Releases: apache/maven-resolver
Releases · apache/maven-resolver
Release list
2.0.21
🚀 New features and improvements
- RRF: self-heal from provably broken auto-discovered prefixes files (#1976) @ascheman
- Feat: config to close connection at end of tx (#1978) @cstamas
- Feat: new (limited) transport (#1966) @cstamas
- Expose additional transport details to TransportListener (#1762) @kwin
- Support HTTP/3 in Jetty and JRE HTTP Client (#1949) @kwin
- Skip validation and decoration on re-entrant RepositorySystem calls (#1957) @gnodet
🐛 Bug Fixes
- Fix: preserve original trace data when stamping re-entrancy marker (#1980) @gnodet
- Bug: in certain cases Resolver caused build failure (#1975) @cstamas
- Make sure to always close input streams bound to responses (#1970) @kwin
- Fix: be more defensive regarding request traces (#1973) @cstamas
- Fix reporting of HTTP/3 in JdkTransporter (#1967) @kwin
- Validate path components (#1959) @cstamas
- Bug: Apache transport deadlock in concurrent use case (#1953) @cstamas
- Fix potential NPEs in IpcClient and resource leak in DependencyGraphParser (#1945) @gnodet
- Bug: Jetty transport used wrong config (#1948) @cstamas
📝 Documentation updates
- fix: Some since javadoc tags were off; fixed (#1968) @cstamas
- Add AGENTS.md + SECURITY.md security-model pointer for scanner discoverability (#1950) @potiuk
👻 Maintenance
- Use try-with-resources in AbstractTransporter (#1947) @Aayush10016
- Add AGENTS.md + SECURITY.md security-model pointer for scanner discoverability (#1950) @potiuk
- Fix potential NPEs in IpcClient and resource leak in DependencyGraphParser (#1945) @gnodet
- Limit internal retries to 1 with Java 26+ (#1946) @kwin
🔧 Build
📦 Dependency updates
- Bump Jetty to 12.1.11 (#1969) @cstamas
- Bump apache/maven-gh-actions-shared/.github/workflows/release-drafter.yml from 4 to 5 (#1963) @dependabot[bot]
- Bump apache/maven-gh-actions-shared/.github/workflows/maven-verify.yml from 4 to 5 (#1961) @dependabot[bot]
- Bump apache/maven-gh-actions-shared/.github/workflows/stale.yml from 4 to 5 (#1960) @dependabot[bot]
- Bump apache/maven-gh-actions-shared/.github/workflows/pr-automation.yml from 4 to 5 (#1962) @dependabot[bot]
- Bump bouncycastleVersion from 1.84 to 1.85 (#1956) @dependabot[bot]
2.0.20
🚀 New features and improvements
- Reduce PathConflictResolver memory and auto-select resolver (#1938) @gnodet
- Fix dependency selector cache regression in DF collector (#1941) @gnodet
- Fix thread contention in GenericVersionScheme and WeakInternPool (#1937) @gnodet
- Improve thread safety across modules (#1902) @gnodet
- WarnChecksumPolicy: proceed on no checksums (#1922) @ascheman
- Extend AuthenticationBuilder to support SSLContext for mTLS authentication (#1907) @jiteshkhatri11
- DependencyCollectionChecker: new session member (#1899) @cstamas
- Add any media type to RFC9457 content type header (#1894) @slawekjaranowski
