Skip to content

Stop dependabot from offering guice 7 on the 1.9.x line - #2072

Merged
slachiewicz merged 1 commit into
masterfrom
dependabot-ignore-guice-on-1.9.x
Aug 23, 2026
Merged

slachiewicz merged 1 commit into
masterfrom
dependabot-ignore-guice-on-1.9.x

Conversation

@slachiewicz

Copy link
Copy Markdown
Member

Guice 6 switched from javax.inject to jakarta.inject, so #2070 fails to compile on maven-resolver-1.9.x:

AetherModule.java:[282,17] no suitable method found for
  toProvider(java.lang.Class<...StaticNameMapperProvider>)

I checked whether the two could be supported at once. Changing the nine *NameMapperProvider classes from javax.inject.Provider to com.google.inject.Provider does make the module compile against guice 5.1.0 and 7.0.0, and all 358 maven-resolver-impl tests pass on 5.1.0. But on 7.0.0 AetherModuleTest.testModuleCompleteness then fails:

No implementation for DependencyCollectorDelegate was bound.
Did you mean?
  * DependencyCollectorDelegate annotated with @Named("bf") bound at AetherModule.configure(:162)
Requested by: AetherModule.dependencyCollectorDelegates(AetherModule.java:370)

Guice 7 dropped javax.inject annotation support outright, so the @Named qualifiers on the @Provides parameters are invisible to it. Fixing the Provider signature only moves the failure from compile time to injector creation. Taking guice 7 on this line means migrating the whole stack to jakarta.inject, which is not a maintenance-branch change.

Worth recording: both 5.1.0 and 7.0.0 are Java 8 bytecode, so the Java 8 baseline is not what blocks this. Master is unaffected — it has no AetherModule.

Supersedes #2070.

This change was created with AI assistance.

Guice 6 moved to jakarta.inject. The Provider signature can be made to
compile against both, but guice 7 also drops javax.inject annotation
scanning, so AetherModule stops wiring. It is a migration, not a bump.
@slachiewicz slachiewicz added the dependencies Pull requests that update a dependency file label Aug 23, 2026
@slachiewicz
slachiewicz marked this pull request as ready for review August 23, 2026 10:32
@slachiewicz
slachiewicz merged commit 02b81a8 into master Aug 23, 2026
24 of 25 checks passed
@slachiewicz
slachiewicz deleted the dependabot-ignore-guice-on-1.9.x branch August 23, 2026 10:32
@github-actions github-actions Bot added this to the 2.0.23 milestone Aug 23, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant