Repository navigation
Fix Go direct dependency classification - #1877
Conversation
Mark go.mod requirements as explicitly referenced unless they carry the // indirect marker. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: b9f67746-b363-43ac-9c8c-764b1890c63c
Increment the detector version because explicit-reference metadata now changes for go.mod dependencies. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: b9f67746-b363-43ac-9c8c-764b1890c63c
|
The snapshot verification failures are expected for this change. The new scan now includes direct Go requirements (for example, |
|
👋 Hi! It looks like you modified some files in the
If none of the above scenarios apply, feel free to ignore this comment 🙂 |
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
No unresolved blocking issues were identified.
Review effort: Lite
Findings: None
What changed in this PR
Fixes Go dependency classification by distinguishing direct requirements from // indirect dependencies and bumps the detector version to 11.
Changes:
- Records explicit-reference metadata from
go.mod. - Adds coverage for single-line and block requirements.
- Tests behavior with the Go CLI available and unavailable.
| File | Description |
|---|---|
test/Microsoft.ComponentDetection.Detectors.Tests/GoComponentDetectorTests.cs |
Tests direct and indirect dependency classification. |
src/Microsoft.ComponentDetection.Detectors/go/Parsers/GoModParser.cs |
Records explicit-reference metadata based on // indirect. |
src/Microsoft.ComponentDetection.Detectors/go/GoComponentDetector.cs |
Updates the detector version. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Summary
go.modas explicitly referenced unless they have the// indirectmarker.require (...)blocks are always transitive.Fixes #1875
Validation
github.com/google/uuidas a direct dependency andgolang.org/x/textas an indirect dependency.explicitlyReferencedComponentIdswhile the indirect dependency is not.