dependabot[bot] opened a new pull request, #27621:
URL: https://github.com/apache/camel/pull/27621

   Bumps 
[eu.maveniverse.maven.scalpel:extension3](https://github.com/maveniverse/scalpel)
 from 0.4.2 to 0.4.3.
   <details>
   <summary>Release notes</summary>
   <p><em>Sourced from <a 
href="https://github.com/maveniverse/scalpel/releases";>eu.maveniverse.maven.scalpel:extension3's
 releases</a>.</em></p>
   <blockquote>
   <h2>Scalpel 0.4.3</h2>
   <h2>What's Changed</h2>
   <h2>🐛 Bug Fixes</h2>
   <h3>Deleted-module source files no longer attributed to surviving ancestor 
(<a 
href="https://redirect.github.com/maveniverse/scalpel/issues/216";>#216</a>)</h3>
   <p>When a module was removed from the reactor, source files that previously 
belonged to it (e.g. <code>libs/lib-gone/src/main/java/Foo.java</code>) were 
being walked up the directory tree until they hit the nearest surviving 
ancestor (<code>libs</code>). That ancestor was then reported as a <code>DIRECT 
SOURCE_CHANGE</code>, pulling all its children and their transitive dependents 
into the build — even though nothing in the surviving reactor depended on the 
deleted module. The fix computes a set of deleted-module directory prefixes at 
detection time and stops the owner-walk at those boundaries.</p>
   <ul>
   <li>fix: deleted-module source files must not be attributed to surviving 
ancestor (<a 
href="https://redirect.github.com/maveniverse/scalpel/issues/216";>#216</a>) (<a 
href="https://redirect.github.com/maveniverse/scalpel/issues/219";>#219</a>) <a 
href="https://github.com/gnodet";><code>@​gnodet</code></a></li>
   </ul>
   <h3>Per-project active profile IDs used when building effective models (<a 
href="https://redirect.github.com/maveniverse/scalpel/issues/215";>#215</a>)</h3>
   <p>POM analysis was incorrectly marking unrelated modules as 
<code>TRANSITIVE</code> / <code>TRANSITIVE_DEPENDENCY</code> when sibling 
modules declared profiles with the same ID but different activations. The root 
cause was that <code>collectAllActiveProfileIds()</code> merged profile IDs 
from all reactor projects into a single union and applied it uniformly when 
building each module's old effective model, causing sibling profiles to be 
force-activated in modules where they are not active. The fix passes 
per-project active profile IDs to the model builder instead.</p>
   <ul>
   <li>fix: use per-project active profile IDs when building effective models 
(<a href="https://redirect.github.com/maveniverse/scalpel/issues/209";>#209</a>) 
(<a href="https://redirect.github.com/maveniverse/scalpel/issues/215";>#215</a>) 
<a href="https://github.com/gnodet";><code>@​gnodet</code></a></li>
   </ul>
   <h3>Effective model builds limited to changed POMs to prevent OOM (<a 
href="https://redirect.github.com/maveniverse/scalpel/issues/208";>#208</a>)</h3>
   <p>In large reactors (e.g. Quarkus: 1800+ modules), Scalpel was building 
effective models for every reactor module upfront during POM analysis. Each 
<code>DefaultModelBuilder.build()</code> call triggered recursive 
<code>importDependencyManagement</code> on BOM chains and copied the full 
system properties (including large <code>env.*</code> entries) for every 
module, causing heap exhaustion. Effective model builds are now limited to 
changed POMs and their direct dependents — the only modules where a change 
comparison is meaningful.</p>
   <ul>
   <li>fix: limit effective model builds to changed POMs and their dependents 
to prevent OOM (<a 
href="https://redirect.github.com/maveniverse/scalpel/issues/207";>#207</a>) (<a 
href="https://redirect.github.com/maveniverse/scalpel/issues/208";>#208</a>) <a 
href="https://github.com/gnodet";><code>@​gnodet</code></a></li>
   </ul>
   <h3>Path-anchored properties skipped in effective-model comparison (<a 
href="https://redirect.github.com/maveniverse/scalpel/issues/214";>#214</a>)</h3>
   <p>Properties in child POMs using Maven built-in path expressions 
(<code>${project.basedir}</code>, <code>${project.build.directory}</code>, 
etc.) were always reported as changed whenever any ancestor POM was modified, 
even when nothing relevant had changed. The root cause: old effective models 
are built in a temporary directory, so Maven resolves path-anchored expressions 
against the temp path — making old and new values structurally different 
regardless of actual content. These properties are now excluded from the 
comparison.</p>
   <ul>
   <li>fix: skip path-anchored properties in effective-model comparison (<a 
href="https://redirect.github.com/maveniverse/scalpel/issues/214";>#214</a>) <a 
href="https://github.com/gnodet";><code>@​gnodet</code></a></li>
   </ul>
   <h2>🧰 Maintenance</h2>
   <ul>
   <li>chore(deps): bump release-drafter/release-drafter from 7.7.0 to 7.9.0 
(<a href="https://redirect.github.com/maveniverse/scalpel/issues/217";>#217</a>) 
<a href="https://github.com/dependabot";><code>@​dependabot</code></a>[bot]</li>
   <li>chore(deps-dev): bump org.mockito:mockito-core from 5.23.0 to 5.24.0 (<a 
