Skip to content

Deprecate, migrate and remove BeanShell across the Maven estate #13207

Description

@slachiewicz

Tracking issue for retiring BeanShell across the Maven estate: deprecate it now, migrate what we own, remove it in the next majors.

Why

  • The bsh artifact we ship is dead on Central: org.apache-extras.beanshell:bsh last published 2.0b6 on 2016-02-05 (the CVE-2016-2510 fix). The GitHub project released 2.1.1 in 2022 but never to Central; nothing since.
  • Every use we have is a test-script or expression language for which Groovy is already the second engine in the same component, and the newer ITs are written in Groovy.
  • maven-plugin-tools already dropped BeanShell mojos for 4.0.0 (MPLUGIN-525).
  • Both interpreters redirect the JVM-global System.out/System.err and serialize all script runs behind a static lock (Global System.out/System.err redirection and static lock serialize all script runs JVM-wide maven-script-interpreter#205); fixing that for one engine is cheaper than for two.

Where BeanShell is used

Component Use Notes
maven-script-interpreter BeanShellScriptInterpreter, registered as bsh next to groovy Also the fallback for any unrecognised script extension (ScriptRunner)
maven-invoker-plugin setup/prebuild/postbuild/selector scripts Through maven-script-interpreter
maven-archetype-plugin archetype:integration-test verify scripts Through maven-script-interpreter
maven-enforcer evaluateBeanshell rule, direct bsh dependency The only place where BeanShell is user-facing syntax; 212 pom.xml on GitHub use the rule
maven-plugin-tools 3.x maven-script-beanshell, maven-plugin-tools-beanshell Gone on master (MPLUGIN-525); ends with the 3.x line
Our own ITs 549 .bsh scripts in the 3.x plugin lines (444 verify.bsh, 70 setup.bsh) against 1 009 .groovy Largest holders: assembly 107, invoker 79, install 47, dependency 44, shade 36, javadoc 28, war 24, deploy 22, site 21, clean 16

Outside the estate, GitHub code search finds 1 628 src/it/**/verify.bsh against 3 240 verify.groovy.

Status (2026-09-30)

50 of the 54 PRs linked here are merged. On the default branches of every apache/maven-* repository the only .bsh files left are engine coverage: maven-invoker-plugin's 17 script-* fixtures, maven-script-interpreter's 7 test resources, and maven-archetype's verify-script-beanshell-rejected fixture, which checks that BeanShell is refused.

maven-archetype has already removed BeanShell on master: verify scripts run through Groovy directly and maven-script-interpreter is gone (f4e8441fb).

Still open:

PR State
apache/maven-enforcer#1035 evaluateGroovy rule approved, green
apache/maven-script-interpreter#216 deprecate BeanShell green, needs review
apache/maven-script-interpreter#217 unknown extensions run as Groovy (stacked on #216) green, needs review
apache/maven-script-interpreter#218 per-thread output instead of swapping System.out (stacked on #217, fixes apache/maven-script-interpreter#205) green, needs review

The three maven-script-interpreter PRs missed 1.9 (2026-09-19), so the deprecation ships in 1.10.

Plan

PRs and per-repo issues link back here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

breakingPull requests that break existing featuresmaintenance

Type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions