Slackbot
12/22/2023, 3:28 AMVampire
12/22/2023, 8:12 AM--scan, or the output of the dependencyInsight and dependencies tasks to find out where the version is coming from.
Besides that, you shouldn't exclude it on cms and declare the dependency just to upgrade it. Only declaring it with higher number would be enough as conflict resolution picks the higher number. But even that would be unclean if you don't use okhttp in your own code. To just upgrade the transitive dependency, you would simply declare a constraint instead.Lance Li
12/22/2023, 8:25 AMgroovy
plugins {
id "org.springframework.boot" version "3.1.1" apply false
id 'io.spring.dependency-management' version '1.1.2' apply false
id 'java'
}
Upon inspecting the spring-boot dependencies https://github.com/spring-projects/spring-boot/blob/v3.1.1/spring-boot-project/spring-boot-dependencies/build.gradle, it appears as follows:
groovy
library("OkHttp", "4.10.0") {
group("com.squareup.okhttp3") {
imports = [
"okhttp-bom"
]
}
}
Consequently, when running gradle dependencies, the output shows:
| +--- com.squareup.okhttp3:okhttp:4.12.0 -> 4.10.0 (*)
Is there a more elegant solution to address this situation? Thank you 🙏Vampire
12/22/2023, 11:18 AMVampire
12/22/2023, 11:21 AMdependencies task, the dependencyInsight task, or a build --scan.
Even the maintainer of that plugin recommends not to use it anymore, but instead to use the built-in BOM support using platform(...).
So remove that plugin and instead use the built-in BOM support, it is also documented in the Spring Boot documentation how to do it.Lance Li
12/25/2023, 2:12 AM