Skip to content

7.1.0 unresolvable: com.sumup.pos.money.bundle:money:3.4.1 missing from maven.sumup.com — sample app also fails from fresh clone #282

Description

@saied-nawaz

Upgrading com.sumup:merchant-sdk 7.0.0 → 7.1.0 per the official docs (single repo https://maven.sumup.com/releases) fails:

Could not find com.sumup.pos.money.bundle:money:3.4.1.
Searched in the following locations:
  - https://dl.google.com/dl/android/maven2/com/sumup/pos/money/bundle/money/3.4.1/money-3.4.1.pom
  - https://repo.maven.apache.org/maven2/com/sumup/pos/money/bundle/money/3.4.1/money-3.4.1.pom
  - https://maven.sumup.com/releases/com/sumup/pos/money/bundle/money/3.4.1/money-3.4.1.pom

gradlew dependencyInsight chain:

com.sumup.pos.money.bundle:money:3.4.1 FAILED
\--- com.sumup:reader-offline:7.1.0
     +--- com.sumup:merchant-sdk:7.1.0
     \--- com.sumup:reader:7.1.0

Notes from investigation (verified 2026-07-11):

  • merchant-sdk-7.1.0.aar and reader-offline-7.1.0.pom return HTTP 200 on maven.sumup.com/releases, but no version of the com.sumup.pos.money.bundle group exists there at all (maven-metadata.xml 404), nor on Maven Central or Google Maven.
  • Reproduces with this repo's own sample app from a fresh clone (after adding the maven.sumup.com/releases repo — which the sample's settings.gradle.kts is also missing; the SDK isn't published to google()/mavenCentral() that it lists).
  • Presumably the artifact exists on an internal SumUp mirror but was never published publicly (or was removed after the June release — integrators who resolved 7.1.0 in June would still have it in their Gradle caches, masking the breakage).

Could you publish com.sumup.pos.money.bundle:money:3.4.1 to maven.sumup.com/releases (and add the repo to the sample's settings.gradle.kts)? This currently blocks any fresh adoption of 7.1.0; we've had to stay on 7.0.0.

Activity

  1. crossweiler91-gif commented on Jul 13, 2026

    @crossweiler91-gif

    :)

  2. HeyPouya commented on Jul 13, 2026

    @HeyPouya
    Contributor

    Hey @saied-nawaz,

    Thanks for opening this issue and for providing the detailed dependencyInsight output.

    We reviewed the complete transitive dependency graph of the currently published merchant-sdk:7.1.0, reader:7.1.0, and reader-offline:7.1.0 artifacts, including all of their com.sumup POMs. We confirmed that none of the currently published modules declare a direct or transitive dependency on com.sumup.pos.money.bundle:money:3.4.1.

    Since your dependencyInsight output shows a reader-offline:7.1.0 → money:3.4.1 dependency that is not present in the current metadata, this suggests that stale dependency metadata is cached somewhere in your environment. Please note that a fresh Git clone does not clear Gradle’s global cache. The cache under ~/.gradle/caches, as well as any Nexus or Artifactory proxy cache, persists across clones. This could also explain why the issue was reproducible with a fresh clone of the sample app.

    Could you please clear the cached metadata and try again?

    ./gradlew --stop
    rm -rf ~/.gradle/caches/modules-2/metadata-*
    ./gradlew clean build --refresh-dependencies
    

    If you use a Maven repository proxy such as Nexus or Artifactory, please also invalidate its cached metadata for the affected com.sumup modules. Otherwise, the proxy may continue serving the stale metadata to clean builds.

    If the issue persists, please share the fresh output from the following command so we can identify which configuration is still requesting the dependency:

    ./gradlew :app:dependencyInsight \
      --configuration releaseRuntimeClasspath \
      --dependency com.sumup.pos.money.bundle:money \
      --refresh-dependencies
    
  3. saied-nawaz commented on Jul 15, 2026

    @saied-nawaz
    Author

    Thanks @HeyPouya — confirmed. After clearing the cached metadata (rm -rf ~/.gradle/caches/modules-2/metadata-*) and rebuilding with --refresh-dependencies, merchant-sdk:7.1.0 resolves cleanly and dependencyInsight no longer shows any reference to com.sumup.pos.money.bundle:money. The stale metadata in the global Gradle cache explains why it reproduced across fresh clones (the cache survives a fresh checkout). Full build and test suite pass on 7.1.0.

    Sorry for the noise, and thanks for the quick investigation — closing.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions