Unlock parent POM?

Tom Zeller tzeller at dragonacea.biz
Wed Jun 10 10:04:34 EDT 2015


On Tue, Jun 9, 2015 at 2:39 PM, Brent Putman <putmanb at georgetown.edu> wrote:
> On 6/9/15 2:47 PM, Cantor, Scott wrote:
>> On 6/9/15, 6:35 PM, "Tom Zeller" <tzeller at dragonacea.biz> wrote:
>>> I'll bump spring-extensions and idp-parent. But I assume I should not
>>> bump opensaml-parent or java-support, since they don't depend on
>>> Spring nor Jetty, is that correct ?
>> I guess that's true in isolation, but in practice if we do new releases of
>> them (which we will), we'll want them on a single parent POM eventually.
>
> Yea, personally I say just keep them all consistent and do them all
> together.  Besides being simpler, that way there's no nasty surprises if
> there's transitive dependencies we haven't accounted for, resulting in
> duplicated deps with differing versions, etc.

While I agree with you Brent, I unlocked the IdP and spring-extensions
but not OpenSAML nor java-support.

Partially because that's "correct" AFAICT, but also because I am
interested in exposing any of those nasty surprises before we unlock
OpenSAML. As far as java-support goes, well ... I don't think we have
a version policy statement that all projects should target the same
parent POM for a release, makes sense though, but then that gets
confusing for me as to when the parent POM version should be made
consistent, i.e. how soon before a pending release.

So ... not trying to be contrary, just trying to follow our rules.

Perhaps we should devote a dev call to versioning at some point, I
think it would be helpful to talk through it again after Scott's
edits, especially when I'm more prepared.


More information about the dev mailing list