升级Wiremock至2.35.0后生成的JAR未含依赖,如何解决?
问题描述
为修复安全漏洞,将Wiremock版本升级至2.35.0,已更新pom.xml中的依赖及Wiremock本身。执行命令mvn -Dmaven.wagon.http.ssl.insecure=true install -DskipTests后,生成的wiremock-body-transformer.jar仅20kb,远小于旧版本(2.17.0)的大小,推测未包含依赖。尝试更换非standalone版本的Wiremock,问题依旧。当前pom.xml代码如下:
<?xml version="1.0" encoding="UTF-8"?> <project xmlns="http://maven.apache.org/POM/4.0.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 http://maven.apache.org/xsd/maven-4.0.0.xsd"> <modelVersion>4.0.0</modelVersion> <groupId>com.*****.wiremock</groupId> <artifactId>wiremock-body-transformer</artifactId> <version>1.0.3-SNAPSHOT</version> <packaging>jar</packaging> <name>Wiremock Body Transformer</name> <description>A Wiremock extensions to transform the response body, http request call back and additional admin API.</description> <developers> <developer> <name>*****</name> <organization>*****</organization> <organizationUrl>http://www.*****.com/</organizationUrl> </developer> </developers> <scm> <connection>scm:git:git@github.com/opentable/wiremock-body-transformer.git</connection> <developerConnection>scm:git:git@github.com/opentable/wiremock-body-transformer.git</developerConnection> <url>https://github.com/opentable/wiremock-body-transformer.git</url> <tag>HEAD</tag> </scm> <build> <plugins> <plugin> <artifactId>maven-assembly-plugin</artifactId> <configuration> <archive> <manifest> <mainClass>fully.qualified.MainClass</mainClass> </manifest> </archive> <descriptorRefs> <descriptorRef>jar-with-dependencies</descriptorRef> </descriptorRefs> </configuration> </plugin> <plugin> <groupId>org.apache.maven.plugins</groupId> <artifactId>maven-compiler-plugin</artifactId> <version>3.1</version> <configuration> <source>1.7</source> <target>1.7</target> </configuration> </plugin> </plugins> </build> <dependencies> <!-- https://mvnrepository.com/artifact/com.github.tomakehurst/wiremock-jre8-standalone --> <dependency> <groupId>com.github.tomakehurst</groupId> <artifactId>wiremock-jre8-standalone</artifactId> <version>2.35.0</version> </dependency> <dependency> <groupId>com.fasterxml.jackson.dataformat</groupId> <artifactId>jackson-dataformat-xml</artifactId> <version>2.14.2</version> </dependency> <dependency> <groupId>com.fasterxml.jackson.core</groupId> <artifactId>jackson-databind</artifactId> <version>2.14.2</version> </dependency> <!-- tests dependencies --> <dependency> <groupId>org.hamcrest</groupId> <artifactId>hamcrest-core</artifactId> <version>2.2</version> <scope>test</scope> </dependency> <dependency> <groupId>org.hamcrest</groupId> <artifactId>hamcrest-library</artifactId> <version>2.2</version> <scope>test</scope> </dependency> <dependency> <groupId>junit</groupId> <artifactId>junit</artifactId> <version>4.13.2</version> <scope>test</scope> </dependency> <dependency> <groupId>io.rest-assured</groupId> <artifactId>rest-assured</artifactId> <version>5.3.0</version> <scope>test</scope> </dependency> <dependency> <groupId>org.apache.commons</groupId> <artifactId>commons-lang3</artifactId> <version>3.12.0</version> <scope>compile</scope> </dependency> <dependency> <groupId>com.mashape.unirest</groupId> <artifactId>unirest-java</artifactId> <version>1.4.9</version> </dependency> </dependencies> </project>
解决方案
问题核心是maven-assembly-plugin未绑定到Maven构建生命周期,执行install时仅生成了普通项目jar,未打包依赖。需修改pom.xml的两个关键位置:
1. 修复maven-assembly-plugin配置,绑定到install阶段
找到<build><plugins>下的maven-assembly-plugin,添加执行阶段绑定,并优化配置:
<plugin> <artifactId>maven-assembly-plugin</artifactId> <version>3.6.0</version> <!-- 升级到稳定版,适配新版依赖 --> <configuration> <archive> <manifest> <!-- Wiremock扩展无需主类,删除该行避免报错 --> <!-- <mainClass>fully.qualified.MainClass</mainClass> --> </manifest> </archive> <descriptorRefs> <descriptorRef>jar-with-dependencies</descriptorRef> </descriptorRefs> </configuration> <executions> <execution> <id>make-assembly</id> <phase>install</phase> <!-- 绑定到install阶段自动执行 --> <goals> <goal>single</goal> <!-- 生成包含依赖的胖jar --> </goals> </execution> </executions> </plugin>
2. 调整Wiremock依赖范围(规范优化)
开发Wiremock扩展时,建议使用非standalone版本,并设置依赖范围为provided(Wiremock运行环境会自带该依赖,避免重复打包):
<!-- 替换原有的wiremock-jre8-standalone依赖 --> <dependency> <groupId>com.github.tomakehurst</groupId> <artifactId>wiremock-jre8</artifactId> <version>2.35.0</version> <scope>provided</scope> </dependency>
验证修改
执行以下命令重新构建:
mvn -Dmaven.wagon.http.ssl.insecure=true clean install -DskipTests
此时target目录会生成两个jar:
wiremock-body-transformer-1.0.3-SNAPSHOT.jar:普通项目jar(约20kb)wiremock-body-transformer-1.0.3-SNAPSHOT-jar-with-dependencies.jar:包含所有依赖的胖jar(大小符合预期)
内容的提问来源于stack exchange,提问作者Koffie
相关产品推荐
相关产品推荐

