[agent] Filed by the October 7 architecture audit campaign (ecosystems). Register: arch-audit register.
Kind: bug. Source: audit B64 (new finding), register E87.
Problem: VEX product detection (vex/product.rs#L79-L86) probes package.json, pyproject.toml, Cargo.toml, go.mod, composer.json and pom.xml (plus single csproj/gemspec), but no settings.gradle/build.gradle(.kts) or build.sbt. A Gradle-only or sbt-only project without a github/gitlab/bitbucket origin fails with product_undetected ("... in .."). scan --vex resolves the product only in generate_vex, after the hosted or vendored writes, the same ordering as #642.
Impact: Gradle and sbt (shipped in #646 and #690) can't produce VEX without --product, and scan --vex fails after it has already rewritten build files.
Proposed change: one product-probe table in core reused by the CLI message (folds E38/#816), with Gradle group/version and sbt organization/name/version probes; resolve the product before any write in scan --vex.
Acceptance criteria:
Dependencies: #816 (E38). Coordinate with #1038 (repo-root walk in product.rs).
Generated by Claude Code
[agent] Filed by the October 7 architecture audit campaign (ecosystems). Register: arch-audit register.
Kind: bug. Source: audit B64 (new finding), register E87.
Problem: VEX product detection (
vex/product.rs#L79-L86) probes package.json, pyproject.toml, Cargo.toml, go.mod, composer.json and pom.xml (plus single csproj/gemspec), but nosettings.gradle/build.gradle(.kts)orbuild.sbt. A Gradle-only or sbt-only project without a github/gitlab/bitbucket origin fails withproduct_undetected("... in ..").scan --vexresolves the product only ingenerate_vex, after the hosted or vendored writes, the same ordering as #642.Impact: Gradle and sbt (shipped in #646 and #690) can't produce VEX without
--product, andscan --vexfails after it has already rewritten build files.Proposed change: one product-probe table in core reused by the CLI message (folds E38/#816), with Gradle group/version and sbt organization/name/version probes; resolve the product before any write in
scan --vex.Acceptance criteria:
scan --vexwith an undetectable product fails before writing.Dependencies: #816 (E38). Coordinate with #1038 (repo-root walk in product.rs).
Generated by Claude Code