Re: Will a version range for a parent pom reference work?

Francois Marot <[email protected]> Tue, 30 Jun 2026 13:36:07 +0200
Newsgroups gmane.comp.jakarta.turbine.maven.user
Message-ID <CALALGCRFbkUR4qm5RngmbUzVnGD1ZTK5Ba6Zy2msizPfLzkrNg@mail.gmail.com>
--00000000000046a65c065576fdbe
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

Hello all,
I would not be as affirmative as Greg and Elliotte. I think that parents
pom usually either define WHAT you build (defining dependencies) or HOW you
build (defining Maven plugins configuration) or a mix of both.
In the case of a parent pom defining exclusively HOW you build, it may be a
good idea to benefit from plugins upgrades shared amongst many projects.
But as soon as thing turn specific (defining Java version, dependencies
version, ...) I agree this may not be a good idea.
best regards

Francois

Le mar. 30 juin 2026 =C3=A0 13:21, Elliotte Rusty Harold <[email protected]=
g> a
=C3=A9crit :

> Whether it works or not, you really, really don't want to do this.
> It's a source of really hard to diagnose security bugs.
>
> On Mon, Jun 29, 2026 at 6:37=E2=80=AFPM KARR, DAVID via users
> <[email protected]> wrote:
> >
> > We are wondering whether we can use a version range for the
> "parent"->"version" property in our pom.xml. The docs don't explicitly sa=
y
> so, but comparing the info for the "version" property in "parent" vs.
> "dependency", we see that only in "dependency" does it mention the
> possibility of using the range syntax.  In our tests, it didn't reject th=
e
> range syntax in the parent, but we'd have to set up a more complex test t=
o
> verify whether it's actually respecting it.  We're currently on version
> 3.9.8.
> >
> > ---------------------------------------------------------------------
> > To unsubscribe, e-mail: [email protected]
> > For additional commands, e-mail: [email protected]
> >
>
>
> --
> Elliotte Rusty Harold
> [email protected]
>
> ---------------------------------------------------------------------
> To unsubscribe, e-mail: [email protected]
> For additional commands, e-mail: [email protected]
>
>

--00000000000046a65c065576fdbe--