href="https://redirect.github.com/maveniverse/scalpel/issues/212";>#212</a>) <a 
href="https://github.com/dependabot";><code>@​dependabot</code></a>[bot]</li>
   <li>chore(deps): bump eu.maveniverse.maven.parent:parent from 62 to 64 (<a 
href="https://redirect.github.com/maveniverse/scalpel/issues/218";>#218</a>) <a 
href="https://github.com/dependabot";><code>@​dependabot</code></a>[bot]</li>
   <li>chore(deps): bump version.slf4j from 2.0.19 to 2.0.20 (<a 
href="https://redirect.github.com/maveniverse/scalpel/issues/210";>#210</a>) <a 
href="https://github.com/dependabot";><code>@​dependabot</code></a>[bot]</li>
   <li>ci: add njord auto-publish parameters to release workflow (<a 
href="https://redirect.github.com/maveniverse/scalpel/issues/206";>#206</a>) <a 
href="https://github.com/gnodet";><code>@​gnodet</code></a></li>
   </ul>
   <p><strong>Full Changelog</strong>: <a 
href="https://github.com/maveniverse/scalpel/compare/0.4.2...0.4.3";>https://github.com/maveniverse/scalpel/compare/0.4.2...0.4.3</a></p>
   </blockquote>
   </details>
   <details>
   <summary>Commits</summary>
   <ul>
   <li><a 
href="https://github.com/maveniverse/scalpel/commit/ed2d41970cb59ae6982b17b8daca1a439d00a492";><code>ed2d419</code></a>
 fix: deleted-module source files must not be attributed to surviving 
ancestor...</li>
   <li><a 
href="https://github.com/maveniverse/scalpel/commit/b1e884166bbd62dd4415352fa5b71ea87350a5ca";><code>b1e8841</code></a>
 chore(deps): bump release-drafter/release-drafter from 7.7.0 to 7.9.0</li>
   <li><a 
href="https://github.com/maveniverse/scalpel/commit/501e5b39dbdc9e22328e0f2d36599f65634617a9";><code>501e5b3</code></a>
 chore(deps-dev): bump org.mockito:mockito-core from 5.23.0 to 5.24.0</li>
   <li><a 
href="https://github.com/maveniverse/scalpel/commit/a5631f00d61fddad5a9a3656d5fc81fae60463f3";><code>a5631f0</code></a>
 chore(deps): bump eu.maveniverse.maven.parent:parent from 62 to 64</li>
   <li><a 
href="https://github.com/maveniverse/scalpel/commit/8a99dd4265a791a21b24097b1565660dafac4137";><code>8a99dd4</code></a>
 chore(deps): bump version.slf4j from 2.0.19 to 2.0.20</li>
   <li><a 
href="https://github.com/maveniverse/scalpel/commit/c49983bd123c299657c9dda098990806e88ee25f";><code>c49983b</code></a>
 fix: use per-project active profile IDs when building effective models (<a 
href="https://redirect.github.com/maveniverse/scalpel/issues/209";>#209</a>)</li>
   <li><a 
href="https://github.com/maveniverse/scalpel/commit/e3f37fc56cf11f137b676af03f56429b94f85088";><code>e3f37fc</code></a>
 fix: limit effective model builds to changed POMs and prevent OOM (<a 
href="https://redirect.github.com/maveniverse/scalpel/issues/207";>#207</a>)</li>
   <li><a 
href="https://github.com/maveniverse/scalpel/commit/789dde7f9553a00bcbf188d57965b36b0dc2c321";><code>789dde7</code></a>
 fix: skip path-anchored properties in effective-model comparison (<a 
href="https://redirect.github.com/maveniverse/scalpel/issues/214";>#214</a>)</li>
   <li><a 
href="https://github.com/maveniverse/scalpel/commit/42bdc91ebd22f8d6c526ab9bf55a5ae823dd646e";><code>42bdc91</code></a>
 ci: add njord auto-publish parameters to release workflow (<a 
href="https://redirect.github.com/maveniverse/scalpel/issues/206";>#206</a>)</li>
   <li><a 
href="https://github.com/maveniverse/scalpel/commit/bf7058735d85766af9997f6878ad88211828c95c";><code>bf70587</code></a>
 Add KEYS file with GPG public signing key</li>
   <li>See full diff in <a 
href="https://github.com/maveniverse/scalpel/compare/0.4.2...0.4.3";>compare 
view</a></li>
   </ul>
   </details>
   <br />
   
   
   [![Dependabot compatibility 
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=eu.maveniverse.maven.scalpel:extension3&package-manager=maven&previous-version=0.4.2&new-version=0.4.3)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
   
   Dependabot will resolve any conflicts with this PR as long as you don't 
alter it yourself. You can also trigger a rebase manually by commenting 
`@dependabot rebase`.
   
   [//]: # (dependabot-automerge-start)
   [//]: # (dependabot-automerge-end)
   
   ---
   
   <details>
   <summary>Dependabot commands and options</summary>
   <br />
   
   You can trigger Dependabot actions by commenting on this PR:
   - `@dependabot rebase` will rebase this PR
   - `@dependabot recreate` will recreate this PR, overwriting any edits that 
have been made to it
   - `@dependabot show <dependency name> ignore conditions` will show all of 
the ignore conditions of the specified dependency
   - `@dependabot ignore this major version` will close this PR and stop 
Dependabot creating any more for this major version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this minor version` will close this PR and stop 
Dependabot creating any more for this minor version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this dependency` will close this PR and stop 
Dependabot creating any more for this dependency (unless you reopen the PR or 
upgrade to it yourself)
   
   
   </details>


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to