Commit 454837b
committed
Submit only runtimeClasspath to the dependency graph
The submission put every configuration the build resolves into the graph: buildSrc with JReleaser,
the root buildscript's plugins, annotation processors and test dependencies, 452 packages in all.
DEPENDENCY_GRAPH_RUNTIME_INCLUDE_CONFIGURATIONS only labelled everything but runtimeClasspath as
'development'. Dependabot alerts on development dependencies all the same, and the auto-triage rule
the comment counted on to dismiss them was never created, so all 24 open alerts, the critical
tika-core one among them, are for build tooling.
Filter the graph instead. Everything that ships is built from runtimeClasspath, so the graph keeps
the same 24 runtime packages and drops the rest. With no scope parameter the packages carry no
scope, which nothing here reads.1 parent a427d59 commit 454837b
1 file changed
Lines changed: 8 additions & 5 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
21 | 21 | | |
22 | 22 | | |
23 | 23 | | |
24 | | - | |
25 | | - | |
26 | | - | |
27 | | - | |
28 | | - | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
0 commit comments