Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion build.gradle
Original file line number Diff line number Diff line change
Expand Up @@ -166,7 +166,7 @@ dependencies {
implementation "com.blackduck.integration:blackduck-common:${blackDuckCommonVersion}"
implementation 'com.blackduck.integration:blackduck-upload-common:4.1.2'
implementation 'com.blackducksoftware:method-analyzer-core:1.0.1'
implementation "${locatorGroup}:${locatorModule}:2.1.0"
implementation "${locatorGroup}:${locatorModule}:2.1.1"

implementation 'org.apache.maven.shared:maven-invoker:3.0.0'

Expand Down
1 change: 1 addition & 0 deletions documentation/src/main/markdown/currentreleasenotes.md
Original file line number Diff line number Diff line change
Expand Up @@ -56,6 +56,7 @@
* (IDETECT-4813) Fix Gradle Native Inspector to correctly identify projects with only `settings.gradle` or `settings.gradle.kts` file in the root directory.
* (IDETECT-4812) Gradle Native Inspector now supports configuration cache (refactored `init-detect.gradle` to add support for configuration cache in Gradle projects).
* (IDETECT-4845) With added support for extracting Python package versions from direct references [PEP 508 URIs](https://packaging.python.org/en/latest/specifications/dependency-specifiers/#environment-markers) in `pyproject.toml` files, [detect_product_short] now correctly parses versions from wheel and archive URLs and VCS references for impacted detectors (Setuptools CLI, Setuptools Parse, and UV Lock detectors). When data is missing or badly formatted, detectors gracefully switch back to reporting only the package name.
* (IDETECT-4810) Exclude unnecessary directories when looking for the locations of dependency declarations to enhance performance when Component Location Analysis is enabled.
* (IDETECT-4724) Updated Yarn Detector to correctly identify components that were previously unmatched.
* (IDETECT-4850) Log a warning when unsupported `PROC_MACRO` dependency exclusion is attempted with the Cargo Lockfile Detector.

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -1011,8 +1011,8 @@ private DetectProperties() {
BooleanProperty.newBuilder("detect.excluded.directories.defaults.disabled", false)
.setInfo("Detect Excluded Directories Defaults Disabled", DetectPropertyFromVersion.VERSION_7_0_0)
.setHelp(
"If false, Detect will exclude the default directory names. See the detailed help for more information. Caution should be exercised when including this parameter on Windows, as the commmand length generated may exceed OS limitations.",
"If false, the following directories will be excluded by Detect when searching for detectors: __MACOX, bin, build, .git, .gradle, .yarn, node_modules, out, packages, target, .synopsys, .blackduck, and the following directories will be excluded from signature scan using the Scan CLI '--exclude' flag: .git, .gradle, gradle, node_modules, .synopsys, .blackduck."
"If false, Detect will exclude the default list of directory names when searching for applicable detectors (see property details for more information).",
"Directories excluded by default: __MACOX, bin, build, .git, .gradle, .yarn, node_modules, out, packages, target, .synopsys, .blackduck, and the following directories will be excluded from signature scan using the Scan CLI '--exclude' flag: .git, .gradle, gradle, node_modules, .synopsys, .blackduck."
Copy link
Contributor Author

@shantyk shantyk Oct 9, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Mainly wanted to remove the "Caution should be exercised when including this parameter on Windows, as the command length generated may exceed OS limitations" which doesn't apply to the property (its simply either TRUE or FALSE) but ended up rewording a little bit. cc: @cpottsbd

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I believe the command length concern refers to the command that gets issued by Detect when it tries to run the signature scanner.
See the change that introduced this message: https://github.com/blackducksoftware/detect/pull/896/files

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for tracking that down. I see the warning for the property "detect.excluded.directories" also, though for this one it makes sense

)
.setGroups(DetectGroup.PATHS, DetectGroup.DETECTOR, DetectGroup.GLOBAL, DetectGroup.SOURCE_SCAN)
.setCategory(DetectCategory.Advanced)
Expand Down