- fix: Configuration to be able to control sending RFC 9457 related Accept HTTP header (#1891) @cstamas
- Improvement: BF dependency selector hot methods (#1882) @cstamas
🐛 Bug Fixes
- Fix ApacheTransport auth cache CCEx (#1923) @cstamas
- Checksums: lack of information (#1917) @cstamas
- Fix inverted SIGTSTP condition in IPC server (#1915) @gnodet
- Bug: fix IPC named lock client-side robustness for Windows (#1910) @gnodet
- Bugfix: Fix NPE in PathConflictResolver (#1904) @cstamas
- Bug: fix IPC named lock server-side waiter leak on client timeout (#1901) @gnodet
- Bug: fix new PCR as it in certain cases left duplicates (#1896) @cstamas
📝 Documentation updates
- Javadoc update (#1925) @cstamas
- Doc: Trusted Checksums Summary File Procedure (#1886) @adambkaplan
👻 Maintenance
- Put PCR aside for now (#1942) @cstamas
- Get rid of BND warnings (#1933) @cstamas
- Align generators (#1929) @cstamas
- Fix for ChainedWorkspaceReader (#1909) @cstamas
- Create simple JMH benchmark to compare CCR and PCR (#1908) @cstamas
- Tidy up suppliers (#1898) @cstamas
- Disable IPC lock tests on Windows (#1900) @cstamas
📦 Dependency updates
- Bump org.apache.maven:maven-parent from 48 to 49 (#1939) @dependabot[bot]
- Bump roasterVersion from 2.31.0.Final to 2.31.1.Final (#1935) @dependabot[bot]
- Bump sisuVersion from 1.0.0 to 1.0.1 (#1936) @dependabot[bot]
- Bump org.redisson:redisson from 4.6.0 to 4.6.1 (#1932) @dependabot[bot]
- Deps: Jetty 12.1.10 (#1930) @cstamas
- Bump org.redisson:redisson from 4.5.0 to 4.6.0 (#1927) @dependabot[bot]
- Bump io.minio:minio from 9.0.2 to 9.0.3 (#1926) @dependabot[bot]
- Bump dev.sigstore:sigstore-java from 2.1.0 to 2.2.0 (#1918) @dependabot[bot]
- Bump io.minio:minio from 9.0.1 to 9.0.2 (#1916) @dependabot[bot]
- Bump okhttpVersion from 5.3.2 to 5.4.0 (#1914) @dependabot[bot]
- Bump biz.aQute.bnd:bnd-maven-plugin from 7.2.3 to 7.3.0 (#1897) @dependabot[bot]
- Bump org.redisson:redisson from 4.4.0 to 4.5.0 (#1906) @dependabot[bot]
- Bump com.github.siom79.japicmp:japicmp-maven-plugin from 0.26.0 to 0.26.1 (#1892) @dependabot[bot]
- Bump io.minio:minio from 9.0.0 to 9.0.1 (#1883) @dependabot[bot]
- Bump org.ow2.asm:asm from 9.10 to 9.10.1 (#1890) @dependabot[bot]
- Bump com.github.siom79.japicmp:japicmp-maven-plugin from 0.25.7 to 0.26.0 (#1887) @dependabot[bot]
- Bump dev.sigstore:sigstore-java from 2.0.0 to 2.1.0 (#1889) @dependabot[bot]
- Bump org.codehaus.plexus:plexus-classworlds from 2.11.0 to 2.12.0 (#1885) @dependabot[bot]
- Bump org.ow2.asm:asm from 9.9.1 to 9.10 (#1879) @dependabot[bot]
- Bump maven3Version from 3.9.15 to 3.9.16 (#1880) @dependabot[bot]
2.0.18
🚀 New features and improvements
- Feat: Reuse same RemoteRepository to HTTP URI creation logic (#1878) @cstamas
- Enh: Maven 3 is with us (#1869) @cstamas
- Feat: Maven 3 experimental scope manager (#1868) @cstamas
- Feat: Pull in version filter builder (#1867) @cstamas
- Feat: Resolution scope aliases (#1863) @cstamas
