如何从命令行覆盖Maven插件父依赖maven-reporting-impl版本?
当前使用Maven 3.9.8版本,执行以下命令调用maven-dependency-plugin以满足漏洞扫描的依赖整合需求:
mvn -X -U -e clean compile package --settings $MAVEN_SETTINGS_XML dependency:copy-dependencies -DincludeScope=runtime -DexcludeScope=provided
Maven 3.9.8默认内置的maven-dependency-plugin版本为3.7.0,该版本通过父依赖maven-reporting-impl 3.2.0引入了存在漏洞的jdom 1.1版本,而此版本的jdom已被Nexus隔离,导致构建失败。
尝试强制使用maven-dependency-plugin 3.7.1版本,命令如下,但该版本仍依赖maven-reporting-impl 3.2.0(进而引入jdom 1.1):
mvn -X -U -e clean compile package --settings $MAVEN_SETTINGS_XML org.apache.maven.plugins:maven-dependency-plugin:3.7.1:copy-dependencies -DincludeScope=runtime -DexcludeScope=provided
已知maven-reporting-impl 4.0.0-M15版本不再依赖jdom,但尝试通过官方文档建议的-DpluginVersion参数指定该版本无效(推测因为maven-reporting-impl是插件的父依赖而非插件本身):
mvn -X -U -e clean compile package --settings $MAVEN_SETTINGS_XML org.apache.maven.plugins:maven-dependency-plugin:3.7.1:copy-dependencies -DpluginVersion=org.apache.maven.reporting:maven-reporting-impl:4.0.0-M15 -DincludeScope=runtime -DexcludeScope=provided
需要找到优先通过命令行覆盖maven-reporting-impl版本为4.0.0-M15的方法。
命令行优先方案
Maven支持通过系统属性强制指定任意依赖的版本,语法为-D<groupId>:<artifactId>:version=<目标版本>。针对此场景,直接在命令行添加该参数即可覆盖maven-reporting-impl的版本:
mvn -X -U -e clean compile package --settings $MAVEN_SETTINGS_XML \ org.apache.maven.plugins:maven-dependency-plugin:3.7.1:copy-dependencies \ -DincludeScope=runtime -DexcludeScope=provided \ -Dorg.apache.maven.reporting:maven-reporting-impl:version=4.0.0-M15
此方式会强制Maven在解析maven-dependency-plugin的依赖时,使用指定的maven-reporting-impl版本,从而避免引入jdom 1.1。
备选:settings.xml配置方案
如果命令行方式无法生效,可在Maven的settings.xml中添加一个激活的profile,通过dependencyManagement强制指定版本:
<settings> <profiles> <profile> <id>override-reporting-impl-version</id> <activation> <activeByDefault>true</activeByDefault> </activation> <dependencyManagement> <dependencies> <dependency> <groupId>org.apache.maven.reporting</groupId> <artifactId>maven-reporting-impl</artifactId> <version>4.0.0-M15</version> </dependency> </dependencies> </dependencyManagement> </profile> </profiles> </settings>
之后执行原命令即可自动应用该版本覆盖。
内容的提问来源于stack exchange,提问作者JoshDM

