Repository navigation
feat(manifest): attribute direct JVM dependencies to subproject build files - #1581
Merged
Jeppe Fredsgaard Blaabjerg (jfblaa) merged 4 commits intoOct 7, 2026
Conversation
… files The Maven, Gradle and sbt facts producers now record each subproject's own build files, and the assembler sets `manifestFiles` on every component that is a direct dependency of at least one subproject: the facts file itself, then the build files of those subprojects, relative to the facts file. Transitive-only components carry no field and keep depscan's default attribution to the facts file. A marked build file names the subproject a dependency comes in through, not necessarily the file declaring it (e.g. a parent POM). A subproject without a build file of its own (a Gradle project configured from the root, an sbt project defined only in the root build.sbt) adds no mark.
…settings sbt's per-directory .sbt discovery left a subproject defined in the root build.sbt without any build-file mark. Use the source positions sbt records for each project-scoped setting instead, restricted to files inside the build. A subproject defined in the root build.sbt is now marked with it, and a root .sbt file that only sets ThisBuild values (e.g. version.sbt) no longer marks the root project.
…-cli-mark-components-with-subproject-build-files-in
Jeppe Fredsgaard Blaabjerg (jfblaa)
marked this pull request as ready for review
October 6, 2026 16:53
…th-subproject-build-files-in
Martin Torp (mtorp)
approved these changes
Oct 7, 2026
Jeppe Fredsgaard Blaabjerg (jfblaa)
deleted the
jfblaa/rea-884-socket-cli-mark-components-with-subproject-build-files-in
branch
October 7, 2026 09:03
Merged
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
LLM Description written by Claude Code:claude-opus-5-5
REA-884. Lets the dashboard answer "which module pulled this in?" for multi-module Maven, Gradle and sbt builds, still with one
.socket.facts.jsonper build.Requires Coana's REA-883 handling of these marks in
socket fix, which ships in@coana-tech/cli15.12.1, already onv1.xand merged into this branch.What changes
manifestFiles:{file: ".socket.facts.json"}first, then the build files of the subprojects it is direct in, relative to the facts file (depscan'sSF_ManifestReferenceSchemashape). Transitive-only components get no field and keep depscan's default attribution.MavenProject.getFile().Project.buildFile, only when it exists.build.sbtis marked with it; a root.sbtthat only setsThisBuildvalues is not.Compatibility
--reach, Coana rebuilds the output facts from depscan's artifacts, somanifestFilescomes through as depscan resolved it.Verification
pnpm run checkpasses.[.socket.facts.json, a/pom.xml, b/pom.xml, pom.xml].build.sbtis marked with it, one with its own.sbtfile with that file. On a real sbt 1.5 build, files underproject/that define project settings are marked too.start/end) are out of scope: sbt'sdependencyPositionsmisattributes appended modules. Tracked in REA-886.run-compat.sh). Not verified end to end: dashboard display after depscan ingest.🤖 Generated with Claude Code
Note
Medium Risk
Changes JVM manifest/SBOM shape and multi-tool record emission; downstream consumers must tolerate the new optional field (older Coana strips unknown keys).
Overview
Multi-module Maven, Gradle, and sbt Socket facts SBOMs now record
manifestFileson each direct dependency:.socket.facts.jsonfirst, then build-root-relative paths for subprojects that resolve that dep directly (e.g.a/pom.xml,build.gradle). Transitive-only components omit the field.Build tools emit a new
projectBuildline-protocol record and the assembler maps direct roots → subprojectbuildFiles→manifestFiles. Maven records each module POM; Gradle uses an on-diskbuildFileonly; sbt infers files from in-build setting source positions. Subprojects with no own build file contribute no extra path (facts file only when applicable).A new assembler test and changelog entry document the behavior for dashboard / Coana
socket fixmodule attribution (REA-883).Reviewed by Cursor Bugbot for commit e8d15a6. Configure here.