dependabot[bot] opened a new pull request, #27621: URL: https://github.com/apache/camel/pull/27621
Bumps [eu.maveniverse.maven.scalpel:extension3](https://github.com/maveniverse/scalpel) from 0.4.2 to 0.4.3. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/maveniverse/scalpel/releases">eu.maveniverse.maven.scalpel:extension3's releases</a>.</em></p> <blockquote> <h2>Scalpel 0.4.3</h2> <h2>What's Changed</h2> <h2>🐛 Bug Fixes</h2> <h3>Deleted-module source files no longer attributed to surviving ancestor (<a href="https://redirect.github.com/maveniverse/scalpel/issues/216">#216</a>)</h3> <p>When a module was removed from the reactor, source files that previously belonged to it (e.g. <code>libs/lib-gone/src/main/java/Foo.java</code>) were being walked up the directory tree until they hit the nearest surviving ancestor (<code>libs</code>). That ancestor was then reported as a <code>DIRECT SOURCE_CHANGE</code>, pulling all its children and their transitive dependents into the build — even though nothing in the surviving reactor depended on the deleted module. The fix computes a set of deleted-module directory prefixes at detection time and stops the owner-walk at those boundaries.</p> <ul> <li>fix: deleted-module source files must not be attributed to surviving ancestor (<a href="https://redirect.github.com/maveniverse/scalpel/issues/216">#216</a>) (<a href="https://redirect.github.com/maveniverse/scalpel/issues/219">#219</a>) <a href="https://github.com/gnodet"><code>@gnodet</code></a></li> </ul> <h3>Per-project active profile IDs used when building effective models (<a href="https://redirect.github.com/maveniverse/scalpel/issues/215">#215</a>)</h3> <p>POM analysis was incorrectly marking unrelated modules as <code>TRANSITIVE</code> / <code>TRANSITIVE_DEPENDENCY</code> when sibling modules declared profiles with the same ID but different activations. The root cause was that <code>collectAllActiveProfileIds()</code> merged profile IDs from all reactor projects into a single union and applied it uniformly when building each module's old effective model, causing sibling profiles to be force-activated in modules where they are not active. The fix passes per-project active profile IDs to the model builder instead.</p> <ul> <li>fix: use per-project active profile IDs when building effective models (<a href="https://redirect.github.com/maveniverse/scalpel/issues/209">#209</a>) (<a href="https://redirect.github.com/maveniverse/scalpel/issues/215">#215</a>) <a href="https://github.com/gnodet"><code>@gnodet</code></a></li> </ul> <h3>Effective model builds limited to changed POMs to prevent OOM (<a href="https://redirect.github.com/maveniverse/scalpel/issues/208">#208</a>)</h3> <p>In large reactors (e.g. Quarkus: 1800+ modules), Scalpel was building effective models for every reactor module upfront during POM analysis. Each <code>DefaultModelBuilder.build()</code> call triggered recursive <code>importDependencyManagement</code> on BOM chains and copied the full system properties (including large <code>env.*</code> entries) for every module, causing heap exhaustion. Effective model builds are now limited to changed POMs and their direct dependents — the only modules where a change comparison is meaningful.</p> <ul> <li>fix: limit effective model builds to changed POMs and their dependents to prevent OOM (<a href="https://redirect.github.com/maveniverse/scalpel/issues/207">#207</a>) (<a href="https://redirect.github.com/maveniverse/scalpel/issues/208">#208</a>) <a href="https://github.com/gnodet"><code>@gnodet</code></a></li> </ul> <h3>Path-anchored properties skipped in effective-model comparison (<a href="https://redirect.github.com/maveniverse/scalpel/issues/214">#214</a>)</h3> <p>Properties in child POMs using Maven built-in path expressions (<code>${project.basedir}</code>, <code>${project.build.directory}</code>, etc.) were always reported as changed whenever any ancestor POM was modified, even when nothing relevant had changed. The root cause: old effective models are built in a temporary directory, so Maven resolves path-anchored expressions against the temp path — making old and new values structurally different regardless of actual content. These properties are now excluded from the comparison.