Maven配置HTTPS镜像仍报Blocked mirror错误的原因与配置方法
问题现象
使用Maven 3.8.5版本时,settings.xml中mirrors配置如下:
<mirrors> <mirror> <id>aliyun</id> <mirrorOf>*</mirrorOf> <name>aliyun</name> <url>https://maven.aliyun.com/nexus/content/groups/public/</url> <blocked>true</blocked> </mirror> </mirrors>
配置中blocked参数设置为false时,执行mvn package命令可正常运行;参数设置为true时,抛出如下错误:
[INFO] Scanning for projects... [ERROR] [ERROR] Some problems were encountered while processing the POMs: [WARNING] 'build.plugins.plugin.version' for org.apache.maven.plugins:maven-compiler-plugin is missing. @ line 209, column 21 [ERROR] Non-resolvable import POM: Could not transfer artifact org.springframework.security:spring-security-bom:pom:5.6.3 from/to aliyun (https://maven.aliyun.com/nexus/content/groups/public/): Blocked mirror for repositories: [central (https://repo.maven.apache.org/maven2, default, releases)] @ org.springframework.boot:spring-boot-dependencies:2.6.7, /data/mvn/repository/org/springframework/boot/spring-boot-dependencies/2.6.7/spring-boot-dependencies-2.6.7.pom, line 2751, column 19 [ERROR] Non-resolvable import POM: Could not transfer artifact org.springframework.session:spring-session-bom:pom:2021.1.3 from/to aliyun (https://maven.aliyun.com/nexus/content/groups/public/): Blocked mirror for repositories: [central (https://repo.maven.apache.org/maven2, default, releases)] @ org.springframework.boot:spring-boot-dependencies:2.6.7, /data/mvn/repository/org/springframework/boot/spring-boot-dependencies/2.6.7/spring-boot-dependencies-2.6.7.pom, line 2758, column 19 @ [ERROR] The build could not read 1 project -> [Help 1] [ERROR] [ERROR] The project com.adwetec:adwetec:1.0 (/data/adwetec-user/adwetec-idm/pom.xml) has 2 errors [ERROR] Non-resolvable import POM: Could not transfer artifact org.springframework.security:spring-security-bom:pom:5.6.3 from/to aliyun (https://maven.aliyun.com/nexus/content/groups/public/): Blocked mirror for repositories: [central (https://repo.maven.apache.org/maven2, default, releases)] @ org.springframework.boot:spring-boot-dependencies:2.6.7, /data/mvn/repository/org/springframework/boot/spring-boot-dependencies/2.6.7/spring-boot-dependencies-2.6.7.pom, line 2751, column 19 -> [Help 2] [ERROR] Non-resolvable import POM: Could not transfer artifact org.springframework.session:spring-session-bom:pom:2021.1.3 from/to aliyun (https://maven.aliyun.com/nexus/content/groups/public/): Blocked mirror for repositories: [central (https://repo.maven.apache.org/maven2, default, releases)] @ org.springframework.boot:spring-boot-dependencies:2.6.7, /data/mvn/repository/org/springframework/boot/spring-boot-dependencies/2.6.7/spring-boot-dependencies-2.6.7.pom, line 2758, column 19 -> [Help 2] [ERROR] [ERROR] To see the full stack trace of the errors, re-run Maven with the -e switch. [ERROR] Re-run Maven using the -X switch to enable full debug logging. [ERROR] [ERROR] For more information about the errors and possible solutions, please read the following articles: [ERROR] [Help 1] http://cwiki.apache.org/confluence/display/MAVEN/ProjectBuildingException [ERROR] [Help 2] http://cwiki.apache.org/confluence/display/MAVEN/UnresolvableModelException
故障原因
blocked是Maven 3.8.1版本新增的镜像配置项,作用是强制标记对应镜像为不可用状态:
- 当某个mirror配置
blocked=true时,Maven会直接拦截所有路由到该镜像的依赖拉取请求,不会发起任何实际网络访问,直接抛出镜像阻塞错误。 - 配置中
mirrorOf设置为*,意味着所有仓库(包括Maven默认的central中央仓库)的请求都会被转发到阿里云镜像,把该镜像设为阻塞状态相当于切断了所有依赖拉取通道,必然出现依赖无法解析的问题。 - 这个参数的设计初衷是默认拦截不安全的HTTP协议镜像,避免依赖通过明文传输被篡改,当前使用的阿里云镜像为HTTPS协议,本身不需要被阻塞。
正确配置方式
- 正常使用阿里云公共镜像时,直接将
blocked参数设置为false,或者删除该配置项即可,可用配置参考:
<mirrors> <mirror> <id>aliyun</id> <mirrorOf>*</mirrorOf> <name>aliyun maven public</name> <url>https://maven.aliyun.com/nexus/content/groups/public/</url> <blocked>false</blocked> </mirror> </mirrors>
blocked=true仅在需要临时禁用某个失效、存在安全风险的镜像时使用,正常可用的镜像不要开启该配置。- 修改配置后如果存在之前拉取失败的缓存坏文件,可以执行
mvn clean package -U强制更新依赖,排除本地缓存干扰。 - 日志中提示的
maven-compiler-plugin未指定版本为警告项,不影响当前构建运行,需要消除警告的话直接在项目pom.xml中给该插件补充明确版本号即可。
内容的提问来源于stack exchange,提问作者Lei Wang
相关产品推荐
相关产品推荐

