Maven resolved version doesn't match version in transitive dependency

Viewed 479

my project (A) is dependent on another proprietary project (B). B lists spring-jms as a dependency like this (spring.version is [4.3.9.RELEASE, 4.3.18.RELEASE]):

    <dependency>
        <groupId>org.springframework</groupId>
        <artifactId>spring-jms</artifactId>
        <version>${spring.version}</version>
    </dependency>

A -> B -> spring-jms

However, when I run mvn clean dependency:tree -Dverbose=true in my A, spring-jms comes back as 5.1.14.RELEASE, which is outside the range specified in B. In the tree, spring-jms is listed twice and both entries have 5.1.14.RELEASE.

I don't have spring-jms listed in A. I know I can add it to dependencyManagement in A to fix the issue, but I'd still like to know why it's resolving that version.

Below is the part of the tree showing spring-jms. These are the only places it's listed.

[INFO] --- maven-dependency-plugin:2.8:tree (default-cli) @ project A ---
[INFO] project A
[INFO] +- project B
[INFO] |  +- (org.springframework:spring-context:jar:5.1.14.RELEASE:compile - omitted for duplicate)
[INFO] |  +- org.springframework:spring-jms:jar:5.1.14.RELEASE:compile
[INFO] |  |  \- (org.springframework:spring-messaging:jar:5.1.14.RELEASE:compile - version managed from 5.1.11.RELEASE; omitted for duplicate)
[INFO] |  +- org.springframework:spring-aop:jar:5.1.14.RELEASE:compile
[INFO] |  +- org.springframework:spring-oxm:jar:5.1.14.RELEASE:compile
[INFO] |  +- org.springframework:spring-expression:jar:5.1.14.RELEASE:compile
[INFO] |  +- (org.apache.commons:commons-collections4:jar:4.3:compile - omitted for duplicate)
[INFO] |  +- org.bouncycastle:bcprov-jdk15on:jar:1.56:compile
[INFO] |  +- org.springframework.integration:spring-integration-jms:jar:5.1.9.RELEASE:compile
[INFO] |  |  \- (org.springframework:spring-jms:jar:5.1.14.RELEASE:compile - version managed from 5.1.11.RELEASE; omitted for duplicate)

2 Answers

It can happen if one of your dependencies is using 5.1.14.RELEASE. If you are using IntelliJ you can use maven section in the right to check your dependencies there you can find out that. Then you can use exclusion to remove that dependency

<dependency>
            <groupId>com.smaple.dependency</groupId>
            <artifactId>dependency</artifactId>
            <version>version</version>
            <exclusions>
                <exclusion>
                    <groupId>springjms</groupId>
                    ...
                </exclusion>
            </exclusions>
</dependency>

Run mvn dependency:tree command and try to find all the appearances of spring-jms.

When maven resolves dependencies and if there are different versions of dependencies it will take the closest to the root in terms of depth in the tree of dependencies.

So if you project has the following tree:

YOUR_PROJECT
|___ <PROJECT_B>
|   |__spring-jms-v1 // depth = 2
|___spring-jms-v2    // depth = 1

Maven will take spring-jms-v2 because its closer to the root

In any case, mvn dependency:tree will show both versions and full paths to the "root"

Related