Repository navigation
feat(manifest): attribute Gradle direct dependencies to their declaring build script - #1593
Merged
Jeppe Fredsgaard Blaabjerg (jfblaa) merged 3 commits intoOct 8, 2026
Merged
Conversation
… them
A direct dependency's build-file mark is now the in-build script that
declared it: the root build script for one added from subprojects {} or
project(':x') {}, a script plugin for apply from. A subproject configured
entirely from the root therefore gets the root script, both on its direct
dependencies and in projects[].manifestFiles, instead of no build file.
A dependency no build script declared, such as one added by a plugin,
keeps the project's own build file.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…uild file A direct dependency no build script is known to declare now falls back to the subproject's configured build file even when it is absent on disk, so every Gradle direct dependency names the subproject pulling it in. The same configured file is the last fallback for projects[].manifestFiles. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Jeppe Fredsgaard Blaabjerg (jfblaa)
force-pushed
the
jfblaa/facts-definition-sites
branch
from
October 8, 2026 13:59
14238a9 to
2d0110c
Compare
Jeppe Fredsgaard Blaabjerg (jfblaa)
changed the base branch from
jfblaa/named-socket-facts-files
to
v1.x
October 8, 2026 13:59
Jeppe Fredsgaard Blaabjerg (jfblaa)
marked this pull request as ready for review
October 8, 2026 13:59
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.
Bugbot Autofix is ON. A cloud agent has been kicked off to fix the reported issue. You can view the agent here.
Comment @cursor review or bugbot run to trigger another review on this PR
Reviewed by Cursor Bugbot for commit 2d0110c. Configure here.
Martin Torp (mtorp)
approved these changes
Oct 8, 2026
Jeppe Fredsgaard Blaabjerg (jfblaa)
deleted the
jfblaa/facts-definition-sites
branch
October 8, 2026 15:13
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

LLM Description written by Claude Code:claude-opus-5-5
A Gradle subproject configured entirely from the root build script (via
subprojects {}orproject(':x') {}) has no build file of its own. Its direct dependencies therefore carried only the facts file inmanifestFiles, which made them indistinguishable from transitive ones and left nothing to route by subproject. Gradle direct dependencies now always carry a build-file mark.apply from, and the subproject's own script otherwise. The init script records the script running when each dependency is added. Groovy stack frames carry its path. For Kotlin DSL, the path comes from the script class loader's internal scope id, which needs Java 9+.buildFile. That file may not exist on disk; it is still emitted because the mark's presence is the signal that the dependency is direct for this subproject.projects[].manifestFilesis the project's own build file, else the scripts declaring its dependencies (typically the root build script), else the configured build file.Known limitations
gradle/deps.gradle) is marked with that script. Coana's Gradle fix then also targets the root project. This is accepted as known behaviour.Coana
Coana confirmed it doesn't infer directness from build-file marks, ignores marks for files it wasn't given, and reads
projects[].manifestFilesonly for Maven. No coordinated release needed.Testing
projects[].manifestFiles.subprojects {}, rootproject(':x') {},apply fromscript plugins, the subproject's own script, andbuildSrcconvention plugins (falling back to the build file). End-to-end throughsocket manifest gradle --factson a Kotlin DSL build.🤖 Generated with Claude Code
Note
Medium Risk
Changes Gradle facts emission and SBOM
manifestFilessemantics used for routing direct deps; Maven is untouched but downstream tools may treat new or missing-file marks differently.Overview
Gradle direct dependencies now get
manifestFilesthat name the build script that declared them (rootbuild.gradle,apply fromplugins, or the subproject script), instead of only listing every subproject build file that pulled them in directly.The Gradle init script records declarations via
declaredline-protocol records (stack walk for Groovy; Kotlin DSL resolves.ktspaths from the script class loader on Java 9+). The assembler prefers those scripts pergroup:name; when none is known it falls back to the subproject’s configuredbuildFile, including files not on disk (projectBuild+missing).projects[].manifestFilesfor Gradle now uses the module’s own build file when present, otherwise the scripts that declare its dependencies, otherwise the configured (possibly missing) build file. Maven/sbt assembly behavior is unchanged aside from type/docs updates.Reviewed by Cursor Bugbot for commit 2d0110c. Configure here.