Provide streamlined dependency management to avoid conflicting dependencies
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 5/5
- Estimated time
- Over a week
- Newbie friendliness
- 35/100
- Issue type
- Feature
- Clarity
- Mostly clear
- Activity status
- Stale
- Tech stack
- java
- Domain
- build-system
Research direction
Start with the linked yt-api-dependency-conflicts reproduction project and run its Maven Enforcer dependencyConvergence rule to confirm the reported paths and versions. Then inspect how google-api-services-youtube and its direct dependencies are published and managed. Done means the requested dependency-management approach is defined and the reproduced conflicts are resolved without brittle consumer exclusions.
Written by the indexing model from the issue text.
Description
Is your feature request related to a problem? Please describe
Hi there,
I'm using the google-api-services-youtube library in one of my projects and noticed (by means of the maven-enforcer-plugin- specifically the dependency convergence rule) that there are a number of conflicting dependencies.
Specifically google-api-services-youtube as of version v3-rev20250224-2.0.0 effectively brings 3 ⚠ different versions of com.google.http-client:google-http-client:
com.google.http-client:google-http-client:jar:1.43.3com.google.http-client:google-http-client:jar:1.45.0com.google.http-client:google-http-client:jar:1.45.2
This is the full output of the enforcer plugin:
[ERROR] Rule 0: org.apache.maven.enforcer.rules.dependency.DependencyConvergence failed with message:
[ERROR] Failed while enforcing releasability.
[ERROR]
[ERROR] Dependency convergence error for com.google.http-client:google-http-client-gson:jar:1.43.3 paths to dependency are:
[ERROR] +-com.github.jjank.example:yt-dependency-conflicts:jar:1.0-SNAPSHOT
[ERROR] +-com.google.apis:google-api-services-youtube:jar:v3-rev20250224-2.0.0:compile
[ERROR] +-com.google.api-client:google-api-client:jar:2.7.2:compile
[ERROR] +-com.google.oauth-client:google-oauth-client:jar:1.36.0:compile
[ERROR] +-com.google.http-client:google-http-client-gson:jar:1.43.3:compile
[ERROR] and
[ERROR] +-com.github.jjank.example:yt-dependency-conflicts:jar:1.0-SNAPSHOT
[ERROR] +-com.google.apis:google-api-services-youtube:jar:v3-rev20250224-2.0.0:compile
[ERROR] +-com.google.api-client:google-api-client:jar:2.7.2:compile
[ERROR] +-com.google.auth:google-auth-library-oauth2-http:jar:1.30.0:compile
[ERROR] +-com.google.http-client:google-http-client-gson:jar:1.45.0:compile
[ERROR] and
[ERROR] +-com.github.jjank.example:yt-dependency-conflicts:jar:1.0-SNAPSHOT
[ERROR] +-com.google.apis:google-api-services-youtube:jar:v3-rev20250224-2.0.0:compile
[ERROR] +-com.google.api-client:google-api-client:jar:2.7.2:compile
[ERROR] +-com.google.http-client:google-http-client-gson:jar:1.45.2:compile
[ERROR]
[ERROR]
[ERROR] Dependency convergence error for commons-codec:commons-codec:jar:1.17.1 paths to dependency are:
[ERROR] +-com.github.jjank.example:yt-dependency-conflicts:jar:1.0-SNAPSHOT
[ERROR] +-com.google.apis:google-api-services-youtube:jar:v3-rev20250224-2.0.0:compile
[ERROR] +-com.google.api-client:google-api-client:jar:2.7.2:compile
[ERROR] +-commons-codec:commons-codec:jar:1.17.1:compile
[ERROR] and
[ERROR] +-com.github.jjank.example:yt-dependency-conflicts:jar:1.0-SNAPSHOT
[ERROR] +-com.google.apis:google-api-services-youtube:jar:v3-rev20250224-2.0.0:compile
[ERROR] +-com.google.api-client:google-api-client:jar:2.7.2:compile
[ERROR] +-org.apache.httpcomponents:httpclient:jar:4.5.14:compile
[ERROR] +-commons-codec:commons-codec:jar:1.11:compile
[ERROR]
[ERROR]
[ERROR] Dependency convergence error for com.google.guava:guava:jar:31.1-android paths to dependency are:
[ERROR] +-com.github.jjank.example:yt-dependency-conflicts:jar:1.0-SNAPSHOT
[ERROR] +-com.google.apis:google-api-services-youtube:jar:v3-rev20250224-2.0.0:compile
[ERROR] +-com.google.api-client:google-api-client:jar:2.7.2:compile
[ERROR] +-com.google.oauth-client:google-oauth-client:jar:1.36.0:compile
[ERROR] +-com.google.guava:guava:jar:31.1-android:compile
[ERROR] and
[ERROR] +-com.github.jjank.example:yt-dependency-conflicts:jar:1.0-SNAPSHOT
[ERROR] +-com.google.apis:google-api-services-youtube:jar:v3-rev20250224-2.0.0:compile
[ERROR] +-com.google.api-client:google-api-client:jar:2.7.2:compile
[ERROR] +-com.google.auth:google-auth-library-oauth2-http:jar:1.30.0:compile
[ERROR] +-com.google.guava:guava:jar:33.3.1-android:compile
[ERROR] and
[ERROR] +-com.github.jjank.example:yt-dependency-conflicts:jar:1.0-SNAPSHOT
[ERROR] +-com.google.apis:google-api-services-youtube:jar:v3-rev20250224-2.0.0:compile
[ERROR] +-com.google.api-client:google-api-client:jar:2.7.2:compile
[ERROR] +-com.google.guava:guava:jar:33.1.0-jre:compile
[ERROR]
[ERROR]
[ERROR] Dependency convergence error for com.google.http-client:google-http-client:jar:1.43.3 paths to dependency are:
[ERROR] +-com.github.jjank.example:yt-dependency-conflicts:jar:1.0-SNAPSHOT
[ERROR] +-com.google.apis:google-api-services-youtube:jar:v3-rev20250224-2.0.0:compile
[ERROR] +-com.google.api-client:google-api-client:jar:2.7.2:compile
[ERROR] +-com.google.oauth-client:google-oauth-client:jar:1.36.0:compile
[ERROR] +-com.google.http-client:google-http-client:jar:1.43.3:compile
[ERROR] and
[ERROR] +-com.github.jjank.example:yt-dependency-conflicts:jar:1.0-SNAPSHOT
[ERROR] +-com.google.apis:google-api-services-youtube:jar:v3-rev20250224-2.0.0:compile
[ERROR] +-com.google.api-client:google-api-client:jar:2.7.2:compile
[ERROR] +-com.google.auth:google-auth-library-oauth2-http:jar:1.30.0:compile
[ERROR] +-com.google.http-client:google-http-client:jar:1.45.0:compile
[ERROR] and
[ERROR] +-com.github.jjank.example:yt-dependency-conflicts:jar:1.0-SNAPSHOT
[ERROR] +-com.google.apis:google-api-services-youtube:jar:v3-rev20250224-2.0.0:compile
[ERROR] +-com.google.api-client:google-api-client:jar:2.7.2:compile
[ERROR] +-com.google.http-client:google-http-client:jar:1.45.2:compile
Aside from the rule violation - dependency conflicts should be avoided wherever possible.
Describe the solution you'd like
Streamlined dependency-management. My personal perference would be a bom maven dependency that manages all direct and transitive dependencies of google-api-java-client-services
Describe alternatives you've considered
Using various (and complicated) exclusions in maven. While this is doable, it seems brittle and hard to maintain. As a user of google-api-services-youtube it's hard to know which versions work well together.
Additional context
I've created a Github-project that reproduces the problem: https://github.com/jjank/yt-api-dependency-conflicts
- Dominant language
- Java
- Stars
- 725
- Forks
- 395
- Avg merge
- 36m
- Merged PRs (30d)
- 212
Getting set up
- No Dockerfile or Docker Compose file
- No pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from googleapis/google-api-java-client-services
-
priority: p3 type: docs
Difficulty 1/5 Under an hour Newbie friendliness 88/100
googleapis/google-api-java-client-services#32558 ·
Maintainers usually reply within 1 day
-
Difficulty 3/5 1-2 days Newbie friendliness 65/100
googleapis/google-api-java-client-services#32796 ·
Maintainers usually reply within 1 day
-
priority: p3 type: bug
Difficulty 2/5 1-3 hours Newbie friendliness 50/100
googleapis/google-api-java-client-services#29581 · 2 comments ·
Maintainers usually reply within 1 day
-
priority: p3 type: feature request
Difficulty 4/5 3-5 days Newbie friendliness 38/100
googleapis/google-api-java-client-services#29317 · 1 comment ·
Maintainers usually reply within 1 day
-
priority: p3 type: bug
Difficulty 3/5 1-2 days Newbie friendliness 35/100
googleapis/google-api-java-client-services#24984 ·
Maintainers usually reply within 1 day
All issues in googleapis/google-api-java-client-services
Similar issues
-
Update license yearOpen0 - Backlog 1 - Ready documentation good first issue help wanted
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
-
cbor
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
FasterXML/jackson-dataformats-binary#844 ·
Maintainers usually reply within 1 day
-
Issue: Bug
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
OpenAPITools/openapi-generator#25107 ·
Maintainers usually reply within 1 day
-
improvement
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
apache/iceberg#18351 · 1 comment ·
Maintainers usually reply within 1 day
-
bug good first issue
Difficulty 2/5 1-3 hours Newbie friendliness 90/100
repowise-dev/repowise#2945 · 1 comment ·
Maintainers usually reply within 1 day