You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Java builds often activate dependencies only under certain Maven profiles or Gradle configurations. Users need to know whether vg scan / graph edges include inactive profile deps, and how to interpret “direct” vs configuration-scoped edges — without implying remote registry calls that leak credentials.
Context
Java builds often activate dependencies only under certain Maven profiles or Gradle configurations. Users need to know whether
vg scan/ graph edges include inactive profile deps, and how to interpret “direct” vs configuration-scoped edges — without implying remote registry calls that leak credentials.Rewritten theme from adjacent SBOM catalogers (profile-activated deps); Vibgrate docs only.
What to do
vg build/vg scangraphs.Acceptance
vgin examplesRefs: #210 · #214 · #215