Maven项目信息报告插件依赖报告搜索仓库定义位置及移除方法问询
问题
我有一个Maven项目,依赖另一个内部项目的特性分支快照版本。当使用maven-project-info-reports-plugin:3.4.1生成「Dependencies」报告时,插件会尝试在多个未配置过的公共仓库(如cdh.snapshots.repo、java.net2等)中查找该快照版本,最终查找失败。我并未在全局settings.xml或个人settings.xml中配置这些仓库,请问:
- 这些仓库来自何处?
- 如何移除这些仓库?
- 为何仅在快照版本时出现该问题?
日志片段:
[INFO] Generating "Dependencies" report --- maven-project-info-reports-plugin:3.4.1:dependencies Downloading from cdh.snapshots.repo: https://repository.confluent.com/content/repositories/snapshots/com/mycompany/myproject/feature-XYZ-SNAPSHOT/maven-metadata.xml Downloading from java.net2: http://download.java.net/maven/2/com/mycompany/myproject/feature-XYZ-SNAPSHOT/maven-metadata.xml Downloading from version99: http://version99.qos.ch/com/mycompany/myproject/feature-XYZ-SNAPSHOT/maven-metadata.xml Downloading from jitpack.io: https://jitpack.io/com/mycompany/myproject/feature-XYZ-SNAPSHOT/maven-metadata.xml [WARNING] Could not transfer metadata com.mycompany:myproject:feature-XYZ-SNAPSHOT/maven-metadata.xml from/to cdh.snapshots.repo (https://repository.confluent.com/content/repositories/snapshots): Transfer failed for https://repository.confluent.com/content/repositories/snapshots/com/mycompany/myproject/feature-XYZ-SNAPSHOT/maven-metadata.xml
分析与解决
1. 这些仓库的来源
这些仓库主要来自两个渠道:
- Maven默认超级POM(Super POM):所有Maven项目都会隐式继承这个父POM,其中内置了若干公共仓库(包括快照仓库),如果你的项目没有显式覆盖仓库配置,就会使用这些默认仓库。
- 依赖传递引入:你的内部依赖可能在自身
pom.xml中配置了这些公共仓库,通过依赖传递被添加到当前项目的仓库列表中。
仅快照版本出现问题的原因:快照版本需要定期请求仓库的maven-metadata.xml来获取最新的快照构建,而发布版本一旦下载到本地仓库后就不会再发起远程查找,因此不会触发这些仓库的请求。
2. 移除这些仓库的方法
方法一:显式覆盖仓库配置
在项目pom.xml中添加<repositories>和<pluginRepositories>节点,只保留你的内部仓库,这会直接覆盖Super POM的默认仓库配置:
<repositories> <repository> <id>internal-repo</id> <url>http://你的内部仓库地址</url> <releases> <enabled>true</enabled> </releases> <snapshots> <enabled>true</enabled> </snapshots> </repository> </repositories> <pluginRepositories> <pluginRepository> <id>internal-plugin-repo</id> <url>http://你的内部插件仓库地址</url> <releases> <enabled>true</enabled> </releases> <snapshots> <enabled>true</enabled> </snapshots> </pluginRepository> </pluginRepositories>
方法二:禁用传递来的不必要仓库
如果是内部依赖传递引入的仓库,可在当前项目pom.xml中显式禁用这些仓库:
<repositories> <!-- 保留内部仓库 --> <repository> <id>internal-repo</id> <url>http://你的内部仓库地址</url> <releases><enabled>true</enabled></releases> <snapshots><enabled>true</enabled></snapshots> </repository> <!-- 禁用不需要的公共仓库 --> <repository> <id>cdh.snapshots.repo</id> <url>https://repository.confluent.com/content/repositories/snapshots</url> <releases><enabled>false</enabled></releases> <snapshots><enabled>false</enabled></snapshots> </repository> <!-- 其他不需要的仓库按同样方式禁用 --> </repositories>
方法三:用镜像拦截所有请求
在settings.xml中配置全局镜像,将所有仓库请求重定向到你的内部仓库,彻底避免请求公共仓库:
<mirrors> <mirror> <id>internal-mirror</id> <mirrorOf>*</mirrorOf> <url>http://你的内部仓库地址</url> </mirror> </mirrors>
内容的提问来源于Stack Exchange,提问作者Karsten Spang
相关产品推荐
相关产品推荐

