Repository navigation
Keep every Gradle module's dependencies when building the tree - #190
Conversation
A component that appears in more than one module's dependency-tree file may be resolved there with different transitive dependencies. Replacing the node let the last file win, which could leave a transitive dependency with no parent at all and crash impact-graph construction.
Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
The prior assertions on 'modb' were vacuously true whether or not module scopes aliased the merged node map, since 'modb' never resolves commons-lang3 in its own file. Assert on modb's own commons-text node's children instead, which does regress if a module's DepTreeNode is aliased to the merged map's node. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: Comment |
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Read each module's dependency-tree file into its own module tree first, then merge those, so each step reads on its own. Fold the two shared-dependency tests into one and drop a test that only restated the DepTree constructor. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Since jf 2.106.0, jf audit matches its exclusion patterns against the absolute path of the working directory, so the default *test* pattern skips any project under src/test and the audit returns an empty SARIF. Copy the fixture to a temporary directory first. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
jf audit now also reports a JFrog Services scanner run. SourceCodeScanType has no value for it, so the whole SARIF failed to parse. Skip unsupported runs instead, and make the npm audit test assert on its SCA finding rather than on the number of files with findings, which grows with the scanners the server runs. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
| public void gradleTreeBuilderSharedDependencyTest(String projectPath) throws IOException { | ||
| final String COMMONS_TEXT = "org.apache.commons:commons-text:1.9"; | ||
| final String COMMONS_LANG3 = "org.apache.commons:commons-lang3:3.11"; | ||
| DepTree depTree = buildGradleDependencyTree(projectPath); |
There was a problem hiding this comment.
buildGradleDependencyTree asserts getRootNode().getChildren().size() == 3 (meant for groovy/kotlin). This fixture only passes that because the init script still emits the root project plus moda/modb.
There was a problem hiding this comment.
Here the 3 isn't a coincidence: this fixture has exactly the root project plus moda and modb, and each one writes a dependency-tree file. The helper's assertion holds for this fixture for the same reason it does for groovy/kotlin, so I'd leave it.
| assertTrue(missing.getScopes().contains("testImplementation")); | ||
| } | ||
|
|
||
| /** |
There was a problem hiding this comment.
One-row data provider plus javadoc that only returns 'sharedDependency' is noise. A plain @Test fits this fixture.
There was a problem hiding this comment.
The data provider is required. @BeforeMethod setUp(Object[] args) copies the fixture named in args[0], so a plain @Test would reach setUp with no arguments. That's why every test in this class uses one.
Treat a missing results list like an empty one when skipping an unsupported scanner, and cover the skip with a SARIF fixture holding an SCA run plus unsupported runs with no, some and missing results. The audit tests look up their SCA finding by file name instead of counting files, and the shared-dependency test asserts each node and module exists before reading it. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Background
Scanning a multi-module Gradle project in the IntelliJ plugin fails with a
NullPointerExceptionwhen two modules resolve the same dependency differently.Description
GradleTreeBuildermerges the per-module dependency trees instead of replacing them, and exposes each module's own tree viaDepTree.modules(), used by jfrog/jfrog-idea-plugin#532.SarifParsernow skips scanners it doesn't support instead of failing.Tests
New
GradleTreeBuilderTestcase. TheJfrogCliDriverTestaudits scan a temp copy of their fixture, sincejf≥ 2.106.0 skips projects under atestpath (XRAY-158874).