Situation:
Define the same alias in multiple deps.edn locations—user, project, extra, i.e., via -Sdeps—and then use it in a Clojure CLI invocation.
Behavior:
The definitions of that alias are merged across the four sources.
Why that might be surprising:
Per the CLI deps sources reference "The merge [of the EDN files] is essentially merge-with merge, except for :paths where only the last deps source :paths is used."
In addition, per the CLI deps aliases reference When multiple aliases are provided, the attributes of each alias are merged together under a specific set of rules.
Based on both of these, if you have a single alias defined in multiple sources, you might expect a simple "last definition wins" behavior, since the second part doesn't apply, and the first part indicates :aliases will be simply merge'd across the sources.
However, in tools.deps we see that create-basis takes the EDN maps from all four tiers, gets the :aliases entry from each and does merge-with merge on those.
That's why the alias ends up with a merge of its definitions. I don't think this is documented?
Why does it happen?
I'm not sure, but I suspect this is part of the "aliases are 'just' data" aspect, where a project-level (and extra level) alias can override parts of an "earlier" definition, from other source deps.edn files.
Does it matter?
I ran into this experimenting with the new Clojure CLI REPL project. I added :repl, :serve, and :attach aliases to my user deps.edn and got a warning (about unnamed access) when starting the REPL. I added :jvm-opts to :repl but still got the warning. Later, I added :jvm-opts to :attach so at least connecting a subsequent client didn't get the warning.
Then I noticed that using :repl no longer produced the warning. I looked at the CLI REPL code and it spawns the client at the process level, using clojure and specifying -Sdeps with an alias of :attach to provide the dependencies and :main-opts.
That means that any tooling that runs Clojure processes, expecting to define and then use an alias via -Sdeps can be affected by whatever happens to be in a user's project or user deps.edn file: if the user has the same named alias defined, the tooling gets a merged alias, not just the one it specifies.