refreshVersionsMigrate appends the version placeholder to version-less dependency declarations, breaking BoM/platform-based builds

#740 ยท closed ยท 0 comments

View on GitHub โ†—

takaharu-nakase

- [x] I have read the [guidelines for submitting issues](https://splitties.github.io/refreshVersions/contributing/submitting-issues/#bug-reports) ## ๐Ÿ› Describe the bug `refreshVersionsMigrate` appends the version placeholder to **version-less** dependency declarations, i.e. declarations whose version is intentionally provided by a platform/BoM (Spring Boot dependency management, `aws.sdk.kotlin:bom`, etc.) or by dependency constraints: ```diff - implementation("com.fasterxml.jackson.module:jackson-module-kotlin") + implementation("com.fasterxml.jackson.module:jackson-module-kotlin:_") ``` This breaks the build: the migration only adds `versions.properties` entries for dependencies that have a hardcoded version (`addMissingEntriesInVersionsProperties` filters on `hasHardcodedVersion`), so the newly written placeholders have no matching entry and can never resolve: ``` * What went wrong: Execution failed for task ':buildSrc:compileKotlin'. > Could not resolve all files for configuration ':buildSrc:compileClasspath'. > Could not find com.fasterxml.jackson.module:jackson-module-kotlin:_. ``` Since the rewrite is a purely textual regex replacement, it also corrupts string literals that merely *look like* coordinates but are not dependency declarations, silently disabling them. Real example from our build, where a `resolutionStrategy.eachDependency` matcher stops matching forever: ```diff resolutionStrategy.eachDependency { when ("${requested.group}:${requested.name}") { - "co.elastic.clients:elasticsearch-java" -> useVersion(elasticsearchJavaVersion) + "co.elastic.clients:elasticsearch-java:_" -> useVersion(elasticsearchJavaVersion) ``` The cause is the empty alternative in `mavenCoordinateRegex`, which makes it match coordinates without a version, combined with the fallback that unconditionally appends `:_`: https://github.com/Splitties/refreshVersions/blob/2a8be134281c5a5f4b1cbc9052b1a48a1a56761e/plugins/dependencies/src/main/kotlin/de/fayard/refreshVersions/RefreshVersionsMigrateTask.kt#L253-L255 ## โš ๏ธ Current behavior Running `./gradlew refreshVersionsMigrate --mode=VersionsPropertiesOnly` on a project that uses a BoM/platform rewrites every version-less coordinate to `coordinate:_` and leaves the build broken (`Could not find <group>:<name>:_.`). ## โœ… Expected behavior Version-less dependency declarations are left untouched by the migration: - In Gradle, a version-less declaration only resolves when a platform/BoM or dependency constraint supplies the version, so it is a reliable signal that the version is deliberately managed outside of refreshVersions. - Appending `:_` to such a declaration can never help: no `versions.properties` entry is created for it, so the placeholder cannot resolve and the build fails. Replacing version-less coordinates with built-in dependency notations when available (covered by the existing `"Replace with dependency names, if present"` test with `org.apache.logging.log4j:log4j-jul`) is fine and should keep working โ€” only the `:_` fallback should skip them. ## ๐Ÿ’ฃ Steps to reproduce 1. Create a project that declares a dependency without a version, resolved through a BoM, e.g.: ```kotlin dependencies { implementation(platform("aws.sdk.kotlin:bom:_")) implementation("aws.sdk.kotlin:s3-jvm") } ``` 2. Run `./gradlew refreshVersionsMigrate --mode=VersionsPropertiesOnly` 3. The declaration becomes `implementation("aws.sdk.kotlin:s3-jvm:_")`, no `versions.properties` entry is added for it, and any subsequent Gradle invocation fails with `Could not find aws.sdk.kotlin:s3-jvm:_.` ## ๐Ÿ“ฑ Tech info - refreshVersions version: 0.60.5 (also reproduced on current `main`, the relevant code is unchanged) - Gradle: 8.14.3 - OS: macOS / Linux (not OS-specific) I'll open a PR with a fix and a test shortly.

Comments