You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Resolve Maven properties in component coordinates - #1882
Resolve Maven property references in group IDs and artifact IDs as well as versions when using static POM parsing. Skip components whose coordinates remain unresolved and bump the detector version for the output change.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
👋 Hi! It looks like you modified some files in the Detectors folder.
You may need to bump the detector versions if any of the following scenarios apply:
The detector detects more or fewer components than before
The detector generates different parent/child graph relationships than before
The detector generates different devDependencies values than before
If none of the above scenarios apply, feel free to ignore this comment 🙂
Recursively resolve coordinate properties with memoization and cycle detection. Add coverage for nested local and inherited properties and cyclic definitions.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Limit recursive coordinate property expansion to prevent deeply nested POM properties from exhausting the process stack. Leave over-depth coordinates unresolved so they are skipped safely.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This check misses unresolved forms such as ${} and ${missing because the resolution regex requires a nonempty, closed expression. Those versions were previously deferred by StartsWith("${") and skipped, but are now registered as Maven components with literal placeholder text. Use a broader residual-marker check after expansion so any remaining Maven interpolation start causes the coordinate to be skipped.
Treat any residual Maven interpolation marker as unresolved so malformed references are skipped rather than emitted as component coordinates.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Resolve Maven property references in every component coordinate field when the static POM parser is used.
groupId,artifactId, andversionspark-core_${scala.version.major}Testing
dotnet build --no-restore --configuration Debugdotnet test test\Microsoft.ComponentDetection.Detectors.Tests\Microsoft.ComponentDetection.Detectors.Tests.csproj --no-build --configuration Debug -p:ExcludeIntegrationTests=false -p:TestingPlatformCommandLineArguments="--filter FullyQualifiedName~MvnCliDetectorTests"