Skip to content

Docs: document how Maven/Gradle profile or configuration scopes appear in vg scan graphs #236

Description

@vibgrate-team

Context

Java builds often activate dependencies only under certain Maven profiles or Gradle configurations. Users need to know whether vg scan / graph edges include inactive profile deps, and how to interpret “direct” vs configuration-scoped edges — without implying remote registry calls that leak credentials.

Rewritten theme from adjacent SBOM catalogers (profile-activated deps); Vibgrate docs only.

What to do

  1. Document current behavior for Maven profiles and Gradle configurations as reflected in vg build / vg scan graphs.
  2. Call out empty/partial graphs when lockfiles or resolved trees are missing — actionable next steps, no secrets.
  3. Link related SBOM scope docs (Docs: document prod vs dev/optional dependency scope in vg sbom exports #210) and multi-version component docs (Docs: document how vg sbom treats multiple versions of the same component #214) where relevant.

Acceptance

  • Docs state what is included vs omitted for inactive profiles/configs
  • Actionable recovery steps when resolution data is missing
  • Uses vg in examples
  • DCO sign-off

Refs: #210 · #214 · #215

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    documentationImprovements or additions to documentation

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions