)]}'
{
  "commit": "cc7ea6020ffbfd3832755012ccb6ad6ce6411a29",
  "tree": "c4bd4c3f222b67388fd9fe58cdb4744b55f00471",
  "parents": [
    "8ecfd36e4db64257ba2de5c0fb9000dbb4f12c0d"
  ],
  "author": {
    "name": "Matt Brown",
    "email": "mattbrown@spotify.com",
    "time": "Wed Nov 19 00:37:39 2025 -0500"
  },
  "committer": {
    "name": "GitHub",
    "email": "noreply@github.com",
    "time": "Wed Nov 19 05:37:39 2025 +0000"
  },
  "message": "coursier: ignore dependencies with classifier\u003d\"sources\" and no \"file\" (#1479)\n\nWhen coursier is asked to resolve an artifact that has a transitive\ndependency on `org.apache.logging.log4j:log4j:3.0.0-beta3` (note the\nlack of packaging in the [real-world example here][0]) and\n`fetch_sources\u003dTrue` is set, coursier will return this in the list of\ndependencies:\n\n```\n{\n  \"coord\": \"org.apache.logging.log4j:log4j:jar:sources:3.0.0-beta3\",\n  \"file\": null,\n  \"directDependencies\": [],\n  \"dependencies\": []\n}\n```\n\nIn `rules_jvm_external` 6.8 this will cause errors when building the\nexternal repo generated by RJE since RJE will end up handling this\ndependency by a) generating a `http_file` with an empty list of `urls`\nand b) emitting a `copy_file` rule in the external repo\u0027s BUILD file\nthat refers to the non-existing `http_file` repo from A. See\n[this comment][1] for a breakdown of why this happens.\n\nPR #1207 added `pom` to the list of `SUPPORTED_PACKAGING_TYPES` so that\nthe dependencies of the pom could be aggregated (Maven interprets a\ndependency on an artifact with packaging\u003dpom as depending on the\n`\u003cdependencies\u003e` in that pom), but that PR didn\u0027t test what happens with\n`fetch_sources\u003dTrue` nor did it consider the case like with\n`org.apache.logging.log4j:log4j:3.0.0-beta3` where the coordinates\noutput by coursier don\u0027t mention the packaging at all.\n\nfixes #1477\n\n[0]: https://central.sonatype.com/artifact/org.opencadc/cadc-util/1.12.10\n[1]: https://github.com/bazel-contrib/rules_jvm_external/issues/1477#issuecomment-3530832168\n",
  "tree_diff": [
    {
      "type": "modify",
      "old_id": "3bf952c536b6123257e8cd7d5df508e308f183be",
      "old_mode": 33188,
      "old_path": "MODULE.bazel",
      "new_id": "047da57800499cbff527660fb42827fd06501dde",
      "new_mode": 33188,
      "new_path": "MODULE.bazel"
    },
    {
      "type": "modify",
      "old_id": "ff0b5ecdf0470675b4a0b72a23cf5d52e3fb6683",
      "old_mode": 33188,
      "old_path": "private/rules/coursier.bzl",
      "new_id": "3d74e635d0cb2d1b50ba42725399a8b4fa5218b8",
      "new_mode": 33188,
      "new_path": "private/rules/coursier.bzl"
    },
    {
      "type": "add",
      "old_id": "0000000000000000000000000000000000000000",
      "old_mode": 0,
      "old_path": "/dev/null",
      "new_id": "996160c1a227fee90994520d7888fba9e077450f",
      "new_mode": 33188,
      "new_path": "tests/custom_maven_install/transitive_dependency_with_type_of_pom.json"
    }
  ]
}
