Skip to content

Remove duplicate assertj-core dependency rejected by Maven 3.10 - #320

Merged
vharseko merged 1 commit into
OpenIdentityPlatform:masterfrom
vharseko:fix-duplicate-assertj-maven-3.10
Oct 9, 2026
Merged

vharseko merged 1 commit into
OpenIdentityPlatform:masterfrom
vharseko:fix-duplicate-assertj-maven-3.10

Conversation

@vharseko

@vharseko vharseko commented Oct 9, 2026

Copy link
Copy Markdown
Member

Problem

The Release Maven run for 3.2.1 (run 37949221344) failed while Maven was still reading the project models:

[ERROR] 'dependencies.dependency.(groupId:artifactId:type:classifier)' must be unique: org.assertj:assertj-core:jar -> duplicate declaration of version (?) @ line 52, column 21
[ERROR] The project org.openidentityplatform.commons.http-framework:binding-test-utils:3.2.1-SNAPSHOT ... has 1 error

commons/http-framework/binding-test-utils/pom.xml declares org.assertj:assertj-core twice. The duplicate is old: Maven 3.9.x only logged a [WARNING] about it, as the successful 3.2.0 release run shows (run 36534373230). The runner image ubuntu24/20261004.327 updated the system Maven from 3.9.16 to 3.10.0. Maven 3.10.0 reports the same problem as an error, so the reactor fails before any build step runs. This affects every workflow that uses the system mvn on ubuntu-24.04, not only the release.

Fix

Keep one assertj-core declaration (the first one) and give it scope compile. Under Maven 3.9 the second declaration was the one in effect, and it had compile scope. With this change the resolved scope and the dependency order stay the same.

Verification

  • help:effective-pom for the module is byte-for-byte identical before and after the change.
  • Ran validate on the full reactor with Maven 3.10.0. With the original POM it reproduces the CI error exactly. With this change it ends in BUILD SUCCESS.

Maven 3.10.0 (now the default on the ubuntu-24.04 runner image) treats
duplicate dependency declarations as a model error instead of a warning,
which broke the 3.2.1 release build. Keep a single declaration with the
effective compile scope.
@vharseko vharseko added bug dependencies Pull requests that update a dependency file ci Build, CI/CD, JDK matrix and workflow changes labels Oct 9, 2026
@vharseko
vharseko merged commit fd569de into OpenIdentityPlatform:master Oct 9, 2026
14 checks passed
@vharseko
vharseko deleted the fix-duplicate-assertj-maven-3.10 branch October 9, 2026 16:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug ci Build, CI/CD, JDK matrix and workflow changes dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant