Repositories from dependencies' pom.xml are not used
Artifact in non-standard maven repos defined in pom.xml of a dependencies cannot be fetched.
Steps to reproduce
1. Use the attached deps.edn and run clj.
lambdacd defines a custom maven repo in the project.clj and translated into the following pom.xml. Note "gocd" is added.
Is it possible to observe custom maven repositories while traversing transitive dependencies?
We have grown increasingly uneasy about using transitive dependency repository declarations due to the security concerns for shadowing. The recommended path here is to declare all repositories needed in the parent. At some future point, we may consider some way to allow this with either reporting or guardrails of some kind.
Same issue exists with transitive deps.edn projects that declare their own repos.
Another case to reproduce this
Thanks for the report! Definitely fixable.