- Feat: Expose scope related bits via scope manager (#1862) @cstamas
🐛 Bug Fixes
📦 Dependency updates
- Deps: update slf4j to 2.0.18 (#1872) @cstamas
- Deps: update Redisson to 4.4.0 (#1873) @cstamas
- Bump org.codehaus.plexus:plexus-classworlds from 2.10.0 to 2.11.0 (#1871) @dependabot[bot]
- Deps: Update parent POM 48 (#1866) @cstamas
- Bump com.github.siom79.japicmp:japicmp-maven-plugin from 0.25.6 to 0.25.7 (#1861) @dependabot[bot]
2.0.17
🚀 New features and improvements
- Lower various component selection debug noise (#1841) @cstamas
- GH-1835: Expose qualifiers for generic version scheme (#1837) @cstamas
- Provide modern TrackingFileManager (#1814) @cstamas
🐛 Bug Fixes
- Send "Accept" request header to indicate RFC 9457 compliance (#1846) @kwin
- Remove unnecessary repository preparation in metadata resolution for prefixes (#1830) @slawekjaranowski
- GH-1834: Version filtering context with BF fails (#1836) @cstamas
📝 Documentation updates
👻 Maintenance
- Maintenance: tidy up IPC locks, make exclusive test timeout a bit longer (#1849) @cstamas
- Increase timeout in tests (#1816) @cstamas
📦 Dependency updates
- Bump commons-codec:commons-codec from 1.21.0 to 1.22.0 (#1855) @dependabot[bot]
- Bump com.google.code.gson:gson from 2.13.2 to 2.14.0 (#1853) @dependabot[bot]
- Deps: Updates (#1848) @cstamas
- Bump testcontainersVersion from 2.0.4 to 2.0.5 (#1847) @dependabot[bot]
- Bump maven3Version from 3.9.14 to 3.9.15 (#1842) @dependabot[bot]
- Bump com.github.siom79.japicmp:japicmp-maven-plugin from 0.25.5 to 0.25.6 (#1840) @dependabot[bot]
- Bump bouncycastleVersion from 1.83 to 1.84 (#1831) @dependabot[bot]
- Bump com.google.guava:guava from 33.5.0-jre to 33.6.0-jre (#1833) @dependabot[bot]
- Bump com.github.siom79.japicmp:japicmp-maven-plugin from 0.25.4 to 0.25.5 (#1828) @dependabot[bot]
- Better control of plexus-utils (#1826) @cstamas
- Bump org.redisson:redisson from 4.3.0 to 4.3.1 (#1824) @dependabot[bot]
- Bump org.codehaus.plexus:plexus-classworlds from 2.9.0 to 2.10.0 (#1822) @dependabot[bot]
- Bump biz.aQute.bnd:bnd-maven-plugin from 7.2.1 to 7.2.3 (#1818) @dependabot[bot]
- Bump org.codehaus.plexus:plexus-utils from 4.0.2 to 4.0.3 in /maven-resolver-demos/maven-resolver-demo-snippets (#1817) @dependabot[bot]
- Bump io.minio:minio from 8.6.0 to 9.0.0 (#1813) @dependabot[bot]
- Bump testcontainersVersion from 2.0.3 to 2.0.4 (#1811) @dependabot[bot]
- Bump maven3Version from 3.9.12 to 3.9.14 (#1810) @dependabot[bot]
- Bump org.mockito:mockito-core from 5.21.0 to 5.23.0 (#1808) @dependabot[bot]
- Bump org.redisson:redisson from 4.2.0 to 4.3.0 (#1805) @dependabot[bot]
2.0.16
1.9.27
2.0.15
🚀 New features and improvements
- Align configuration properties and more (#1785) @cstamas
- Better checksum control (#1784) @cstamas
- JDK Transport: Do no longer leverage temp file for transfering artifact (#1755) @kwin
- Log retries in JDK HTTP Client (#1778) @kwin
