Skip to content

Commit 4479a4f

Browse files
authored
Merge pull request #82 from openjavaformat/dependency-graph-runtime-only
Submit only runtimeClasspath to the dependency graph
2 parents 462a18c + 454837b commit 4479a4f

1 file changed

Lines changed: 8 additions & 5 deletions

File tree

‎.github/workflows/dependency-submission.yml‎

Lines changed: 8 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -21,8 +21,11 @@ jobs:
2121

2222
- name: Submit Dependency Snapshot
2323
uses: gradle/actions/dependency-submission@9c971963bec38e04b3d30dcc455b5382be2fdbfb # v6.3.0
24-
env:
25-
# Only runtime-classpath dependencies of the published modules count as 'runtime';
26-
# annotation processors, Gradle plugin classpaths and test-only dependencies are
27-
# reported as 'development' so Dependabot auto-triage rules can dismiss their alerts.
28-
DEPENDENCY_GRAPH_RUNTIME_INCLUDE_CONFIGURATIONS: 'runtimeClasspath'
24+
with:
25+
# Only what ships goes into the graph. The published jars, the native image and the IntelliJ and
26+
# Eclipse plugins are all built from runtimeClasspath, and the formatter configuration the IntelliJ
27+
# plugin also bundles is open-java-format's runtimeClasspath again. The name is matched whole, so
28+
# testRuntimeClasspath stays out. Without the filter the graph holds every configuration the build
29+
# resolves, buildSrc with JReleaser and the root buildscript's plugins included, and Dependabot
30+
# raises alerts for all of it: marking a dependency 'development' does not stop an alert.
31+
dependency-graph-include-configurations: 'runtimeClasspath'

0 commit comments

Comments
 (0)