.7:compile
[INFO] |  +- com.fasterxml.jackson.dataformat:jackson-dataformat-cbor:jar:2.6.7:compile
[INFO] |  +- org.apache.httpcomponents:httpclient:jar:4.5.4:compile
[INFO] |  |  \- commons-logging:commons-logging:jar:1.2:compile
[INFO] |  \- org.apache.httpcomponents:httpcore:jar:4.4.8:compile
[INFO] +- org.apache.hadoop:hadoop-azure-datalake:jar:2.8.2-palantir.2:compile
[INFO] |  +- com.microsoft.azure:azure-data-lake-store-sdk:jar:2.1.4:compile
[INFO] |  +- org.apache.hadoop:hadoop-common:jar:2.8.2-palantir.2:compile
[INFO] |  |  +- commons-cli:commons-cli:jar:1.2:compile
[INFO] |  |  +- xmlenc:xmlenc:jar:0.52:compile
[INFO] |  |  +- commons-io:commons-io:jar:2.4:compile
[INFO] |  |  +- commons-collections:commons-collections:jar:3.2.2:compile
[INFO] |  |  +- org.mortbay.jetty:jetty:jar:6.1.26:compile
[INFO] |  |  +- org.mortbay.jetty:jetty-util:jar:6.1.26:compile
[INFO] |  |  +- org.mortbay.jetty:jetty-sslengine:jar:6.1.26:compile
[INFO] |  |  +- javax.servlet.jsp:jsp-api:jar:2.1:runtime
[INFO] |  |  +- commons-configuration:commons-configuration:jar:1.6:compile
[INFO] |  |  |  +- commons-digester:commons-digester:jar:1.8:compile
[INFO] |  |  |  |  \- commons-beanutils:commons-beanutils:jar:1.9.3:compile
[INFO] |  |  |  \- commons-beanutils:commons-beanutils-core:jar:1.8.0:compile
[INFO] |  |  +- com.google.code.gson:gson:jar:2.2.4:compile
[INFO] |  |  +- org.apache.hadoop:hadoop-auth:jar:2.8.2-palantir.2:compile
[INFO] |  |  |  +- com.nimbusds:nimbus-jose-jwt:jar:3.9:compile
[INFO] |  |  |  |  +- net.jcip:jcip-annotations:jar:1.0:compile
[INFO] |  |  |  |  \- net.minidev:json-smart:jar:1.1.1:compile
[INFO] |  |  |  \- org.apache.directory.server:apacheds-kerberos-codec:jar:2.0.0-M15:compile
[INFO] |  |  |     +- org.apache.directory.server:apacheds-i18n:jar:2.0.0-M15:compile
[INFO] |  |  |     +- org.apache.directory.api:api-asn1-api:jar:1.0.0-M20:compile
[INFO] |  |  |     \- org.apache.directory.api:api-util:jar:1.0.0-M20:compile
[INFO] |  |  +- com.jcraft:jsch:jar:0.1.54:compile
[INFO] |  |  +- org.apache.curator:curator-client:jar:2.7.1:compile
[INFO] |  |  \- org.apache.htrace:htrace-core4:jar:4.0.1-incubating:compile
[INFO] |  \- com.squareup.okhttp:okhttp:jar:2.7.5:compile
[INFO] |     \- com.squareup.okio:okio:jar:1.13.0:compile
[INFO] +- org.apache.hadoop:hadoop-azure:jar:2.8.2-palantir.2:compile
[INFO] |  \- com.microsoft.azure:azure-storage:jar:2.2.0:compile
[INFO] +- com.google.guava:guava:jar:14.0.1:compile
[INFO] +- org.apache.spark:spark-yarn_2.11:jar:2.4.0-SNAPSHOT:compile
[INFO] |  +- org.apache.hadoop:hadoop-yarn-api:jar:2.8.2-palantir.2:compile
[INFO] |  +- org.apache.hadoop:hadoop-yarn-common:jar:2.8.2-palantir.2:compile
[INFO] |  |  +- javax.xml.bind:jaxb-api:jar:2.2.2:compile
[INFO] |  |  |  \- javax.xml.stream:stax-api:jar:1.0-2:compile
[INFO] |  |  +- org.codehaus.jackson:jackson-jaxrs:jar:1.9.13:compile
[INFO] |  |  +- org.codehaus.jackson:jackson-xc:jar:1.9.13:compile
[INFO] |  |  +- com.google.inject.extensions:guice-servlet:jar:3.0:compile
[INFO] |  |  \- com.google.inject:guice:jar:3.0:compile
[INFO] |  |     +- javax.inject:javax.inject:jar:1:compile
