在我們平時的開發過程中,常常會遇到引入各種不同的 jar 包,然后引發的 Maven
依賴沖突,今天我們來學習下如何使用 Maven 命令檢測 pom.xml
中的重復依賴項。
為什么要檢測重復的依賴關系
在pom.xml
中, 經常引入各種不同的jar 包, 又會依賴其他的jar。特別是一些常用的工具庫,比較容易出現版本沖突,例如,讓我們看下這個pom.xml
。
< project >
[...]
< dependencies >
< dependency >
< groupId >org.apache.commons< /groupId >
< artifactId >commons-lang3< /artifactId >
< version >3.12.0< /version >
< /dependency >
< dependency >
< groupId >org.apache.commons< /groupId >
< artifactId >commons-lang3< /artifactId >
< version >3.11< /version >
< /dependency >
< /dependencies >
[...]
< /project >
從上面的代碼中,commons-lang3
被引用了兩次,而且版本號也不一樣?,F在我們就來看看如何使用Maven命令來檢測這些重復的依賴關系。
依賴樹命令
讓我們在終端運行 mvn dependency:tree
的命令,看看輸出結果
$ mvn dependency:tree
[INFO] Scanning for projects...
[WARNING]
[WARNING] Some problems were encountered while building the effective model for com.javanorth:maven-duplicate-dependencies:jar:0
.0.1-SNAPSHOT
[WARNING] 'dependencies.dependency.(groupId:artifactId:type:classifier)' must be unique: org.apache.commons:commons-lang3:jar -
> version 3.12.0 vs 3.11 @ line 14, column 15
[WARNING]
[WARNING] It is highly recommended to fix these problems because they threaten the stability of your build.
[WARNING]
[WARNING] For this reason, future Maven versions might no longer support building such malformed projects.
[WARNING]
[INFO]
[INFO] -------------< com.javanorth:maven-duplicate-dependencies >--------------
[INFO] Building maven-duplicate-dependencies 0.0.1-SNAPSHOT
[INFO] --------------------------------[ jar ]---------------------------------
[INFO]
[INFO] --- maven-dependency-plugin:2.8:tree (default-cli) @ maven-duplicate-dependencies ---
[WARNING] The artifact xml-apis:xml-apis:jar:2.0.2 has been relocated to xml-apis:xml-apis:jar:1.0.b2
[INFO] com.javanorth:maven-duplicate-dependencies:jar:0.0.1-SNAPSHOT
[INFO] - org.apache.commons:commons-lang3:jar:3.11:compile
[INFO] ------------------------------------------------------------------------
[INFO] BUILD SUCCESS
[INFO] ------------------------------------------------------------------------
[INFO] Total time: 1.136 s
...
我們可以看到,commons-lang3
jar的3.11版和 3.12 版同時被引入進來了,出現這種情況是因為Maven選擇了pom.xml
中后來出現的依賴。
依賴關系analyze-duplicate
命令
現在讓我們運行 mvn dependency:analyze-duplicate
,看看輸出輸出結果。
$ mvn dependency:analyze-duplicate
[INFO] Scanning for projects...
[WARNING]
[WARNING] Some problems were encountered while building the effective model for com.javanorth:maven-duplicate-dependencies:jar:0
.0.1-SNAPSHOT
[WARNING] 'dependencies.dependency.(groupId:artifactId:type:classifier)' must be unique: org.apache.commons:commons-lang3:jar -
> version 3.12.0 vs 3.11 @ line 14, column 15
[WARNING]
[WARNING] It is highly recommended to fix these problems because they threaten the stability of your build.
[WARNING]
[WARNING] For this reason, future Maven versions might no longer support building such malformed projects.
