https://gradle.com/ logo
Join Slack
Powered by
# github-integrations
  • s

    Simon Kågedal Reimer

    04/22/2024, 1:20 PM
    We just tried the new Dependency Submission Action, seems very nice!
  • d

    Daz DeBoer

    04/22/2024, 9:10 PM
    Thanks for the feedback @Simon Kågedal Reimer
    🙌 1
  • d

    Daz DeBoer

    04/22/2024, 9:15 PM
    For folks joining this channel, here are some useful links: • Guide to Resolving a Dependency Vulnerability: it's sometimes tricky to work out why a dependency is appearing in your project. This is a guide to working out what's bringing it in, and how to fix it. • A project demonstrating the use of `dependency-submission` with some examples of dependency vulnerabilities. Fork this project and follow the guide to fixing some real-world vulnerabilities. • Frequently asked questions about
    dependency-submission
  • a

    Armandorobleee

    04/22/2024, 10:24 PM
    Contiene!
  • o

    Oleg Nenashev

    05/06/2024, 4:12 AM
    GitHub Universe CFPs are open until the end of the week. https://githubuniverse.com/
  • p

    Praveen

    05/10/2024, 1:59 PM
    Hi, we've just started using the dependency submission action, dependencies and version are being populated under the Insights -> Dependency Graph -> Dependencies tab. However, license details aren't. For example
    pkg:maven/com.google.code.gson/gson@2.9.0
    from the demo repo is labelled
    "licenseConcluded": "Apache-2.0"
    but for the same package there is no
    licenseConcluded
    entry on ours. Following setting up the build env the action is being run in the same way as the demo repo (minus scan publishing). Any ideas on how to resolve the licenses problem? For ref we're running a self-hosted GHE instance. Cheers!
    d
    • 2
    • 2
  • o

    Oleg Nenashev

    06/26/2024, 11:53 AM
    https://gradle-community.slack.com/archives/CRA9GTYBH/p1719402825277929
  • o

    Oleg Nenashev

    07/02/2024, 12:24 PM
    FYI

    https://www.youtube.com/watch?v=gV94I28FPos▾

  • b

    Bartosz Galek

    10/25/2024, 7:23 AM
    hi! How do you feel about github generated dependency graph (SBOM) having gradle version inside? I'm missing it in my reports 😉
    d
    • 2
    • 3