如何解决poi-ooxml与jersey-server间的commons-io依赖冲突?
我们的项目里用了jersey-server (2.28)和poi-ooxml(5.2.5),这俩包都把commons-io当子依赖:
poi-ooxml依赖的是commons-io 2.15版本jersey依赖的是commons-io 2.11版本,就算把jersey更到最新版也还是这样
跑项目的时候碰到了这个错误:
<[ACTIVE] ExecuteThread:
'1' for queue: 'weblogic.kernel.Default (self-tuning)'> <> <> <> <> <[severity-value: 8] [rid: 0] [partition-id: 0] [partition-name: DOMAIN] > <[ServletContext@264727129 [app:abc
module:abc.war path:null spec-version: 3.1]] Root cause of ServletException. org.glassfish.jersey.server.ContainerException: java.lang.NoSuchMethodError:
org.apache.commons.io.output.UnsynchronizedByteArrayOutputStream.builder()Lorg/apache/commons/io/output/UnsynchronizedByteArrayOutputStreamSBuilder
我们已经在pom.xml里显式加了commons-io 2.15.1的依赖,本来想让项目只用这个版本,但问题还是没解决,初步判断是依赖冲突导致的,求解决办法。
编辑1:项目pom.xml内容如下
<dependencies> <dependency> <groupId>junit</groupId> <artifactId>junit</artifactId> <version>4.12</version> <scope>test</scope> </dependency> <dependency> <groupId>org.glassfish.jersey.containers</groupId> <artifactId>jersey-container-servlet-core</artifactId> <version>2.28</version> </dependency> <dependency> <groupId>org.glassfish.jersey.core</groupId> <artifactId>jersey-client</artifactId> <version>2.28</version> </dependency> <dependency> <groupId>org.codehaus.jackson</groupId> <artifactId>jackson-jaxrs</artifactId> <version>1.9.14.jdk17-redhat-00001</version> </dependency> <dependency> <groupid> org.apache.commons </groupid> <artifactId>commons-collections4</artifactId> <version>4.1</version> </dependency> <dependency> <groupId>javax.xml</groupId> <artifactId>jaxb-impl</artifactId> <version>2.1</version> </dependency> <dependency> <groupId>org.jvnet.staxex</groupId> <artifactId>stax-ex</artifactId> <version>1.7.7</version> </dependency> <dependency> <groupId>org.apache.poi</groupId> <artifactId>poi-ooxml-schemas</artifactId> <version>4.1.2</version> </dependency> <dependency> <groupId>org.apache.xmlbeans</groupId> <artifactId>xmlbeans</artifactId> <version>5.0.3</version> <!--3.1.0--> </dependency> <dependency> <groupId>org.codehaus.jackson</groupId> <artifactId>jackson-xc</artifactId> <version>1.9.14.jdk17-redhat-00001</version> </dependency> <dependency> <groupId>cglib</groupId> <artifactId>cglib</artifactId> <version>3.2.6</version> </dependency> <dependency> <groupId>org.apache.poi</groupId> <artifactId>poi-ooxml</artifactId> <version>5.2.5</version> </dependency> <dependency> <groupId>org.apache.commons</groupId> <artifactId>commons-collections4</artifactId> <version>4.1</version> </dependency> <!--dependency> <groupId>org.glassfish.jersey.media</groupId> <artifactId>jersey-media-json</artifactId> <version>2.0-m05-1</version> </dependency--> <dependency> <groupId>org.codehaus.jackson</groupId> <artifactId>jackson-core-asl</artifactId> <version>1.9.14.jdk17-redhat-00001</version> </dependency> <dependency> <groupId>org.codehaus.jackson</groupId> <artifactId>jackson-mapper-asl</artifactId> <version>1.9.14.jdk17-redhat-00001</version> </dependency> <dependency> <groupId>clojure-interop</groupId> <artifactId>javax.net</artifactId> <version>1.0.0</version> </dependency> <dependency> <groupId>javax.activation</groupId> <artifactId>activation</artifactId> <version>2.1.3</version> </dependency> <dependency> <groupId>org.ow2.asm</groupId> <artifactId>asm</artifactId> <version>9.6</version> </dependency> <dependency> <groupId>org.daisy.pipeline</groupId> <artifactId>common-stax</artifactId> <version>1.0.0</version> </dependency> <dependency> <groupId>org.daisy.pipeline</groupId> <artifactId>common-stax</artifactId> <version>1.0.0</version> </dependency> <dependency> <groupId>org.daisy.pipeline</groupId> <artifactId>common-utils</artifactId> <version>6.0.0</version> </dependency> <dependency> <groupId>commons-codec</groupId> <artifactId>commons-codec</artifactId> <version>1.17.0</version> </dependency> <dependency> <groupId>commons-fileupload</groupId> <artifactId>commons-fileupload</artifactId> <version>2.0</version> </dependency> <dependency> <groupId>com.github.virtuald</groupId> <artifactId>curvesapi</artifactId> <version>1.08</version> </dependency> <dependency> <groupId>org.daisy.pipeline</groupId> <artifactId>framework-core</artifactId> <version>8.0.1</version> </dependency> <dependency> <groupId>com.google.guava</groupId> <artifactId>guava</artifactId> <version>33.2.1-jre</version> </dependency> <dependency> <groupId>commons-io</groupId> <artifactId>commons-io</artifactId> <version>2.15.1</version> </dependency> </dependencies>
先确认实际依赖版本
直接在项目根目录运行mvn dependency:tree命令,查看项目最终引入的commons-io版本,以及哪个依赖还在带旧版本进来,明确冲突的源头。排除jersey的旧版本依赖
在pom.xml里的jersey依赖中,显式排除它自带的commons-io 2.11,确保项目只加载你指定的2.15.1版本。修改后的jersey依赖如下:<dependency> <groupId>org.glassfish.jersey.containers</groupId> <artifactId>jersey-container-servlet-core</artifactId> <version>2.28</version> <exclusions> <exclusion> <groupId>commons-io</groupId> <artifactId>commons-io</artifactId> </exclusion> </exclusions> </dependency> <dependency> <groupId>org.glassfish.jersey.core</groupId> <artifactId>jersey-client</artifactId> <version>2.28</version> <exclusions> <exclusion> <groupId>commons-io</groupId> <artifactId>commons-io</artifactId> </exclusion> </exclusions> </dependency>验证并重新构建
再跑一遍mvn dependency:tree,确认commons-io只有2.15.1版本被引入。然后执行mvn clean install重新构建项目,部署后测试是否还会出现错误。WebLogic特殊处理
如果是在WebLogic上部署,还要注意WebLogic自身可能自带旧版本的commons-io,导致类加载优先级问题。可以在项目的weblogic.xml里加配置,强制WebLogic优先用项目里的jar包:<container-descriptor> <prefer-web-inf-classes>true</prefer-web-inf-classes> </container-descriptor>或者更精准地指定只优先加载
commons-io:<container-descriptor> <prefer-application-packages> <package-name>org.apache.commons.io.*</package-name> </prefer-application-packages> </container-descriptor>
内容的提问来源于stack exchange,提问作者some_programmer

