Hacker News new | ask | show | jobs
by zahlman 315 days ago
So you... manually re-lock the parts you need to?
2 comments

Don't forget the part where Maven silently picks one version for you when there are transitive dependency conflicts (and no, it's not always the newest one).
Sure, I'm happy with locking the parts I need to lock. Why would I lock the parts I don't need to lock?
Because you can’t know which ones you “need” to lock.
You can definitely know this. Use

    mvn dependency:tree -Dverbose
Or use maven-enforcer-plugin to fail the build on conflicts.