<html>
  <head>
    <meta http-equiv="Content-Type" content="text/html; charset=utf-8">
  </head>
  <body text="#000000" bgcolor="#FFFFFF">
    <p><br>
    </p>
    <br>
    <div class="moz-cite-prefix">On 5/13/17 2:35 PM, Tom Zeller wrote:<br>
    </div>
    <blockquote type="cite"
      cite="mid:E0478A27-D53E-42F0-9660-9F91EC8088C1@dragonacea.biz">
      <blockquote type="cite">
        <blockquote type="cite">
          <pre wrap="">Have we ever actually looked in detail at all of our dependencies' dependencies to see that we're
actually getting what we/they think we should?  I personally haven't (b/c we assume it works rationally).
</pre>
        </blockquote>
      </blockquote>
      <pre wrap="">
I casually check the IdP's WEB-INF/lib during a release, but not rigorously (i.e. comparing to what Maven says).</pre>
    </blockquote>
    <br>
    I'm pretty confident that the IdP distribution includes what Maven
    *says* to include (what it resolves).  The issue is whether we can
    trust it to correctly supply the dependencies that are expected.<br>
    <br>
    What I meant by checking is actually looking at our direct
    dependencies' POMs, and seeing if what they intended to say are
    their dependencies are the same as what we get when Maven resolves
    those transitively through our direct dependencies.<br>
    <br>
    <br>
  </body>
</html>