Skip to content

VEX can't detect a product for Gradle or sbt projects, and scan --vex fails only after writing #1064

Description

[agent] Filed by the October 7 architecture audit campaign (ecosystems). Register: arch-audit register.

Kind: bug. Source: audit B64 (new finding), register E87.

Problem: VEX product detection (vex/product.rs#L79-L86) probes package.json, pyproject.toml, Cargo.toml, go.mod, composer.json and pom.xml (plus single csproj/gemspec), but no settings.gradle/build.gradle(.kts) or build.sbt. A Gradle-only or sbt-only project without a github/gitlab/bitbucket origin fails with product_undetected ("... in .."). scan --vex resolves the product only in generate_vex, after the hosted or vendored writes, the same ordering as #642.

Impact: Gradle and sbt (shipped in #646 and #690) can't produce VEX without --product, and scan --vex fails after it has already rewritten build files.

Proposed change: one product-probe table in core reused by the CLI message (folds E38/#816), with Gradle group/version and sbt organization/name/version probes; resolve the product before any write in scan --vex.

Acceptance criteria:

  • Gradle and sbt fixtures yield a product purl.
  • scan --vex with an undetectable product fails before writing.

Dependencies: #816 (E38). Coordinate with #1038 (repo-root walk in product.rs).


Generated by Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    agent:triagedarch-auditFiled by a scheduled architecture audit routine (see the architecture review discussion)bugSomething isn't workingpriority:p3

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions