slachiewicz opened a new pull request, #1225:
URL: https://github.com/apache/maven-plugin-tools/pull/1225

   `JavaAnnotationsMojoDescriptorExtractor` unpacked dependency `*-sources.jar` 
files through plexus-archiver's `ArchiverManager`, which the Maven 4 API line 
cannot inject. It now uses `java.util.zip` with a guard that rejects entries 
resolving outside the target directory; the layout and the extracted files are 
the same. plexus-archiver goes from maven-plugin-tools-annotations and from 
dependency management. The `ArchiverManager` was field-injected, so the 
extractor's constructor is unchanged.
   
   Ported to `maven-plugin-tools-3.x` in a separate PR.
   
   Part of apache/maven#13309.
   
   Verified: `mvn verify -Prun-its` → annotations 39 tests (2 new: extraction 
and a `../` entry), plugin ITs 32 passed, report ITs 12 passed.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to