You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

为何Gradle并非始终遵循依赖约束配置?

Gradle依赖约束未生效问题

问题场景

在Gradle项目开发中,发现Gradle并未始终遵循已声明的依赖约束。例如spring-boot-starter-tomcat:3.1.3会引入tomcat-embed-core,但其依赖的10.1.12版本存在公开的CVE-2023-41080漏洞,原本计划通过依赖约束将版本升级至无漏洞的10.1.13,但配置后并未生效。

配置示例

dependencies {
    implementation('org.springframework.boot:spring-boot-starter-tomcat:3.1.3')
    constraints {
        // 升级Tomcat嵌入版本,修复10.1.12版本的CVE漏洞
        implementation('org.apache.tomcat.embed:tomcat-embed-websocket:10.1.13') {
            because '...'
        }
        implementation('org.apache.tomcat.embed:tomcat-embed-core:10.1.13') {
            because '...'
        }
        implementation('org.apache.tomcat.embed:tomcat-embed-el:10.1.13') {
            because '...'
        }
    }
}

依赖树解析结果

compileClasspath - Compile classpath for source set 'main'.
+--- org.springframework.boot:spring-boot-starter-tomcat:3.1.3
|    +--- jakarta.annotation:jakarta.annotation-api:2.1.1
|    +--- org.apache.tomcat.embed:tomcat-embed-core:10.1.12
|    +--- org.apache.tomcat.embed:tomcat-embed-el:10.1.12
|    \--- org.apache.tomcat.embed:tomcat-embed-websocket:10.1.12
|         \--- org.apache.tomcat.embed:tomcat-embed-core:10.1.12
+--- org.apache.tomcat.embed:tomcat-embed-core:10.1.13 -> 10.1.12 (c)
+--- org.apache.tomcat.embed:tomcat-embed-el:10.1.13 -> 10.1.12 (c)
\--- org.apache.tomcat.embed:tomcat-embed-websocket:10.1.13 -> 10.1.12 (c)

疑问

Gradle文档提到:

开发人员经常通过添加直接依赖来错误地解决传递依赖问题。为避免这种情况,Gradle提供了依赖约束的概念。

但目前只有添加直接依赖才能成功升级Tomcat版本,请问对依赖约束的理解存在哪些误区?为何Gradle不遵循这些配置?


内容的提问来源于stack exchange,提问作者Chris

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.11 10:56:14