[WARNING]
[INFO]
[INFO] -------------< com.javanorth:maven-duplicate-dependencies >--------------
[INFO] Building maven-duplicate-dependencies 0.0.1-SNAPSHOT
[INFO] --------------------------------[ jar ]---------------------------------
[INFO]
[INFO] --- maven-dependency-plugin:2.8:analyze-duplicate (default-cli) @ maven-duplicate-dependencies ---
[WARNING] The artifact xml-apis:xml-apis:jar:2.0.2 has been relocated to xml-apis:xml-apis:jar:1.0.b2
[INFO] List of duplicate dependencies defined in < dependencies/ > in your pom.xml:
o org.apache.commons:commons-lang3:jar
[INFO] ------------------------------------------------------------------------
[INFO] BUILD SUCCESS
[INFO] ------------------------------------------------------------------------
[INFO] Total time: 0.835 s
。。。
我們注意到,WARNING
和INFO
日志語句都提到了重復依賴的存在。
如果存在重復的依賴,則構建失敗
在上面的例子中,我們看到了如何檢測重復的依賴關系,但BUILD
仍然是成功的,但這可能導致使用了不正確的 jar 版本。
使用[Maven Enforcer Plugin](https://maven.apache.org/enforcer/maven-enforcer-plugin/index.html),我們可以確保在存在重復依賴的情況下構建不成功。
我們需要在pom.xml
中加入這個Maven插件,并加入banDuplicatePomDependencyVersions
規則。
< project >
[...]
< build >
< plugins >
< plugin >
< groupId >org.apache.maven.plugins< /groupId >
< artifactId >maven-enforcer-plugin< /artifactId >
< version >3.0.0< /version >
< executions >
< execution >
< id >no-duplicate-declared-dependencies< /id >
< goals >
< goal >enforce< /goal >
< /goals >
< configuration >
< rules >
< banDuplicatePomDependencyVersions/ >
< /rules >
< /configuration >
< /execution >
< /executions >
< /plugin >
< /plugins >
< /build >
[...]
< /project >
現在,該規則約束了我們的Maven構建。
$ mvn verify
[INFO] Scanning for projects...
[WARNING]
[WARNING] Some problems were encountered while building the effective model for com.javanorth:maven-duplicate-dependencies:jar:0
.0.1-SNAPSHOT
[WARNING] 'dependencies.dependency.(groupId:artifactId:type:classifier)' must be unique: org.apache.commons:commons-lang3:jar -
> version 3.12.0 vs 3.11 @ line 14, column 14
[WARNING]
[INFO] -------------< com.javanorth:maven-duplicate-dependencies >--------------
[INFO] Building maven-duplicate-dependencies 0.0.1-SNAPSHOT
[INFO] --------------------------------[ jar ]---------------------------------
[INFO]
[INFO] --- maven-enforcer-plugin:3.0.0:enforce (no-duplicate-declared-dependencies) @ maven-duplicate-dependencies ---
[WARNING] Rule 0: org.apache.maven.plugins.enforcer.BanDuplicatePomDependencyVersions failed with message:
Found 1 duplicate dependency declaration in this project:
- dependencies.dependency[org.apache.commons:commons-lang3:jar] ( 2 times )
[INFO] ------------------------------------------------------------------------
[INFO] BUILD FAILURE
[INFO] ------------------------------------------------------------------------
[ERROR] Failed to execute goal org.apache.maven.plugins:maven-enforcer-plugin:3.0.0:enforce (no-duplicate-declared-dependencies) on project maven-duplicate-dependencie
s: Some Enforcer rules have failed. Look above for specific messages explaining why the rule failed.
刪除重復的依賴關系
只要確定了重復的依賴關系,我們就需要在 pom.xml
中刪除它們,只保留那些我們項目使用的唯一依賴關系。
總結
本文中,我們學習了如何使用mvn dependency:tree
和mvn dependency:analyze-duplicate
命令檢測Maven中的重復依賴,還學習了如何使用Maven Enforcer插件,通過應用內置規則使包含重復依賴的構建失敗。
-
開發
+關注
關注
0文章
370瀏覽量
40842 -
日志
+關注
關注
0文章
138瀏覽量
10642 -
maven
+關注
關注
0文章
30瀏覽量
3709
發布評論請先 登錄
相關推薦
評論