[INFO] |  |     \- aopalliance:aopalliance:jar:1.0:compile
[INFO] |  +- org.apache.hadoop:hadoop-yarn-server-web-proxy:jar:2.8.2-palantir.2:compile
[INFO] |  |  \- org.apache.hadoop:hadoop-yarn-server-common:jar:2.8.2-palantir.2:compile
[INFO] |  \- org.apache.hadoop:hadoop-yarn-client:jar:2.8.2-palantir.2:compile
[INFO] +- org.apache.spark:spark-kubernetes_2.11:jar:2.4.0-SNAPSHOT:compile
[INFO] |  +- io.fabric8:kubernetes-client:jar:3.0.0:compile
[INFO] |  |  +- io.fabric8:kubernetes-model:jar:2.0.0:compile
[INFO] |  |  |  \- com.fasterxml.jackson.module:jackson-module-jaxb-annotations:jar:2.6.7:compile
[INFO] |  |  +- com.squareup.okhttp3:logging-interceptor:jar:3.9.1:compile
[INFO] |  |  +- io.fabric8:zjsonpatch:jar:0.3.0:compile
[INFO] |  |  \- com.github.mifmif:generex:jar:1.0.1:compile
[INFO] |  |     \- dk.brics.automaton:automaton:jar:1.11-8:compile
[INFO] |  +- com.fasterxml.jackson.dataformat:jackson-dataformat-yaml:jar:2.6.7:compile
[INFO] |  |  \- org.yaml:snakeyaml:jar:1.15:compile
[INFO] |  \- com.squareup.okhttp3:okhttp:jar:3.9.1:compile
[INFO] +- com.palantir.spark.influx:spark-influx-sink:jar:0.3.12:compile
[INFO] |  \- com.izettle:dropwizard-metrics-influxdb:jar:1.1.8:runtime
[INFO] |     +- io.dropwizard:dropwizard-metrics:jar:0.9.2:runtime
[INFO] |     |  +- io.dropwizard:dropwizard-lifecycle:jar:0.9.2:runtime
[INFO] |     |  |  +- org.eclipse.jetty:jetty-server:jar:9.4.8.v20171121:provided
[INFO] |     |  |  |  +- org.eclipse.jetty:jetty-http:jar:9.4.8.v20171121:provided
[INFO] |     |  |  |  |  \- org.eclipse.jetty:jetty-util:jar:9.4.8.v20171121:provided
[INFO] |     |  |  |  \- org.eclipse.jetty:jetty-io:jar:9.4.8.v20171121:provided
[INFO] |     |  |  \- io.dropwizard:dropwizard-util:jar:0.9.2:runtime
[INFO] |     |  +- io.dropwizard:dropwizard-jackson:jar:0.9.2:runtime
[INFO] |     |  |  +- com.fasterxml.jackson.datatype:jackson-datatype-jdk7:jar:2.6.7:runtime
[INFO] |     |  |  +- com.fasterxml.jackson.datatype:jackson-datatype-guava:jar:2.6.7:runtime
[INFO] |     |  |  +- com.fasterxml.jackson.module:jackson-module-afterburner:jar:2.6.7:runtime
[INFO] |     |  |  \- com.fasterxml.jackson.datatype:jackson-datatype-joda:jar:2.6.7:runtime
[INFO] |     |  \- io.dropwizard:dropwizard-validation:jar:0.9.2:runtime
[INFO] |     |     +- org.hibernate:hibernate-validator:jar:5.2.2.Final:runtime
[INFO] |     |     |  +- org.jboss.logging:jboss-logging:jar:3.2.1.Final:runtime
[INFO] |     |     |  \- com.fasterxml:classmate:jar:1.1.0:runtime
[INFO] |     |     \- org.glassfish:javax.el:jar:3.0.0:runtime
[INFO] |     \- com.izettle:metrics-influxdb:jar:1.1.8:runtime
[INFO] +- org.spark-project.spark:unused:jar:1.0.0:compile
[INFO] +- org.scalatest:scalatest_2.11:jar:3.0.3:test
[INFO] |  +- org.scalactic:scalactic_2.11:jar:3.0.3:test
[INFO] |  +- org.scala-lang:scala-reflect:jar:2.11.8:compile
[INFO] |  \- org.scala-lang.modules:scala-xml_2.11:jar:1.0.5:compile
[INFO] +- junit:junit:jar:4.12:test
[INFO] |  \- org.hamcrest:hamcrest-core:jar:1.3:test
[INFO] \- com.novocode:junit-interface:jar:0.11:test
[INFO]    \- org.scala-sbt:test-interface:jar:1.0:test

