Description

The Maven crawler looks recursively for all pom.xml files from a specific root directory, and tries to update the dependencies declared in each one.

Two things are updated per POM:

  • every entry under <dependencies>

  • the <parent> POM, when one is declared

This crawler is enabled by default, so it can be used either automatically by running updatecli diff from a directory containing the files to update, or by providing a manifest. The automatic discovery behavior can be tuned by providing a YAML manifest with a maven crawler in top-level directive autodiscovery as explained in the "Autodiscovery" page.

Generated manifests

Each dependency produces a maven source resolving the latest version, two xml conditions asserting that the groupId and artifactId still match, and an xml target writing the new version into the POM.

Repositories, mirrors, and credentials

The repository used to look up a dependency is taken from the <repositories> declared in the POM, falling back to Maven Central.

Updatecli also reads settings.xml, looked up in this order:

  1. settings.xml next to the POM

  2. $HOME/.m2/settings.xml

From it, Updatecli applies:

  • mirrors - a repository whose id or URL matches a <mirrorOf> rule is replaced by the mirror, including the central shorthand,

  • server credentials - the <username> and <password> of the <server> whose id matches the repository.

The MAVEN_MIRROR_URL environment variable is honoured, and ${env.VARIABLE} expressions inside settings.xml are interpolated.

Version filtering

Unlike most crawlers, the version filter defaults to kind latest, because Maven coordinates do not reliably follow semantic versioning. Set an explicit versionfilter to constrain updates.

More details on the "Version Filtering" page.

Limitations

  • A dependency whose <version> is a property reference, such as ${junit.version}, is skipped. Updatecli does not resolve the property to find the literal it should rewrite.

  • Only files named exactly pom.xml are scanned.

Manifest

Parameters

NameTypeDescriptionRequired
ignorearrayIgnore allows to specify rule to ignore autodiscovery a specific Helm based on a rule
    artifactidsobjectArtifactIDs specifies the list of Maven ArtifactIDs to check
    groupidsarrayGroupIDs specifies the list of Maven GroupIDs to check
    pathstringPath specifies a Helm chart path pattern, the pattern requires to match all of name, not just a substring.
onlyarrayOnly allows to specify rule to only autodiscover manifest for a specific Helm based on a rule
    artifactidsobjectArtifactIDs specifies the list of Maven ArtifactIDs to check
    groupidsarrayGroupIDs specifies the list of Maven GroupIDs to check
    pathstringPath specifies a Helm chart path pattern, the pattern requires to match all of name, not just a substring.
rootdirstringRootDir defines the root directory used to recursively search for Helm Chart
versionfilterobject

versionfilter provides parameters to specify the version pattern used when generating manifest.

kind - semver versionfilter of kind semver uses semantic versioning as version filtering pattern accepts one of: prerelease - Updatecli tries to identify the latest prerelease whatever it means patch - Updatecli only handles patch version update minor - Updatecli handles patch AND minor version update minoronly - Updatecli handles minor version only major - Updatecli handles patch, minor, AND major version update majoronly - Updatecli only handles major version update a version constraint such as >= 1.0.0

kind - regex versionfilter of kind regex uses regular expression as version filtering pattern accepts a valid regular expression

example:

  versionfilter:
    kind: semver
    pattern: minor

and its type like regex, semver, or just latest.

More examples can be found at https://www.updatecli.io/docs/core/versionfilter/

    kindstringspecifies the version kind such as semver, regex, or latest
    patternstringspecifies the version pattern according the version kind for semver, it is a semver constraint for regex, it is a regex pattern for time, it is a date format
    regexstringspecifies the regex pattern, used for regex/semver and regex/time. Output of the first capture group will be used.
    replaceallobjectreplaceAll applies a regex replacement to version strings before filtering. This is useful for transforming versions (e.g., curl-8_15_0 to curl-8.15.0) before regex extraction.
        patternstringPattern specifies the regex pattern to match for replacement
        replacementstringReplacement specifies the replacement string (supports $1, $2, etc. for captured groups)
    strictbooleanstrict enforce strict versioning rule. Only used for semantic versioning at this time
⚠ This table is generated from the Updatecli codebase and may contain inaccurate data. Feel free to report them on github.com/updatecli/updatecli

Example

# updatecli.d/default.yaml
name: "Maven autodiscovery using git scm"
scms:
  default:
    kind: git 
    spec:
      url: https://github.com/olblak/jenkins-datadog-plugin.git
      branch: master
    
autodiscovery:
  # scmid is applied to all crawlers
  scmid: default
  crawlers:
    maven:
      # To ignore specific path
      #ignore:
      #  - path: <filepath relative to scm repository>
      #only:
      #  - path: <filepath relative to scm repository>