You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This pull request improves the Dockerfile component detector's handling of files that are named like Dockerfiles but contain other formats. Parse failures are now treated as expected non-Dockerfile input and logged as warnings, while other processing failures remain errors.
The detector also skips files under node_modules, where packages may include Dockerfile language definitions that are not build instructions. Tests cover JavaScript content in dockerfile.mjs and dockerfile.d.mts, as well as a Dockerfile-like file under node_modules, ensuring these files do not produce false positives.
👋 Hi! It looks like you modified some files in the Detectors folder.
You may need to bump the detector versions if any of the following scenarios apply:
The detector detects more or fewer components than before
The detector generates different parent/child graph relationships than before
The detector generates different devDependencies values than before
If none of the above scenarios apply, feel free to ignore this comment 🙂
Skipping every matching file under node_modules intentionally removes components that version 1 previously reported, but the detector version is unchanged. The repository requires detector versions to be incremented for breaking output changes (docs/creating-a-new-detector.md:178), and verification uses version increases to identify intentional detector changes (ComponentDetectionIntegrationTests.cs:240-265). Increment this detector to version 2 with the new exclusion.
Skipping an entire path class can remove DockerReference components that version 1 previously reported, so this is a breaking detector-output change. The repository's detector guidance requires incrementing Version for breaking changes (docs/creating-a-new-detector.md:176-179); bump this detector to version 2 so consumers can identify the changed results.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This pull request improves the Dockerfile component detector's handling of files that are named like Dockerfiles but contain other formats. Parse failures are now treated as expected non-Dockerfile input and logged as warnings, while other processing failures remain errors.
The detector also skips files under
node_modules, where packages may include Dockerfile language definitions that are not build instructions. Tests cover JavaScript content indockerfile.mjsanddockerfile.d.mts, as well as a Dockerfile-like file undernode_modules, ensuring these files do not produce false positives.