Skip to content

Add the JAXB API dependency for javax.xml.bind imports the parser could not resolve - #1257

Merged
jkschneider merged 1 commit into
java25/if-else-if-switch-commentsfrom
java25/jaxb-api-for-imports
Oct 3, 2026
Merged

jkschneider merged 1 commit into
java25/if-else-if-switch-commentsfrom
java25/jaxb-api-for-imports

Conversation

@jkschneider

Copy link
Copy Markdown
Member

AddJaxbAPIDependencies detects JAXB use through resolved types. A project compiled on JDK 8 got JAXB from the JDK, so its LST has unresolved javax.xml.bind types, no dependency was added, and the project no longer compiles on Java 25. New scanning recipe AddJaxbApiForImports, added to the composite: collect compilation units importing javax.xml.bind.*, map each to the nearest Maven module, and add jakarta.xml.bind:jakarta.xml.bind-api:2.3.x (test scope when only tests import it) unless the module already has it.

Found by a team of coding agents reviewing a Moderne run of org.openrewrite.java.migrate.UpgradeToJava25 over eight open-source repositories (run 20261003103223-WtyA8). The issue is jaxb-unattributed-usage-missed in the run's io.moderne.RecipeIssues data table, and the fix was discussed and reviewed on the run's message board. A row from the table, as a generalized example:

JAXB usage without resolved types is left without the dependency needed after Java 8. (CSPF-Founder/JavaVulnerableLab, pom.xml)

Before:

import javax.xml.bind.DatatypeConverter; class A { String encode(byte[] b) { return DatatypeConverter.printBase64Binary(b); } } // Java 8; no JAXB dependency

What the recipe produced:

Same source; Java 25; no JAXB dependency

Expected:

Same source; Java 25; dependency jakarta.xml.bind:jakarta.xml.bind-api:2.3.3

Stacked on #1256 (8 of 9); merge that one first.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

1 participant