oscerd commented on PR #3065:
URL: https://github.com/apache/camel-kamelets/pull/3065#issuecomment-5865100325

   Reviewed. CI is green and the diff is one line, but this major bump changes 
the published classpath of `camel-kamelets-catalog`, so it is worth landing 
deliberately rather than as routine.
   
   **fabric8 8.0.0 moves from Jackson 2 to Jackson 3** ([release 
notes](https://github.com/fabric8io/kubernetes-client/releases/tag/v8.0.0): 
*"Fix #7374: Upgrade Jackson from 2.x to 3.2.1"*). `camel-kamelets-crds` 
declares `kubernetes-client` at compile scope, and `camel-kamelets-catalog` 
depends on `camel-kamelets-crds`, so it propagates two hops.
   
   Resolved from this tree, `mvn dependency:tree -pl 
library/camel-kamelets-catalog -am`:
   
   <details>
   <summary>fabric8 7.9.0 — Jackson 2 only</summary>
   
   ```
   +- 
com.fasterxml.jackson.dataformat:jackson-dataformat-yaml:jar:2.22.2:compile
   |  +- com.fasterxml.jackson.core:jackson-databind:jar:2.22.2:compile
   |  \- com.fasterxml.jackson.core:jackson-core:jar:2.22.2:compile
   +- com.fasterxml.jackson.datatype:jackson-datatype-jsr310:jar:2.22.2:compile
   |  \- com.fasterxml.jackson.core:jackson-annotations:jar:2.22:compile
   ```
   </details>
   
   <details>
   <summary>fabric8 8.0.0 — both stacks</summary>
   
   ```
   |  |  |  +- 
tools.jackson.dataformat:jackson-dataformat-yaml:jar:3.2.3:compile
   |  |  |  +- tools.jackson.core:jackson-databind:jar:3.2.3:compile
   |  |  |  \- tools.jackson.core:jackson-core:jar:3.2.3:compile
   +- 
com.fasterxml.jackson.dataformat:jackson-dataformat-yaml:jar:2.22.2:compile
   |  +- com.fasterxml.jackson.core:jackson-databind:jar:2.22.2:compile
   |  \- com.fasterxml.jackson.core:jackson-core:jar:2.22.2:compile
   +- com.fasterxml.jackson.datatype:jackson-datatype-jsr310:jar:2.22.2:compile
   |  \- com.fasterxml.jackson.core:jackson-annotations:jar:2.22:compile
   ```
   </details>
   
   Jackson 3 lives under `tools.jackson`, a different groupId, so Maven 
mediation does not substitute it for the Jackson 2 we already ship — it is 
**added**. Every consumer of `camel-kamelets-catalog` gains a second JSON stack 
at compile scope. That is also why the build stays green: `jackson-annotations` 
keeps its `com.fasterxml.jackson.core` coordinates (2.22 either way), so 
nothing in this repository fails to compile.
   
   **Why this is probably fine anyway.** Camel's parent already defines both 
(`camel-parent` 39):
   
   ```xml
   <jackson2-version>2.22.2</jackson2-version>
   <jackson3-version>3.2.2</jackson3-version>
   ```
   
   so coexistence is the direction the ecosystem is already moving in, and the 
two are designed to sit side by side. `camel-kamelets-catalog` itself only uses 
Jackson 2 (`com.fasterxml.jackson.databind.ObjectMapper` in `KameletsCatalog`), 
declared explicitly in its own pom rather than inherited from fabric8, so its 
own behaviour does not change.
   
   **Two small things for whoever merges:**
   
   1. Minor skew — Camel pins Jackson 3 at `3.2.2`, fabric8 8.0.0 brings 
`3.2.3`. Harmless in isolation, mediated in any downstream app, but worth 
knowing it is not the same number.
   2. `kubernetes-client` is a compile-scope leak through 
`camel-kamelets-crds`. If the intent is that the CRD POJOs be usable without 
dragging a full Kubernetes client (and now two JSON stacks) into every 
consumer, that is a separate conversation from this bump — just noting it is 
this bump that makes the leak visible.
   
   No objection from me, and nothing here blocks the merge. Flagging so the 
classpath change is a decision rather than a side effect. Needs a human 
approval regardless.
   
   ---
   _Claude Code on behalf of Andrea Cosentino_
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to