<?xml version="1.0" encoding="UTF-8"?>
<project xmlns="http://maven.apache.org/POM/4.0.0"
         xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
         xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 http://maven.apache.org/xsd/maven-4.0.0.xsd">
    <modelVersion>4.0.0</modelVersion>

    <groupId>xyz.tcheeric</groupId>
    <artifactId>cashu-ledger</artifactId>
    <version>0.7.1</version>
    <packaging>pom</packaging>
    <name>Cashu Ledger</name>
    <description>Standalone CLI for inspecting vouchers on Nostr relays</description>

    <modules>
        <module>cashu-ledger-trace-core</module>
        <module>cashu-ledger-trace-publisher</module>
        <module>cashu-ledger-core</module>
        <module>cashu-ledger-cli</module>
        <module>cashu-ledger-web</module>
        <module>cashu-ledger-integration-tests</module>
        <module>cashu-ledger-e2e-tests</module>
    </modules>

    <properties>
        <java.version>21</java.version>
        <maven.compiler.source>${java.version}</maven.compiler.source>
        <maven.compiler.target>${java.version}</maven.compiler.target>
        <project.build.sourceEncoding>UTF-8</project.build.sourceEncoding>

        <nostr-java.version>2.0.7</nostr-java.version>
        <nostrdb-jni.version>0.3.0</nostrdb-jni.version>
        <imani-bom.version>0.1.77</imani-bom.version>
        <picocli.version>4.7.6</picocli.version>
        <slf4j.version>2.0.17</slf4j.version>
        <logback.version>1.5.34</logback.version>
        <!-- Jackson version managed by Spring Boot BOM -->
        <lombok.version>1.18.40</lombok.version>
        <sqlite.jdbc.version>3.47.1.0</sqlite.jdbc.version>
        <maven.shade.plugin.version>3.6.0</maven.shade.plugin.version>
        <spring.boot.version>3.5.9</spring.boot.version>

        <junit.version>5.12.2</junit.version>
        <assertj.version>3.27.4</assertj.version>
        <mockito.version>5.19.0</mockito.version>
        <jqwik.version>1.9.2</jqwik.version>
        <testcontainers.version>1.21.3</testcontainers.version>
        <selenium.version>4.27.0</selenium.version>
        <cashu-lib-crypto.version>0.30.0</cashu-lib-crypto.version>
        <cashu-wallet-client.version>0.8.0</cashu-wallet-client.version>
        <!-- Spec 048 T059 — wallet-lib's WalletTraceProducer drives the
             E2E test, replacing hand-built TransactionEvent fixtures. -->
        <imani-wallet.version>0.1.18</imani-wallet.version>
        <opentelemetry.version>1.45.0</opentelemetry.version>
        <springdoc.version>2.8.6</springdoc.version>

        <!-- The test-only modules are always part of the reactor (so IDEs import
             them), but their tests run only under the matching profile below. -->
        <skip.integration.tests>true</skip.integration.tests>
        <skip.e2e.tests>true</skip.e2e.tests>
        <maven.surefire.plugin.version>3.5.2</maven.surefire.plugin.version>
        <jib.version>3.4.4</jib.version>
    </properties>

    <distributionManagement>
        <repository>
            <id>reposilite-releases</id>
            <url>https://maven.398ja.xyz/releases</url>
        </repository>
        <snapshotRepository>
            <id>reposilite-snapshots</id>
            <url>https://maven.398ja.xyz/snapshots</url>
        </snapshotRepository>
    </distributionManagement>

    <repositories>
        <repository>
            <id>reposilite-releases</id>
            <name>398ja Maven Repository</name>
            <url>https://maven.398ja.xyz/releases</url>
            <releases>
                <enabled>true</enabled>
            </releases>
            <snapshots>
                <enabled>false</enabled>
            </snapshots>
        </repository>
        <repository>
            <id>reposilite-snapshots</id>
            <name>398ja Maven Snapshots Repository</name>
            <url>https://maven.398ja.xyz/snapshots</url>
            <releases>
                <enabled>false</enabled>
            </releases>
            <snapshots>
                <enabled>true</enabled>
            </snapshots>
        </repository>
    </repositories>