- GH-1773: Treat 410 Gone as 404 Not Found (#1775) @cstamas
- GH-1737: Revert partially parallel upload change (#1765) @cstamas
- Update to Jetty 12.1 (#1748) @kwin
- Add retries for JDK HTTP client (#1735) @kwin
🐛 Bug Fixes
- Minor bugfix: If proxy host cannot be resolved, fail (#1793) @cstamas
- GH-1768 Drastically simplify auth caching (#1791) @cstamas
- Fix preemptive proxy authentication in JDK Client (#1766) @kwin
📝 Documentation updates
- Document how resolver works internally (#1794) @cstamas
- Improve clarity and correctness in RRF documentation (#1795) @elharo
- Document known transport issues (#1792) @cstamas
- Clarify description of JDK Transport modules (#1767) @kwin
- Remove generated configuration.md from Git (#1769) @kwin
- Fix typos and improve clarity in using resolver docs (#1713) @elharo
👻 Maintenance
📦 Dependency updates
- Bump sisuVersion from 0.9.0.M4 to 1.0.0 (#1789) @dependabot[bot]
- Bump org.redisson:redisson from 4.1.0 to 4.2.0 (#1787) @dependabot[bot]
- Deps: Jetty 12.1.6 (#1779) @cstamas
- Bump commons-codec:commons-codec from 1.20.0 to 1.21.0 (#1777) @dependabot[bot]
- Bump org.codehaus.plexus:plexus-xml from 4.1.0 to 4.1.1 (#1759) @dependabot[bot]
- Bump com.github.siom79.japicmp:japicmp-maven-plugin from 0.25.3 to 0.25.4 (#1745) @dependabot[bot]
- Bump biz.aQute.bnd:bnd-maven-plugin from 7.2.0 to 7.2.1 (#1746) @dependabot[bot]
- Update to Jetty 12.1 (#1748) @kwin
- Bump org.apache.maven:maven-parent from 46 to 47 (#1749) @dependabot[bot]
- Bump roasterVersion from 2.30.3.Final to 2.31.0.Final (#1729) @dependabot[bot]
- Bump com.github.siom79.japicmp:japicmp-maven-plugin from 0.25.1 to 0.25.3 (#1740) @dependabot[bot]
- Bump org.codehaus.plexus:plexus-testing from 2.0.2 to 2.1.0 (#1730) @dependabot[bot]
- Bump com.github.mizosoft.methanol:methanol from 1.8.4 to 1.9.0 (#1723) @dependabot[bot]
- Bump org.redisson:redisson from 4.0.0 to 4.1.0 (#1728) @dependabot[bot]
- Bump org.redisson:redisson from 3.52.0 to 4.0.0 (#1717) @dependabot[bot]
- Bump testcontainersVersion from 2.0.2 to 2.0.3 (#1715) @dependabot[bot]
- Bump biz.aQute.bnd:bnd-maven-plugin from 7.1.0 to 7.2.0 (#1726) @dependabot[bot]
- Bump org.codehaus.mojo:exec-maven-plugin from 3.6.2 to 3.6.3 (#1721) @dependabot[bot]
- Bump com.github.siom79.japicmp:japicmp-maven-plugin from 0.25.0 to 0.25.1 (#1722) @dependabot[bot]
- Bump org.ow2.asm:asm from 9.9 to 9.9.1 (#1716) @dependabot[bot]
- Bump maven3Version from 3.9.11 to 3.9.12 (#1718) @dependabot[bot]
1.9.26
🚀 New features and improvements
- GH-1773: Treat 410 Gone as 404 Not Found (#1774) @cstamas
- GH-1737: Revert partially parallel upload change (#1764) @cstamas
🐛 Bug Fixes
- GH-1768 Drastically simplify auth caching (#1790) @cstamas
- [1.9.x] Bug: GH-1703 Locally cached artifacts defy RRF (#1708) @cstamas
📝 Documentation updates
📦 Dependency updates
- Bump sisuVersion from 0.9.0.M4 to 1.0.0 (#1788) @dependabot[bot]