</p> <ul> <li>fix: skip path-anchored properties in effective-model comparison (<a href="https://redirect.github.com/maveniverse/scalpel/issues/214">#214</a>) <a href="https://github.com/gnodet"><code>@gnodet</code></a></li> </ul> <h2>🧰 Maintenance</h2> <ul> <li>chore(deps): bump release-drafter/release-drafter from 7.7.0 to 7.9.0 (<a href="https://redirect.github.com/maveniverse/scalpel/issues/217">#217</a>) <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot]</li> <li>chore(deps-dev): bump org.mockito:mockito-core from 5.23.0 to 5.24.0 (<a href="https://redirect.github.com/maveniverse/scalpel/issues/212">#212</a>) <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot]</li> <li>chore(deps): bump eu.maveniverse.maven.parent:parent from 62 to 64 (<a href="https://redirect.github.com/maveniverse/scalpel/issues/218">#218</a>) <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot]</li> <li>chore(deps): bump version.slf4j from 2.0.19 to 2.0.20 (<a href="https://redirect.github.com/maveniverse/scalpel/issues/210">#210</a>) <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot]</li> <li>ci: add njord auto-publish parameters to release workflow (<a href="https://redirect.github.com/maveniverse/scalpel/issues/206">#206</a>) <a href="https://github.com/gnodet"><code>@gnodet</code></a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/maveniverse/scalpel/compare/0.4.2...0.4.3">https://github.com/maveniverse/scalpel/compare/0.4.2...0.4.3</a></p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/maveniverse/scalpel/commit/ed2d41970cb59ae6982b17b8daca1a439d00a492"><code>ed2d419</code></a> fix: deleted-module source files must not be attributed to surviving ancestor...</li> <li><a href="https://github.com/maveniverse/scalpel/commit/b1e884166bbd62dd4415352fa5b71ea87350a5ca"><code>b1e8841</code></a> chore(deps): bump release-drafter/release-drafter from 7.7.0 to 7.9.0</li> <li><a href="https://github.com/maveniverse/scalpel/commit/501e5b39dbdc9e22328e0f2d36599f65634617a9"><code>501e5b3</code></a> chore(deps-dev): bump org.mockito:mockito-core from 5.23.0 to 5.24.0</li> <li><a href="https://github.com/maveniverse/scalpel/commit/a5631f00d61fddad5a9a3656d5fc81fae60463f3"><code>a5631f0</code></a> chore(deps): bump eu.maveniverse.maven.parent:parent from 62 to 64</li> <li><a href="https://github.com/maveniverse/scalpel/commit/8a99dd4265a791a21b24097b1565660dafac4137"><code>8a99dd4</code></a> chore(deps): bump version.slf4j from 2.0.19 to 2.0.20</li> <li><a href="https://github.com/maveniverse/scalpel/commit/c49983bd123c299657c9dda098990806e88ee25f"><code>c49983b</code></a> fix: use per-project active profile IDs when building effective models (<a href="https://redirect.github.com/maveniverse/scalpel/issues/209">#209</a>)</li> <li><a href="https://github.com/maveniverse/scalpel/commit/e3f37fc56cf11f137b676af03f56429b94f85088"><code>e3f37fc</code></a> fix: limit effective model builds to changed POMs and prevent OOM (<a href="https://redirect.github.com/maveniverse/scalpel/issues/207">#207</a>)</li> <li><a href="https://github.com/maveniverse/scalpel/commit/789dde7f9553a00bcbf188d57965b36b0dc2c321"><code>789dde7</code></a> fix: skip path-anchored properties in effective-model comparison (<a href="https://redirect.github.com/maveniverse/scalpel/issues/214">#214</a>)</li> <li><a href="https://github.com/maveniverse/scalpel/commit/42bdc91ebd22f8d6c526ab9bf55a5ae823dd646e"><code>42bdc91</code></a> ci: add njord auto-publish parameters to release workflow (<a href="https://redirect.github.com/maveniverse/scalpel/issues/206">#206</a>)</li> <li><a href="https://github.com/maveniverse/scalpel/commit/bf7058735d85766af9997f6878ad88211828c95c"><code>bf70587</code></a> Add KEYS file with GPG public signing key</li> <li>See full diff in <a href="https://github.com/maveniverse/scalpel/compare/0.4.2...0.4.3">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
