Ignore org.eclipse.m2e:lifecycle-mapping in Maven dependency checks#15138
Open
yeikel wants to merge 1 commit into
Open
Ignore org.eclipse.m2e:lifecycle-mapping in Maven dependency checks#15138yeikel wants to merge 1 commit into
yeikel wants to merge 1 commit into
Conversation
This package is a virtual Eclipse IDE plugin that does not exist in any Maven repository. Dependabot was spending ~25 seconds per job making HTTP requests that always returned 404. Filter it out at parse time via a VIRTUAL_PACKAGES constant so version checking is never attempted. Closes dependabot#14877
1 task
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What are you trying to accomplish?
This package is a virtual Eclipse IDE plugin that does not exist in any Maven repository. Dependabot was spending ~25 seconds per job making HTTP requests that always returned 404.
After this change, we filter it out at parse time via a
VIRTUAL_PACKAGESconstant so version checking is never attempted.Fixes #14877
How will you know you've accomplished your goal?
Both existing and new tests pass
Checklist