Sitelet https://github.com/microsoft/component-detection/pull/1877
Skip to content

Fix Go direct dependency classification - #1877

Merged
Aayush Maini (AMaini503) merged 2 commits into
mainfrom
users/aamaini/go-explicit-references
Sep 21, 2026
Merged

Aayush Maini (AMaini503) merged 2 commits into
mainfrom
users/aamaini/go-explicit-references

Conversation

@AMaini503

Copy link
Copy Markdown
Contributor

Summary

  • Mark dependencies parsed from go.mod as explicitly referenced unless they have the // indirect marker.
  • Remove the incorrect assumption that dependencies inside require (...) blocks are always transitive.
  • Bump the Go detector version from 10 to 11.
  • Cover single-line and block requirements with the Go CLI both available and unavailable.

Fixes #1875

Validation

  • Ran the Microsoft.ComponentDetection.Detectors.Tests project: 968 passed, 0 failed.
  • Built the Component Detection CLI successfully.
  • Created and scanned a Go 1.24.3 module with github.com/google/uuid as a direct dependency and golang.org/x/text as an indirect dependency.
  • Confirmed the direct dependency is emitted in explicitlyReferencedComponentIds while the indirect dependency is not.

Aayush Maini added 2 commits September 21, 2026 13:30
Mark go.mod requirements as explicitly referenced unless they carry the // indirect marker.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: b9f67746-b363-43ac-9c8c-764b1890c63c
Increment the detector version because explicit-reference metadata now changes for go.mod dependencies.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: b9f67746-b363-43ac-9c8c-764b1890c63c
@AMaini503
Aayush Maini (AMaini503) requested a review from a team as a code owner September 21, 2026 20:55
@AMaini503

Copy link
Copy Markdown
Contributor Author

The snapshot verification failures are expected for this change. The new scan now includes direct Go requirements (for example, github.com/sirupsen/logrus v1.8.3 - Go) in explicitlyReferencedComponentIds, while the published release snapshot has an empty explicit-reference set for that Go graph. All three platforms report this same intentional metadata difference; the remaining verification tests pass.

@github-actions

Copy link
Copy Markdown

👋 Hi! It looks like you modified some files in the Detectors folder.
You may need to bump the detector versions if any of the following scenarios apply:

  • The detector detects more or fewer components than before
  • The detector generates different parent/child graph relationships than before
  • The detector generates different devDependencies values than before

If none of the above scenarios apply, feel free to ignore this comment 🙂

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

No unresolved blocking issues were identified.

Review effort: Lite
Findings: None

What changed in this PR

Fixes Go dependency classification by distinguishing direct requirements from // indirect dependencies and bumps the detector version to 11.

Changes:

  • Records explicit-reference metadata from go.mod.
  • Adds coverage for single-line and block requirements.
  • Tests behavior with the Go CLI available and unavailable.
File Description
test/​Microsoft.ComponentDetection.Detectors.Tests/​GoComponentDetectorTests.cs Tests direct and indirect dependency classification.
src/​Microsoft.ComponentDetection.Detectors/​go/​Parsers/​GoModParser.cs Records explicit-reference metadata based on // indirect.
src/​Microsoft.ComponentDetection.Detectors/​go/​GoComponentDetector.cs Updates the detector version.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@AMaini503
Aayush Maini (AMaini503) merged commit a35446f into main Sep 21, 2026
19 of 25 checks passed
@AMaini503
Aayush Maini (AMaini503) deleted the users/aamaini/go-explicit-references branch September 21, 2026 21:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Go 1.17+ direct requirements are omitted from explicitlyReferencedComponentIds

3 participants