Skip to content

feat(manifest): mark build modules as firstParty in facts components - #1569

Merged
Jeppe Fredsgaard Blaabjerg (jfblaa) merged 3 commits into
v1.xfrom
jfblaa/facts-first-party
Sep 29, 2026
Merged

Jeppe Fredsgaard Blaabjerg (jfblaa) merged 3 commits into
v1.xfrom
jfblaa/facts-first-party

Conversation

@jfblaa

@jfblaa Jeppe Fredsgaard Blaabjerg (jfblaa) commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

LLM Description written by Claude Code:claude-opus-5-5

Important

Release gate: do not merge until this branch also bumps the bundled @coana-tech/cli to a version whose --compute-artifacts-sidecar schema accepts components[].firstParty. Released coana versions parse the sidecar strictly and reject the key ("Invalid --compute-artifacts-sidecar"), which breaks socket scan --reach and socket fix --dynamic-sbom-inference.

Components in .socket.facts.json whose exact GAV is a module of the scanned build now carry firstParty: true (maven, gradle, sbt). The field is omitted otherwise, never false.

Why: on multi-module builds, socket fix treated a sibling module that pins a vulnerable dependency as a published package blocking the upgrade ("no version of org.example:A is compatible"). With the build's own modules marked, depscan proposes the direct upgrade instead.

  • Matching reuses the GAV lookup that already attaches project sources/targets; qualifiers are not compared.
  • A published release of a sibling module (different version) stays unmarked; internal is unchanged.
  • Everything else in the facts output is identical: regenerated maven/gradle/sbt multi-module fixtures match 1.2.1 output byte-for-byte apart from the new field.
  • Sidecar components[] carry the field as plain copies of the facts components; sidecar projects[] never do (tested).

🤖 Generated with Claude Code

Components whose exact GAV is a module of the scanned build now carry
`firstParty: true` in .socket.facts.json, for maven, gradle and sbt. This
lets dependency resolution stop treating the build's own modules as
published packages that block upgrades. The match reuses the same GAV
lookup that attaches project sources/targets. Published releases of a
sibling module stay unmarked.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

Comment thread src/commands/manifest/scripts/facts.mts Outdated
Comment thread src/commands/manifest/scripts/assemble.mts
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@jfblaa
Jeppe Fredsgaard Blaabjerg (jfblaa) merged commit 6c64cc2 into v1.x Sep 29, 2026
10 checks passed
@jfblaa
Jeppe Fredsgaard Blaabjerg (jfblaa) deleted the jfblaa/facts-first-party branch September 29, 2026 11:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants