Hacktoberfest 2026: los issues que los mantenedores marcaron para octubre, abiertos y aptos para principiantes. Explorar issues de Hacktoberfest

`AddJaxbAPIDependencies` silently no-ops when `javax.xml.bind` is only JDK-provided

Abierto
#1,246 0 comentarios 0 reacciones 0 asignados Ver en GitHub

Los mantenedores suelen responder en 1 día

Nadie ha tomado este issue todavía.

Evaluación

Dificultad
4/5
Tiempo estimado
3-5 días
Aptitud para principiantes
68/100
Tipo de issue
Error
Claridad
Bastante claro
Estado de actividad
Activo
Stack tecnológico
java

Línea de trabajo

Start with jaxb-apis.yml at the AddJaxbAPIDependencies recipe and trace its onlyIfUsing condition when parsing the supplied Java example on JDK 11 or later. Compare the related recipes named in the issue and add a regression test for a module using javax.xml.bind with no JAXB dependency. Done means the migration adds the required JAXB dependencies and the project no longer has the reported compile break.

Escrito por el modelo de indexación a partir del texto del issue.

Descripción

bug

What version of OpenRewrite are you using?

  • Moderne CLI v4.8.8
  • org.openrewrite.recipe:rewrite-migrate-java:3.44.0-20260829.193944-5

Recipe YAML is unchanged on main as of b6526609.

How are you running OpenRewrite?

Moderne CLI against a single-module Maven project:

mod run . --recipe org.openrewrite.java.migrate.UpgradeToJava25

Reached via UpgradeToJava25 -> 21 -> 17 -> Java8toJava11 -> AddJaxbDependenciesWithRuntime -> AddJaxbAPIDependencies. Should also affect the Maven/Gradle plugin whenever the JDK parsing the project is 11+.

Public reproducer: https://github.com/CSPF-Founder/JavaVulnerableLab

What is the smallest, simplest way to reproduce the problem?

A Maven project using JAXB with no JAXB dependency declared — i.e. relying on the JDK to provide it:

<maven.compiler.source>1.7</maven.compiler.source>
<maven.compiler.target>1.7</maven.compiler.target>
<!-- no javax.xml.bind:jaxb-api / jakarta.xml.bind dependency -->
import javax.xml.bind.DatatypeConverter;

class JwtUtil {
    static String base64Url(byte[] data) {
        return DatatypeConverter.printBase64Binary(data);
    }
}

Run UpgradeToJava25 (or Java8toJava11) parsing with a JDK >= 11.

What did you expect to see?

AddJaxbAPIDependencies adds jakarta.xml.bind:jakarta.xml.bind-api (plus the glassfish runtime), so the project still compiles once source/target are raised.

What did you see instead?

source/target raised to 25, but no JAXB dependency added — leaving the exact compile break the recipe exists to prevent:

[ERROR] .../JwtUtil.java:[6,22] package javax.xml.bind does not exist
[ERROR] .../JwtUtil.java:[59,16] cannot find symbol
[ERROR]   symbol: variable DatatypeConverter
Root cause: type-attribution bootstrap problem
# jaxb-apis.yml:117-123
- org.openrewrite.java.dependencies.AddDependency:
    groupId: jakarta.xml.bind
    artifactId: jakarta.xml.bind-api
    version: 2.3.x
    onlyIfUsing: javax.xml.bind..*   # never matches
    acceptTransitive: true

onlyIfUsing needs the type attributed in the LST. But javax.xml.bind is JDK-provided only through Java 8 and was removed in 11 — so when parsed by a JDK >= 11 with no JAXB dependency declared, it never resolves.

The recipe that adds the missing JAXB dependency only fires if the JAXB dependency is already there.

This is attribution, not a broken classpath — FindTypes on the same LST, types from the same file:

Type Provided by Found
javax.crypto.Mac JDK (still present) 1
org.json.JSONObject declared dep 2
javax.servlet.http.HttpServletRequest declared dep 10
javax.xml.bind.DatatypeConverter JDK-only, removed in 11 0

Note the preconditions are not at fault — both recipes use preconditions: [org.openrewrite.Singleton] (jaxb-apis.yml:32, :93) and do run. The inner onlyIfUsing silently no-ops.

Likely affects sibling recipes

Same flaw for any onlyIfUsing on a JDK-11-removed package:

  • javax.annotation..* — add-common-annotations-dependencies.yml:50
  • javax.activation..* — jakarta-ee-9.yml:106
  • javax.xml.bind..* — jakarta-ee-9.yml:997
  • javax.xml.soap..* — jakarta-ee-9.yml:1092
  • AddJaxwsDependencies
Suggested fix

onlyIfUsing can't be the sole trigger for JDK-removed modules. Either fall back to matching unresolved imports when the type is unattributed, or add an onlyIfUsingImport-style option to AddDependency.

Worth a regression test on a module that uses javax.xml.bind with no JAXB dependency, parsed on a modern JDK — existing tests likely declare it, which is how this slipped through.

Impact

Upgrading any Java <= 8 project relying on JDK-provided JAXB to 11+ produces a silent compile break, with no warning in the recipe output.

Lenguaje dominante
Java
Estrellas
156
Forks
129
Merge medio
3 d 8 h
PR fusionados (30 d)
14

Preparar el entorno

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Más de openrewrite/rewrite-migrate-java

Todos los issues de openrewrite/rewrite-migrate-java

Issues similares

Más issues de Java

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.