- Bump org.redisson:redisson from 4.1.0 to 4.2.0 (#1786) @dependabot[bot]
- Bump commons-codec:commons-codec from 1.20.0 to 1.21.0 (#1776) @dependabot[bot]
- Bump org.codehaus.mojo:animal-sniffer-maven-plugin from 1.26 to 1.27 (#1756) @dependabot[bot]
- Bump org.apache.maven:maven-parent from 46 to 47 (#1750) @dependabot[bot]
- Bump com.github.siom79.japicmp:japicmp-maven-plugin from 0.25.3 to 0.25.4 (#1747) @dependabot[bot]
- Bump com.github.siom79.japicmp:japicmp-maven-plugin from 0.25.1 to 0.25.3 (#1741) @dependabot[bot]
- Bump org.apache.maven:maven-parent from 45 to 46 (#1734) @dependabot[bot]
- Bump org.redisson:redisson from 4.0.0 to 4.1.0 (#1727) @dependabot[bot]
- Bump org.redisson:redisson from 3.52.0 to 4.0.0 (#1720) @dependabot[bot]
- Bump com.github.siom79.japicmp:japicmp-maven-plugin from 0.25.0 to 0.25.1 (#1724) @dependabot[bot]
- Bump mavenVersion from 3.9.11 to 3.9.12 (#1719) @dependabot[bot]
2.0.14
🚀 New features and improvements
- Enhance RRF (#1709) @cstamas
- Locking inhibitor SPI (#1696) @cstamas
- Repository Key Function SPI (#1679) @cstamas
- GH-1668: Add catch-all for group filter (#1694) @cstamas
- Remote repository intent (#1680) @cstamas
- Name mappers cleanup and new GAECV mapper (#1677) @cstamas
- Remove hack from Basic connector (#1676) @cstamas
- HTTP compression support in Java Http Client (#1627) @kwin
- Support preemptive authentication with Java HTTP Client (#1625) @kwin
🐛 Bug Fixes
- Bug: GH-1711 make sure last wins (#1712) @cstamas
- Bug: GH-1703 Gaps in G segments resets result (#1706) @cstamas
- Bug: GH-1703 Locally cached artifacts defy RRF (#1707) @cstamas
- Bug: depMgt in manager was "last wins" instead of "first wins" (#1702) @cstamas
- Bugfix: Prioritized Components Cache change detection got removed (#1698) @cstamas
- TrackingFileManager changes (#1692) @cstamas
- Make filters daemon friendly (#1681) @cstamas
- Fix locking issues (#1660) @cstamas
- Bug: Filter fixes (#1655) @cstamas
- Fix automatic module names and missing methanol (#1651) @cstamas
- ScopeManager: do not interfere with session graph transformer (#1650) @cstamas
- GH-1646 bugfix for filter support in ADNC (#1647) @cstamas
- Set the request timeout with Java HTTP Client (#1633) @kwin
📝 Documentation updates
👻 Maintenance
- Test: Increase IPC test timeout (#1710) @cstamas
- Use try-with for resource in test HttpServer (#1521) (#1686) @martins-avots
- Cleanup prefix and others (#1670) @cstamas
- Maven Resolver lockrepro (#1665) @cstamas
- Update GH CI (#1658) @cstamas
📦 Dependency updates
- Update test tools (#1705) @cstamas
- Bump org.mockito:mockito-core from 5.20.0 to 5.21.0 (#1704) @dependabot[bot]
- Bump org.codehaus.plexus:plexus-testing from 2.0.1 to 2.0.2 (#1697) @dependabot[bot]
- Bump bouncycastleVersion from 1.82 to 1.83 (#1693) @dependabot[bot]
- Update to SigStore 2.0.0 (#1685) @cstamas
- Bump org.jboss.forge.roaster:roaster-api from 2.30.1.Final to 2.30.3.Final (#1687) @dependabot[bot]
- Bump org.jboss.forge.roaster:roaster-jdt from 2.30.1.Final to 2.30.3.Final (#1688) @dependabot[bot]
- Bump com.github.siom79.japicmp:japicmp-maven-plugin from 0.24.2 to 0.25.0 (#1689) @dependabot[bot]
- Bump okhttpVersion from 5.3.1 to 5.3.2 (#1678) @dependabot[bot]
- Bump okhttpVersion from 5.3.0 to 5.3.1 (#1672) @dependabot[bot]
- Bump org.apache.commons:commons-lang3 from 3.19.0 to 3.20.0 (#1673) @dependabot[bot]
- Bump commons-codec:commons-codec from 1.19.0 to 1.20.0 (#1652) @dependabot[bot]
- Bump okhttpVersion from 5.2.1 to 5.3.0 (#1645) @dependabot[bot]
- Bump org.codehaus.plexus:plexus-testing from 1.7.0 to 2.0.1 (#1642) @dependabot[bot]
- Bump org.codehaus.mojo:exec-maven-plugin from 3.6.1 to 3.6.2 (#1638) @dependabot[bot]
- Bump com.github.siom79.japicmp:japicmp-maven-plugin from 0.23.1 to 0.24.2 (#1628) @dependabot[bot]
- Bump com.github.mizosoft.methanol:methanol from 1.8.3 to 1.8.4 (#1634) @dependabot[bot]
- Bump org.codehaus.plexus:plexus-testing from 1.6.0 to 1.7.0 (#1635) @dependabot[bot]
- Bump okhttpVersion from 5.1.0 to 5.2.1 (#1626) @dependabot[bot]
1.9.25
🚀 New features and improvements
- Add scope support for trusted checksums (#1700) @slawekjaranowski
- [1.9.x] Name mappers cleanup and new GAECV mapper (#1674) @cstamas
- [1.9.x] Proper metadata locking support (#1669) @cstamas
- Ability to augment metadata nature for version range request (#1518) @cstamas
🐛 Bug Fixes
- [1.9.x] TrackingFileManager changes (#1695) @cstamas
- [1.9.x] Maven filters daemon friendly (#1682) @cstamas
- [1.9.x] Remove hack from Basic connector (#1675) @cstamas
- [1.9.x] Fix locking issues (#1662) @cstamas
📝 Documentation updates
- Updated the documentation to reflect the current list of name mappers (#1699) @slawekjaranowski
👻 Maintenance
- [1.9.x] Mild backport: support same properties as Resolver 2.x (#1656) @cstamas
- [1.9.x] Maven resolver lockrepro (#1664) @cstamas
- Bugfix: Java 25 broke test (#1657) @cstamas
📦 Dependency updates
- Bump com.github.siom79.japicmp:japicmp-maven-plugin from 0.24.2 to 0.25.0 (#1690) @dependabot[bot]
- Bump org.codehaus.mojo:animal-sniffer-maven-plugin from 1.24 to 1.26 (#1624) @dependabot[bot]
- Bump com.github.siom79.japicmp:japicmp-maven-plugin from 0.23.1 to 0.24.2 (#1630) @dependabot[bot]
- Bump commons-codec:commons-codec from 1.19.0 to 1.20.0 (#1653) @dependabot[bot]
- Bump org.redisson:redisson from 3.51.0 to 3.52.0 (#1602) @dependabot[bot]
- Bump com.google.guava:guava from 33.4.8-jre to 33.5.0-jre (#1592) @dependabot[bot]
- Bump com.google.code.gson:gson from 2.13.1 to 2.13.2 (#1580) @dependabot[bot]
- Bump org.redisson:redisson from 3.50.0 to 3.51.0 (#1559) @dependabot[bot]
- Bump jettyVersion from 9.4.57.v20241219 to 9.4.58.v20250814 (#1551) @dependabot[bot]
- Bump commons-codec:commons-codec from 1.18.0 to 1.19.0 (#1536) @dependabot[bot]
- Bump mavenVersion from 3.9.10 to 3.9.11 (#1532) @dependabot[bot]