Skip to content

Commit 454837b

Browse files
committed
Submit only runtimeClasspath to the dependency graph
The submission put every configuration the build resolves into the graph: buildSrc with JReleaser, the root buildscript's plugins, annotation processors and test dependencies, 452 packages in all. DEPENDENCY_GRAPH_RUNTIME_INCLUDE_CONFIGURATIONS only labelled everything but runtimeClasspath as 'development'. Dependabot alerts on development dependencies all the same, and the auto-triage rule the comment counted on to dismiss them was never created, so all 24 open alerts, the critical tika-core one among them, are for build tooling. Filter the graph instead. Everything that ships is built from runtimeClasspath, so the graph keeps the same 24 runtime packages and drops the rest. With no scope parameter the packages carry no scope, which nothing here reads.
1 parent a427d59 commit 454837b

1 file changed

Lines changed: 8 additions & 5 deletions

File tree

‎.github/workflows/dependency-submission.yml‎

Lines changed: 8 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -21,8 +21,11 @@ jobs:
2121

2222
- name: Submit Dependency Snapshot
2323
uses: gradle/actions/dependency-submission@9c971963bec38e04b3d30dcc455b5382be2fdbfb # v6.3.0
24-
env:
25-
# Only runtime-classpath dependencies of the published modules count as 'runtime';
26-
# annotation processors, Gradle plugin classpaths and test-only dependencies are
27-
# reported as 'development' so Dependabot auto-triage rules can dismiss their alerts.
28-
DEPENDENCY_GRAPH_RUNTIME_INCLUDE_CONFIGURATIONS: 'runtimeClasspath'
24+
with:
25+
# Only what ships goes into the graph. The published jars, the native image and the IntelliJ and
26+
# Eclipse plugins are all built from runtimeClasspath, and the formatter configuration the IntelliJ
27+
# plugin also bundles is open-java-format's runtimeClasspath again. The name is matched whole, so
28+
# testRuntimeClasspath stays out. Without the filter the graph holds every configuration the build
29+
# resolves, buildSrc with JReleaser and the root buildscript's plugins included, and Dependabot
30+
# raises alerts for all of it: marking a dependency 'development' does not stop an alert.
31+
dependency-graph-include-configurations: 'runtimeClasspath'

0 commit comments

Comments
 (0)