dsmiley commented on PR #4966:
URL: https://github.com/apache/solr/pull/4966#issuecomment-5905296646

   🤖 A thought for a follow-up, based on generating the 9.11 dependency entries 
by hand. Comparing the jars actually inside the binary distribution is more 
accurate than comparing `solr/licenses/*.sha1` plus the LICENSE-file filter.
   
   For 9.10.1 → 9.11, I compared the output against the jars in the official 
9.10.1 tarball and in a fresh 9.11 build (`gradlew :solr:packaging:devFull`):
   - **32 jars appeared that we don't ship**, e.g. mockito, testcontainers, 
docker-java, the hadoop minicluster/minikdc/kerby jars, byte-buddy and 
`bc*-jdk18on`. They have `.sha1` files, and on 9.x also LICENSE files.
   - **10 real removals were missed**, e.g. `bc*-jdk15on`, jaxb, `jna` and 
`joda-time`. They left the distribution (likely with the in-process Tika 
backend) but still have `.sha1` files because tests use them.
   
   Net effect: upgraded went from 87 to 74 entries and removed from 43 to 48. 
That's what I committed for 9.11.
   
   Proposal: take the jar list from each distribution instead.
   - **Old side:** the previous release tarball from archive.apache.org (or 
Docker container). Listing the tarball's contents is enough; nothing has to be 
unpacked.
   - **New side:** the jars from `:solr:packaging:devFull`, or the RC tarball 
when one exists.
   - **Parsing and grouping** stay as they are.
   - **Cost:** a build or a download of roughly 300 MB, instead of pure git. It 
also makes the LICENSE-file heuristic and the test-artifact name filter 
unnecessary.
   
   This could go in this PR or a follow-up. The current sha1-based version is 
still a big improvement over the old per-PR entries.
   
   Note: looking at JARs is less than perfect as well, as it doesn't include 
non-JAR dependencies such as jQuery.
   
   Finally... what we _really_ want is likely a Cyclone DX SBOM to do 
comparisons.  CC @epugh 
   
   🤖 Generated with [Claude Code](https://claude.com/claude-code) and 
reviewed/edited by Smiley
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to