Title: When graphql-java 17.x is an implementation dependency of a gradle project, it pulls in guava. · Issue #2540 · graphql-java/graphql-java · GitHub
Open Graph Title: When graphql-java 17.x is an implementation dependency of a gradle project, it pulls in guava. · Issue #2540 · graphql-java/graphql-java
X Title: When graphql-java 17.x is an implementation dependency of a gradle project, it pulls in guava. · Issue #2540 · graphql-java/graphql-java
Description: Describe the bug It appears that graphql-java is not supposed to have a runtime dependency on Guava, because the main jar artifact is an output of shadowJar, which embeds guava underneath the graphql package namespace. And indeed, guava ...
Open Graph Description: Describe the bug It appears that graphql-java is not supposed to have a runtime dependency on Guava, because the main jar artifact is an output of shadowJar, which embeds guava underneath the graph...
X Description: Describe the bug It appears that graphql-java is not supposed to have a runtime dependency on Guava, because the main jar artifact is an output of shadowJar, which embeds guava underneath the graph...
Opengraph URL: https://github.com/graphql-java/graphql-java/issues/2540
X: @github
Domain: github.com
{"@context":"https://schema.org","@type":"DiscussionForumPosting","headline":"When graphql-java 17.x is an implementation dependency of a gradle project, it pulls in guava.","articleBody":"**Describe the bug**\r\nIt appears that graphql-java is not supposed to have a runtime dependency on Guava, because the main jar artifact is an output of shadowJar, which embeds guava underneath the graphql package namespace. And indeed, guava is not listed as a dependency in the pom. And yet, when you build a project using gradle to depend on graphql-java 17.x, guava (and several of its dependencies) are pulled into its dependency graph.\r\n\r\nThis appears to be because gradle will prefer the data in the generated graphql-java-17.2.module file, being directed to do so by a comment in the pom. The pom has its guava dependency edited out in build, but the .module file is unchanged.\r\n\r\nThis probably applies to antlr4 as well. (I think antlr4-runtime is supposed to be there but not plain antlr4?)\r\n\r\nThis did not occur with graphql 16.2. It appears it starts with 17.0, and continues with 17.2.\r\n\r\n**To Reproduce**\r\nAttached is a trivial gradle project called `graphql-depender` because all it does is depend on graphql-java. It's made by creating a default gradle java application project (using gradle init), editing build.gradle and removing the default guava dependency and adding an implementation dependency on graphl-java 17.2, in the form:\r\n\r\n```\r\n implementation 'com.graphql-java:graphql-java:17.2'\r\n```\r\n\r\n[graphql-depender.tar.gz](https://github.com/graphql-java/graphql-java/files/7120661/graphql-depender.tar.gz)\r\n\r\nUnpack the jar, and run:\r\n\r\n```\r\n./gradlew installDist\r\n```\r\n\r\nYou will see that `app/build/install/app/lib` contains a number of jars, including guava and its dependencies.\r\n\r\nShow the dependency tree:\r\n\r\n```\r\n./gradlew --console=plain app:dependencies --configuration runtimeClasspath\r\n\r\n\u003e Task :app:dependencies\r\n\r\n------------------------------------------------------------\r\nProject ':app'\r\n------------------------------------------------------------\r\n\r\nruntimeClasspath - Runtime classpath of source set 'main'.\r\n\\--- com.graphql-java:graphql-java:17.2\r\n +--- org.antlr:antlr4-runtime:4.9.2\r\n +--- org.slf4j:slf4j-api:1.7.30\r\n +--- com.google.guava:guava:30.0-jre\r\n | +--- com.google.guava:failureaccess:1.0.1\r\n | +--- com.google.guava:listenablefuture:9999.0-empty-to-avoid-conflict-with-guava\r\n | +--- com.google.code.findbugs:jsr305:3.0.2\r\n | +--- org.checkerframework:checker-qual:3.5.0\r\n | +--- com.google.errorprone:error_prone_annotations:2.3.4\r\n | \\--- com.google.j2objc:j2objc-annotations:1.3\r\n +--- com.graphql-java:java-dataloader:3.1.0\r\n | \\--- org.slf4j:slf4j-api:1.7.30\r\n +--- org.reactivestreams:reactive-streams:1.0.2\r\n \\--- org.antlr:antlr4:4.9.2\r\n +--- org.antlr:antlr4-runtime:4.9.2\r\n +--- org.antlr:antlr-runtime:3.5.2\r\n +--- org.antlr:ST4:4.3\r\n | \\--- org.antlr:antlr-runtime:3.5.2\r\n +--- org.abego.treelayout:org.abego.treelayout.core:1.0.3\r\n +--- org.glassfish:javax.json:1.0.4\r\n \\--- com.ibm.icu:icu4j:61.1\r\n\r\n(*) - dependencies omitted (listed previously)\r\n\r\nA web-based, searchable dependency report is available by adding the --scan option.\r\n\r\nBUILD SUCCESSFUL in 468ms\r\n1 actionable task: 1 executed\r\n```\r\n\r\n**Workaround**\r\n\r\nI have a workaround, which I'm not entirely sure is correct, which is to exclude the transitive dependencies I don't want (ie: don't think are really required) in the dependency declaration like this:\r\n\r\n```\r\n implementation('com.graphql-java:graphql-java:17.2') {\r\n exclude group: 'com.google.guava'\r\n exclude group: 'org.antlr', module: 'antlr4'\r\n }\r\n```\r\n\r\nThis appears to work:\r\n\r\n```\r\n./gradlew --console=plain app:dependencies --configuration runtimeClasspath\r\n\r\n\u003e Task :app:dependencies\r\n\r\n------------------------------------------------------------\r\nProject ':app'\r\n------------------------------------------------------------\r\n\r\nruntimeClasspath - Runtime classpath of source set 'main'.\r\n\\--- com.graphql-java:graphql-java:17.2\r\n +--- org.antlr:antlr4-runtime:4.9.2\r\n +--- org.slf4j:slf4j-api:1.7.30\r\n +--- com.graphql-java:java-dataloader:3.1.0\r\n | \\--- org.slf4j:slf4j-api:1.7.30\r\n \\--- org.reactivestreams:reactive-streams:1.0.2\r\n\r\n(*) - dependencies omitted (listed previously)\r\n\r\nA web-based, searchable dependency report is available by adding the --scan option.\r\n\r\nBUILD SUCCESSFUL in 558ms\r\n1 actionable task: 1 executed\r\n```\r\n","author":{"url":"https://github.com/StrangeNoises","@type":"Person","name":"StrangeNoises"},"datePublished":"2021-09-07T10:24:45.000Z","interactionStatistic":{"@type":"InteractionCounter","interactionType":"https://schema.org/CommentAction","userInteractionCount":8},"url":"https://github.com/2540/graphql-java/issues/2540"}
| route-pattern | /_view_fragments/issues/show/:user_id/:repository/:id/issue_layout(.:format) |
| route-controller | voltron_issues_fragments |
| route-action | issue_layout |
| fetch-nonce | v2:9dce9c79-4e95-9515-6657-be386fa60749 |
| current-catalog-service-hash | 81bb79d38c15960b92d99bca9288a9108c7a47b18f2423d0f6438c5b7bcd2114 |
| request-id | D090:2AB1FC:301340F:4572A87:6A60EEC5 |
| html-safe-nonce | 7d6a58387bae2f9a6920a213958220f2d69db081780c721106b57bd0f00f37be |
| visitor-payload | eyJyZWZlcnJlciI6IiIsInJlcXVlc3RfaWQiOiJEMDkwOjJBQjFGQzozMDEzNDBGOjQ1NzJBODc6NkE2MEVFQzUiLCJ2aXNpdG9yX2lkIjoiMjg5NDg1OTc2NTE4NDI2MTgyOSIsInJlZ2lvbl9lZGdlIjoiaWFkIiwicmVnaW9uX3JlbmRlciI6ImlhZCJ9 |
| visitor-hmac | 9e5343bd28a58ab6fa4613299620c84c6992becad003342606a54f7f7a703078 |
| hovercard-subject-tag | issue:989833352 |
| github-keyboard-shortcuts | repository,issues,copilot |
| google-site-verification | Apib7-x98H0j5cPqHWwSMm6dNU4GmODRoqxLiDzdx9I |
| octolytics-url | https://collector.github.com/github/collect |
| analytics-location | / |
| fb:app_id | 1401488693436528 |
| apple-itunes-app | app-id=1477376905, app-argument=https://github.com/_view_fragments/issues/show/graphql-java/graphql-java/2540/issue_layout |
| twitter:image | https://opengraph.githubassets.com/7933fcf7d41198c4f05d684f2f8742acdc294f2804695c461a6c8f359f9fa0bd/graphql-java/graphql-java/issues/2540 |
| twitter:card | summary_large_image |
| og:image | https://opengraph.githubassets.com/7933fcf7d41198c4f05d684f2f8742acdc294f2804695c461a6c8f359f9fa0bd/graphql-java/graphql-java/issues/2540 |
| og:image:alt | Describe the bug It appears that graphql-java is not supposed to have a runtime dependency on Guava, because the main jar artifact is an output of shadowJar, which embeds guava underneath the graph... |
| og:image:width | 1200 |
| og:image:height | 600 |
| og:site_name | GitHub |
| og:type | object |
| og:author:username | StrangeNoises |
| hostname | github.com |
| expected-hostname | github.com |
| None | 3ba36a464b9464992131f4003292a219fc87f92404b0dbe3fd1ef07f11102d0f |
| turbo-cache-control | no-preview |
| go-import | github.com/graphql-java/graphql-java git https://github.com/graphql-java/graphql-java.git |
| octolytics-dimension-user_id | 14289921 |
| octolytics-dimension-user_login | graphql-java |
| octolytics-dimension-repository_id | 38602457 |
| octolytics-dimension-repository_nwo | graphql-java/graphql-java |
| octolytics-dimension-repository_public | true |
| octolytics-dimension-repository_is_fork | false |
| octolytics-dimension-repository_network_root_id | 38602457 |
| octolytics-dimension-repository_network_root_nwo | graphql-java/graphql-java |
| turbo-body-classes | logged-out env-production page-responsive |
| disable-turbo | false |
| browser-stats-url | https://api.github.com/_private/browser/stats |
| browser-errors-url | https://api.github.com/_private/browser/errors |
| release | 2cc5e4f897a27632dd600edfec4c737bea2f8338 |
| ui-target | full |
| theme-color | #1e2327 |
| color-scheme | light dark |
Links:
Viewport: width=device-width