tools-deps 2025-08-19

Trying to use the osx keychain as the Java trust store for dep resolution. This works:

; export JAVA_TOOL_OPTIONS="-Djavax.net.ssl.trustStoreType=KeychainStore"

; clojure -Spath
Picked up JAVA_TOOL_OPTIONS: -Djavax.net.ssl.trustStoreType=KeychainStore
This doesn't:
; clojure -J-Djavax.net.ssl.trustStoreType=KeychainStore -Spath

...
Caused by: sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target
What am I doing wrong with the latter? Edit: solution is to use the CLJ_JVM_OPTS env var (details in thread)

✅ 1

(trying to access internal repo with its own company-issued cert)

JAVA_TOOL_OPTIONS causes the option to be picked up by any jvm started, passing to the clojure launcher script relies on the launcher script to pass it through

clojure --help does say the following:

...
-Jopt          Pass opt through in java_opts, ex: -J-Xmx512m
...

the java process that does deps resolution is separate from the actual "clojure" process that gets launched with access to the deps

-J is for passing opts to the "launched" process with the constructed class path, not for pass opts to the classpath building process

is there a way to pass opts to the deps resolution process?

oh, nice, let me try that

ah, that did work, lovely, thank you!

Alex Miller (Clojure team) 2025-08-19T18:04:57.142009Z

yes, that is the way. (reference: https://clojure.org/reference/clojure_cli#env_vars)