Maven
Description
The Maven crawler looks recursively for all pom.xml files from a specific root directory, and tries to update the dependencies declared in each one.
Two things are updated per POM:
every entry under
<dependencies>the
<parent>POM, when one is declared
This crawler is enabled by default, so it can be used either automatically by running updatecli diff from a directory containing the files to update, or by providing a manifest.
The automatic discovery behavior can be tuned by providing a YAML manifest with a maven crawler in top-level directive autodiscovery as explained in the "Autodiscovery" page.
Generated manifests
Repositories, mirrors, and credentials
The repository used to look up a dependency is taken from the <repositories> declared in the POM, falling back to Maven Central.
Updatecli also reads settings.xml, looked up in this order:
settings.xmlnext to the POM$HOME/.m2/settings.xml
From it, Updatecli applies:
mirrors - a repository whose
idor URL matches a<mirrorOf>rule is replaced by the mirror, including thecentralshorthand,server credentials - the
<username>and<password>of the<server>whoseidmatches the repository.
The MAVEN_MIRROR_URL environment variable is honoured, and ${env.VARIABLE} expressions inside settings.xml are interpolated.
Version filtering
Unlike most crawlers, the version filter defaults to kind latest, because Maven coordinates do not reliably follow semantic versioning. Set an explicit versionfilter to constrain updates.
More details on the "Version Filtering" page.
Limitations
A dependency whose
<version>is a property reference, such as${junit.version}, is skipped. Updatecli does not resolve the property to find the literal it should rewrite.Only files named exactly
pom.xmlare scanned.
Manifest
Parameters
| Name | Type | Description | Required |
|---|---|---|---|
| ignore | array | Ignore allows to specify rule to ignore autodiscovery a specific Helm based on a rule | |
| artifactids | object | ArtifactIDs specifies the list of Maven ArtifactIDs to check | |
| groupids | array | GroupIDs specifies the list of Maven GroupIDs to check | |
| path | string | Path specifies a Helm chart path pattern, the pattern requires to match all of name, not just a substring. | |
| only | array | Only allows to specify rule to only autodiscover manifest for a specific Helm based on a rule | |
| artifactids | object | ArtifactIDs specifies the list of Maven ArtifactIDs to check | |
| groupids | array | GroupIDs specifies the list of Maven GroupIDs to check | |
| path | string | Path specifies a Helm chart path pattern, the pattern requires to match all of name, not just a substring. | |
| rootdir | string | RootDir defines the root directory used to recursively search for Helm Chart | |
| versionfilter | object |
kind - semver
versionfilter of kind kind - regex
versionfilter of kind example: and its type like regex, semver, or just latest. More examples can be found at https://www.updatecli.io/docs/core/versionfilter/ | |
| kind | string | specifies the version kind such as semver, regex, or latest | |
| pattern | string | specifies the version pattern according the version kind for semver, it is a semver constraint for regex, it is a regex pattern for time, it is a date format | |
| regex | string | specifies the regex pattern, used for regex/semver and regex/time. Output of the first capture group will be used. | |
| replaceall | object | replaceAll applies a regex replacement to version strings before filtering. This is useful for transforming versions (e.g., curl-8_15_0 to curl-8.15.0) before regex extraction. | |
| pattern | string | Pattern specifies the regex pattern to match for replacement | |
| replacement | string | Replacement specifies the replacement string (supports $1, $2, etc. for captured groups) | |
| strict | boolean | strict enforce strict versioning rule. Only used for semantic versioning at this time |
Example
# updatecli.d/default.yaml
name: "Maven autodiscovery using git scm"
scms:
default:
kind: git
spec:
url: https://github.com/olblak/jenkins-datadog-plugin.git
branch: master
autodiscovery:
# scmid is applied to all crawlers
scmid: default
crawlers:
maven:
# To ignore specific path
#ignore:
# - path: <filepath relative to scm repository>
#only:
# - path: <filepath relative to scm repository>