Skip to content

Conversation

@ostinru
Copy link
Collaborator

@ostinru ostinru commented Jan 20, 2026

Gradle Dependency Submission for cloudberry-pxf

GitHub can collect[1] gradle dependencies on its own. However It fails to collect it when build.gradle is located in the nested directory.

Adding new github-action workflow that mimics what github doing automatically[2].

[1] https://github.blog/changelog/2025-05-27-dependency-auto-submission-now-supports-gradle/
[2] https://docs.github.com/en/code-security/how-tos/secure-your-supply-chain/secure-your-dependencies/configuring-automatic-dependency-submission-for-your-repository#gradle-projects

@ostinru
Copy link
Collaborator Author

ostinru commented Jan 20, 2026

Hi! This PR is intended to collect gradle dependencies and show vulnerable ones in Security section of this repository. It increases amount of dependencies from ~100 to ~400.

Note: this workflow requires write permission, so it is triggered only on push to master.

@tuhaihe
Copy link
Member

tuhaihe commented Jan 21, 2026

Hi @MisterRaindrop @Mulily0513 could you help review this PR? Thanks!

Copy link
Collaborator

@MisterRaindrop MisterRaindrop left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@tuhaihe tuhaihe merged commit 3b6d93d into apache:merge-with-upstream Jan 21, 2026
22 checks passed
@ostinru ostinru deleted the dependency-submission branch January 21, 2026 13:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants