如何避免继承的Maven插件执行扩散至孙级POM?
解决方案
有两种可靠的方式实现仅让一级子POM执行OWASP依赖检查插件,具体如下:
方案一:通过项目父级判断自动跳过孙级模块(无需修改子POM)
利用Maven内置的项目属性,在超级POM的profile中配置插件的skip参数,仅当当前项目直接继承超级POM时执行检查,孙级模块自动跳过。
修改超级POM中的profile配置:
<profile> <id>dependencycheck</id> <build> <plugins> <plugin> <groupId>org.owasp</groupId> <artifactId>dependency-check-maven</artifactId> <configuration> <!-- 将`super-pom-artifact-id`替换为你的超级POM实际artifactId --> <skip>${!project.parent.artifactId.equals('super-pom-artifact-id')}</skip> </configuration> <executions> <execution> <goals> <goal>check</goal> </goals> <!-- 绑定到合适的生命周期阶段,比如verify --> <phase>verify</phase> </execution> </executions> </plugin> </plugins> </build> </profile>
原理:
- 一级子POM(Module1/Module2)的父级是超级POM,
project.parent.artifactId匹配超级POM的ID,因此skip为false,执行检查。 - 孙级模块的父级是Module1/Module2,
project.parent.artifactId不匹配超级POM的ID,因此skip为true,自动跳过检查。
方案二:通过pluginManagement+inherited属性控制继承范围
先在超级POM的profile中统一管理插件配置,再在一级子POM中显式引用并禁止继承给孙级模块。
步骤1:超级POM的profile配置
<profile> <id>dependencycheck</id> <build> <pluginManagement> <plugins> <plugin> <groupId>org.owasp</groupId> <artifactId>dependency-check-maven</artifactId> <executions> <execution> <goals> <goal>check</goal> </goals> <phase>verify</phase> </execution> </executions> </plugin> </plugins> </pluginManagement> </build> </profile>
步骤2:一级子POM(Module1/Module2)中引用插件
在每个需要执行检查的一级子POM的<build><plugins>节点添加:
<plugin> <groupId>org.owasp</groupId> <artifactId>dependency-check-maven</artifactId> <inherited>false</inherited> </plugin>
原理:
- 超级POM的
pluginManagement统一定义插件的执行规则,确保所有子项目可以复用配置。 - 一级子POM显式引用插件并设置
<inherited>false</inherited>,意味着该插件配置不会被孙级模块继承,从而避免孙级执行检查。
内容的提问来源于stack exchange,提问作者Morgoth
相关产品推荐
相关产品推荐