    <dependencyManagement>
        <dependencies>
            <!-- CVE-2025-12543 (CRITICAL): undertow-core 2.3.18.Final arrives test-scoped and
                 transitively via org.testcontainers:testcontainers 1.21.4, which pins a version
                 carrying the advisory. Overriding it here is the only lever this repository has,
                 since nothing declares undertow directly. Declared BEFORE the BOM imports because
                 the first declaration in dependencyManagement wins.

                 Test scope, so it is not shipped and not reachable by a deployed ledger, but it
                 runs in CI and on developer machines, and it is precisely what includeTestScope
                 in the SBOM exists to surface. Remove this once Testcontainers ships a release
                 that pulls a fixed undertow. -->
            <dependency>
                <groupId>io.undertow</groupId>
                <artifactId>undertow-core</artifactId>
                <version>2.3.21.Final</version>
            </dependency>
            <!-- imani-bom first: in dependencyManagement the FIRST declaration wins, so
                 importing it ahead of spring-boot-dependencies is what lets it set the
                 estate's shared versions. It also carries Spring Boot itself (3.5.16 here,
                 against the 3.5.9 this repo pinned by hand), so Boot's own managed versions
                 still arrive — one hop further along.

                 This import replaces a hand-maintained cashu-voucher pin that had drifted to
                 0.14.0, a version that was NEVER PUBLISHED: the reposilite line runs
                 0.13.0 -> 0.14.1 -> 0.14.2. That is why `build` and `scan` are red on master
                 and have been since 0ff3fb5, for a reason no code change here could fix. A
                 version this repository maintains alone is a version that can point at
                 nothing and still look deliberate. -->
            <dependency>
                <groupId>xyz.tcheeric</groupId>
                <artifactId>imani-bom</artifactId>
                <version>${imani-bom.version}</version>
                <type>pom</type>
                <scope>import</scope>
            </dependency>
            <dependency>
                <groupId>org.springframework.boot</groupId>
                <artifactId>spring-boot-dependencies</artifactId>
                <version>${spring.boot.version}</version>
                <type>pom</type>
                <scope>import</scope>
            </dependency>
            <dependency>
                <groupId>org.testcontainers</groupId>
                <artifactId>testcontainers-bom</artifactId>
                <version>${testcontainers.version}</version>
                <type>pom</type>
                <scope>import</scope>
            </dependency>
            <!-- nostr-java 2.x modules (the umbrella BOM is not published to this repo) -->
            <dependency>
                <groupId>xyz.tcheeric</groupId>
                <artifactId>nostr-java-core</artifactId>
                <version>${nostr-java.version}</version>
            </dependency>
            <dependency>
                <groupId>xyz.tcheeric</groupId>
                <artifactId>nostr-java-event</artifactId>
                <version>${nostr-java.version}</version>
            </dependency>
            <dependency>
                <groupId>xyz.tcheeric</groupId>
                <artifactId>nostr-java-identity</artifactId>
                <version>${nostr-java.version}</version>
            </dependency>
            <dependency>
                <groupId>xyz.tcheeric</groupId>
                <artifactId>nostr-java-client</artifactId>
                <version>${nostr-java.version}</version>
            </dependency>
            <dependency>
                <groupId>xyz.tcheeric</groupId>
                <artifactId>nostrdb-jni</artifactId>
                <version>${nostrdb-jni.version}</version>
            </dependency>
            <dependency>
                <groupId>info.picocli</groupId>
                <artifactId>picocli</artifactId>
                <version>${picocli.version}</version>
            </dependency>
            <dependency>
                <groupId>org.slf4j</groupId>
                <artifactId>slf4j-api</artifactId>
                <version>${slf4j.version}</version>
            </dependency>
            <dependency>
                <groupId>org.slf4j</groupId>
                <artifactId>slf4j-simple</artifactId>
                <version>${slf4j.version}</version>
            </dependency>
            <dependency>
                <groupId>ch.qos.logback</groupId>
                <artifactId>logback-classic</artifactId>
                <version>${logback.version}</version>
            </dependency>
            <dependency>
                <groupId>ch.qos.logback</groupId>
                <artifactId>logback-core</artifactId>
                <version>${logback.version}</version>
            </dependency>
            <!-- jackson-databind version managed by Spring Boot BOM -->
            <dependency>
                <groupId>org.junit.jupiter</groupId>
                <artifactId>junit-jupiter</artifactId>
                <version>${junit.version}</version>
                <scope>test</scope>
            </dependency>
            <dependency>
                <groupId>org.assertj</groupId>
                <artifactId>assertj-core</artifactId>
                <version>${assertj.version}</version>
                <scope>test</scope>
            </dependency>
            <dependency>
                <groupId>org.mockito</groupId>
                <artifactId>mockito-core</artifactId>
                <version>${mockito.version}</version>
                <scope>test</scope>
            </dependency>
            <dependency>
                <groupId>org.mockito</groupId>
                <artifactId>mockito-junit-jupiter</artifactId>
                <version>${mockito.version}</version>
                <scope>test</scope>
            </dependency>
            <dependency>
                <groupId>org.projectlombok</groupId>
                <artifactId>lombok</artifactId>
                <version>${lombok.version}</version>
            </dependency>
            <dependency>
                <groupId>net.jqwik</groupId>
                <artifactId>jqwik</artifactId>
                <version>${jqwik.version}</version>
                <scope>test</scope>
            </dependency>
            <dependency>
                <groupId>org.xerial</groupId>
                <artifactId>sqlite-jdbc</artifactId>
                <version>${sqlite.jdbc.version}</version>
            </dependency>
        </dependencies>
    </dependencyManagement>

    <build>
        <pluginManagement>
            <plugins>
                <plugin>
                    <groupId>org.apache.maven.plugins</groupId>
                    <artifactId>maven-compiler-plugin</artifactId>
                    <configuration>
                        <release>${java.version}</release>
                        <parameters>true</parameters>
                        <annotationProcessorPaths>
                            <path>
                                <groupId>org.projectlombok</groupId>
                                <artifactId>lombok</artifactId>
                                <version>${lombok.version}</version>
                            </path>
                        </annotationProcessorPaths>
                    </configuration>
                </plugin>
                <plugin>
                    <groupId>org.apache.maven.plugins</groupId>
                    <artifactId>maven-surefire-plugin</artifactId>
                    <version>${maven.surefire.plugin.version}</version>
                    <configuration>
                        <useModulePath>false</useModulePath>
                    </configuration>
                </plugin>
                <plugin>
                    <groupId>org.apache.maven.plugins</groupId>
                    <artifactId>maven-shade-plugin</artifactId>
                    <version>${maven.shade.plugin.version}</version>
                </plugin>
                <plugin>
                    <groupId>com.google.cloud.tools</groupId>
                    <artifactId>jib-maven-plugin</artifactId>
                    <version>${jib.version}</version>
                </plugin>
            </plugins>
        </pluginManagement>
    </build>

    <profiles>
        <profile>
            <id>container-push</id>
            <properties>
                <!-- Skip default Maven deploy when pushing images via Jib -->
                <maven.deploy.skip>true</maven.deploy.skip>
            </properties>
        </profile>
        <profile>
            <id>integration-tests</id>
            <properties>
                <skip.integration.tests>false</skip.integration.tests>
            </properties>
        </profile>
        <profile>
            <id>e2e-tests</id>
            <properties>
                <skip.e2e.tests>false</skip.e2e.tests>
            </properties>
        </profile>
    </profiles>
</project>
