You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何从maven-bundle-plugin 5.1.9排除/替换commons-collections 3.2

解决maven-bundle-plugin依赖commons-collections 3.2安全漏洞的方案

下面提供几种可行的修复方案,可根据你的项目场景选择:

方案1:直接替换maven-bundle-plugin的依赖版本

针对插件自身依赖的旧版本commons-collections,直接在插件配置中指定安全版本,覆盖默认依赖:

<plugin>
    <groupId>org.apache.felix</groupId>
    <artifactId>maven-bundle-plugin</artifactId>
    <version>5.1.9</version>
    <extensions>true</extensions>
    <configuration>
        <!-- 保留原有的instructions配置 -->
        <instructions>
            <Import-Package><![CDATA[
             !org.eclipse.jdt.core.compiler,
             com.google.common.base,
             org.eclipse.gemini.blueprint.extensions.annotation,
             org.springframework.data.mapping,
             org.springframework.util,
             !com.querydsl.apt,
             !com.mysema.codegen,
             *
             ]]></Import-Package>
             <Embed-Dependency>
                spring-data-commons;scope=runtime,
                spring-data-mongodb;scope=runtime,
                xmlprojector
             </Embed-Dependency>
        </instructions>
    </configuration>
    <dependencies>
        <!-- 强制插件使用安全版本的commons-collections -->
        <dependency>
            <groupId>org.apache.commons</groupId>
            <artifactId>commons-collections</artifactId>
            <version>3.2.2</version> <!-- 修复漏洞的版本 -->
        </dependency>
    </dependencies>
</plugin>

方案2:全局锁定安全版本(推荐)

在项目的dependencyManagement中添加版本强制规则,让所有模块(包括插件)统一使用安全版本,无需单独修改插件配置:

<project>
    <!-- 其他配置保持不变 -->
    <dependencyManagement>
        <dependencies>
            <dependency>
                <groupId>org.apache.commons</groupId>
                <artifactId>commons-collections</artifactId>
                <version>3.2.2</version>
            </dependency>
        </dependencies>
    </dependencyManagement>
    <!-- 其他配置保持不变 -->
</project>

方案3:处理嵌入依赖的传递问题

如果漏洞版本是通过Embed-Dependency中的组件(如spring-data-commons)间接引入的,可在嵌入时排除旧版本,并结合版本锁定使用安全版本:

<Embed-Dependency>
    spring-data-commons;scope=runtime;excludes=org.apache.commons:commons-collections,
    spring-data-mongodb;scope=runtime;excludes=org.apache.commons:commons-collections,
    xmlprojector
</Embed-Dependency>

验证修复结果

执行以下命令检查依赖树,确认commons-collections已替换为安全版本:

# 检查项目依赖树
mvn dependency:tree -Dverbose -Dincludes=org.apache.commons:commons-collections

# 单独检查maven-bundle-plugin的依赖树
mvn org.apache.maven.plugins:maven-dependency-plugin:3.6.1:tree -Dplugin=org.apache.felix:maven-bundle-plugin -Dverbose -Dincludes=org.apache.commons:commons-collections

内容的提问来源于stack exchange,提问作者Erik Torres

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.16 13:50:13