However with coursier:

coursier resolve -t org.apache.spark:spark-dist_2.11-hadoop-palantir:2.4.0-palantir.18 -F hadoop-cloud -F hadoop-palantir -F kinesis-asl -F kubernetes -F yarn -F sparkr -r bintray:palantir/releases

I can see that dependencies that should be transitively excluded from e.g. hadoop-common, according to this block in the parent POM of the resolved coordinate, are in fact not (snippet):

└─ org.apache.spark:spark-dist_2.11-hadoop-palantir:2.4.0-palantir.7
   ├─ com.google.guava:guava:14.0.1 -> 19.0 (possible incompatibility)
   ...
   ├─ org.apache.hadoop:hadoop-azure-datalake:2.8.2-palantir.2
   │  ├─ com.microsoft.azure:azure-data-lake-store-sdk:2.1.4
   │  │  ├─ com.fasterxml.jackson.core:jackson-core:2.7.4 -> 2.7.9
   │  │  └─ org.slf4j:slf4j-api:1.7.21 -> 1.7.25
   │  ├─ com.squareup.okhttp:okhttp:2.4.0
   │  │  └─ com.squareup.okio:okio:1.4.0 -> 1.13.0 (possible incompatibility)
   │  └─ org.apache.hadoop:hadoop-common:2.8.2-palantir.2
   │     ├─ com.google.code.findbugs:jsr305:3.0.0 -> 3.0.2
   │     ├─ com.google.code.gson:gson:2.2.4
   │     ├─ com.google.guava:guava:11.0.2 -> 19.0 (possible incompatibility)
   │     ├─ com.google.protobuf:protobuf-java:2.5.0
   │     ├─ com.jcraft:jsch:0.1.54
   │     ├─ com.sun.jersey:jersey-core:1.9
   │     ├─ com.sun.jersey:jersey-json:1.9
...

Specifically pointing out the com.sun.jersey dependencies that are excluded because of

<exclusion>
            <groupId>com.sun.jersey</groupId>
            <artifactId>*</artifactId>
</exclusion>

in the block linked above.

@dansanduleac dansanduleac changed the title Exclusions defined in dependencyManagment don't apply transitively Exclusions defined in dependencyManagement don't apply transitively May 4, 2018
@derrley
Copy link

derrley commented Jun 8, 2018

I just ran into this myself. Does anyone know of a good workaround?

@jin
Copy link

jin commented Aug 29, 2019

This issue has shown up with a user of rules_jvm_external: bazelbuild/rules_jvm_external#233

We can work around this by explicitly excluding the artifact, but it'll likely be a confusing first-time experience for users running into this problem. It'll be great to have support for this.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants