Deps: Bump to Resolver 2.0.21#12509
Merged
Merged
Conversation
And add more validation to MavenValidator.
cstamas
marked this pull request as ready for review
July 20, 2026 16:31
gnodet
approved these changes
Jul 20, 2026
gnodet
left a comment
Contributor
There was a problem hiding this comment.
Clean dependency bump adapting Maven 4.x (master) to the upcoming Resolver 2.0.21 API. Well-structured changes across 7 files.
What's good:
- The
Optional<Repository>return type inInternalSession.getRepository()properly handles the newArtifactResult.NO_REPOSITORYsentinel — much cleaner than exposing the sentinel to callers - Good Javadoc on the
getRepository()method explaining the sentinel semantics and whenOptional.empty()is returned - Additional validation via
PathUtils.validateArtifactComponents()/validateMetadataComponents()inMavenValidatorhardens against path traversal — nice security improvement - Both
RepositorySystemSupplierimplementations (main + testing stubs) correctly updated with the newTransporterProviderparameter - All CI passing across all platforms and JDK versions
Minor note:
- In
DefaultArtifactResolver, themappedExceptionscollector uses.orElse(null)which could produce anullkey in the map ifNO_REPOSITORYappears in exception mappings. This is fine withHashMapsemantics but worth keeping in mind if the map type ever changes.
LGTM — companion to #12504 (maven-3.10.x), this one cleanly adapts the master branch.
This review was generated by an AI agent and may contain inaccuracies. Please verify all suggestions before applying.
Claude Code on behalf of Guillaume Nodet
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
And add more validation to MavenValidator.