Skip to content

fix: stop exporting Spring Framework from the Spring module - #408

Merged
heruan merged 10 commits into
mainfrom
feat/spring-provided-scope
Sep 29, 2026
Merged

heruan merged 10 commits into
mainfrom
feat/spring-provided-scope

Conversation

@totally-not-ai

@totally-not-ai totally-not-ai Bot commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Summary

The plain Spring module no longer pulls in Spring Framework (spring-context) for the application. The application now declares Spring itself, so the application decides the Spring version, not the kit.

What changed

Behavior change: spring-context is now an optional dependency in observability-kit-spring, so it no longer comes in through the kit. This affects plain Spring apps (without Spring Boot) that use observability-kit-spring and got spring-context only through the kit. These apps must now declare spring-context themselves (plus spring-web for the HTTP observation hooks), best with org.springframework:spring-framework-bom imported.

🤖 Generated with Claude Code

spring-context in observability-kit-spring, and spring-boot-autoconfigure
and spring-boot-starter-micrometer-metrics in observability-kit-starter,
are now provided scope, so the kit no longer exports Spring artifacts
transitively. The application brings Spring and Spring Boot and defines
their versions.

The auto-configuration now references Boot's Micrometer metrics
auto-configurations by name, as they are no longer guaranteed to be on
the classpath.

Applications using the starter must declare
spring-boot-starter-micrometer-metrics, or spring-boot-starter-actuator
which includes it.
Comment thread observability-kit-starter/pom.xml Outdated
A Spring Boot starter is expected to bring the starters it builds on, so
observability-kit-starter keeps spring-boot-starter-micrometer-metrics and
spring-boot-autoconfigure at compile scope and stays a single-dependency
setup. Only observability-kit-spring keeps spring-context provided.
@totally-not-ai totally-not-ai Bot changed the title feat!: stop exporting Spring dependencies at compile scope fix: stop exporting spring-context from the Spring module Sep 25, 2026
@Artur-
Artur- marked this pull request as ready for review September 25, 2026 11:14
@Artur-
Artur- requested a review from heruan September 25, 2026 11:14

@heruan heruan left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Starter changes look good now, agree with Artur. A few things on the Spring module:

  1. spring-context still comes in transitively. vaadin-spring is a compile dependency here and brings spring-webmvc, which depends on spring-context, spring-web, spring-beans and spring-core (see mvn dependency:tree -pl :observability-kit-spring). So the kit still picks the Spring version. To fix it, mark vaadin-spring as optional too. Apps using this module are Vaadin Spring apps, so they already have it.
  2. Please use <optional>true</optional> instead of provided for spring-context. That matches spring-web in the same POM and is the usual Spring convention. provided is for things the container gives at runtime, like the servlet API.
  3. With the current POM, "you must now add spring-context yourself" in the description is not true. Please update it after the fix. The README could also say the app needs vaadin-spring, and suggest spring-framework-bom to align Spring versions.

The application already has vaadin-spring and Spring Framework, so the
module must not bring them, or it still decides the Spring version
through vaadin-spring's own dependencies. The starter declares
spring-web optional for the resync detection filter, and the plain
Spring test application declares vaadin-spring itself.
@totally-not-ai totally-not-ai Bot changed the title fix: stop exporting spring-context from the Spring module fix: stop exporting Spring and vaadin-spring from the Spring module Sep 25, 2026
The module's main code does not use vaadin-spring; only a test does.
@totally-not-ai

Copy link
Copy Markdown
Contributor Author

@heruan Thanks, all three are addressed:

  1. vaadin-spring is no longer exported by observability-kit-spring. The main code does not use it, only a test does, so it is now test scope. dependency:tree -pl :observability-kit-spring shows no non-optional Spring artifacts any more. The starter had been getting spring-web (for OncePerRequestFilter behind the resync detection filter) through vaadin-spring, so it now declares spring-web as optional; the application's web starter provides it. The plain-Spring integration test application relied on vaadin-spring coming transitively and now declares it.
  2. spring-context is now <optional>true</optional> instead of provided, matching spring-web.
  3. The description is rewritten: it no longer says the application must add spring-context, and it explains that the application brings vaadin-spring and Spring. The README's plain-Spring section now says the application brings vaadin-spring and Spring Framework, and suggests importing spring-framework-bom to keep their versions aligned.

Unit tests pass (503) and the integration test applications build.

@Artur-

Artur- commented Sep 25, 2026

Copy link
Copy Markdown
Member

The dependency on vaadin-spring should remain as that one is fixed in a flow pr, right?

@totally-not-ai totally-not-ai Bot changed the title fix: stop exporting Spring and vaadin-spring from the Spring module fix: stop exporting Spring Framework from the Spring module Sep 25, 2026
@totally-not-ai

Copy link
Copy Markdown
Contributor Author

@Artur- Right. I restored vaadin-spring as a normal compile dependency of observability-kit-spring and updated the README to match: the module brings vaadin-spring, while Spring Framework comes from the application. spring-context stays optional, and the starter keeps its optional spring-web, which it needs to compile the resync detection filter once vaadin-spring no longer exports it.

One caveat: the kit currently builds against Flow 25.3. Until it moves to a Flow version that includes vaadin/flow#25927, vaadin-spring still brings spring-webmvc and the core Spring artifacts with it, so Spring is only fully gone from the kit's dependency tree after that version bump.

@heruan
heruan enabled auto-merge (squash) September 28, 2026 11:39
@heruan
heruan merged commit 1c69c4e into main Sep 29, 2026
3 checks passed
@heruan
heruan deleted the feat/spring-provided-scope branch September 29, 2026 11:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants