Conversation
When a Gradle project does not set the `group` property, the JS client threw "Artifact coordinates should have a non-empty group ID" instead of scanning the manifest. Mirror the Java client's fallback: default to "unknown" for empty group and "0.0.0" for empty version. Resolves: TC-6400 Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Reviewer's guide (collapsed on small PRs)Reviewer's GuideThe PR fixes Gradle root PURL construction by centralizing coordinate generation and applying Java-client-compatible fallbacks for missing group and version metadata, while adding Groovy and Kotlin regression coverage that verifies successful SBOM generation for projects without a group. Sequence diagram for Gradle root PURL fallback constructionsequenceDiagram
participant Gradle as Gradle manifest
participant Provider as Java_gradle
participant SBOM as Sbom
participant PURL as parseDep
Gradle->>Provider: #buildSbom(content, properties, manifestPath, opts, hashMap)
Provider->>Provider: #buildRootCoordinate(properties)
alt group or version is empty
Provider->>PURL: parseDep(unknown:rootName:jar:0.0.0)
else metadata is present
Provider->>PURL: parseDep(group:rootName:jar:version)
end
PURL-->>Provider: rootPurl
Provider->>SBOM: addRoot(rootPurl, license)
Gradle->>Provider: #buildDirectDependenciesSbom(content, properties, manifestPath, opts, hashMap)
Provider->>Provider: #buildRootCoordinate(properties)
Provider->>PURL: parseDep(rootCoordinate)
PURL-->>Provider: rootPurl
Provider->>SBOM: addRoot(rootPurl, license)
File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
There was a problem hiding this comment.
Hey - I've reviewed your changes and they look great!
Sourcery assessment
Needs a human reviewer. If the fallback coordinate or project-name parsing is wrong, generated SBOMs can contain an incorrect or colliding root PURL, affecting downstream dependency identification. Reverting stops the behavior, and affected SBOMs can be regenerated, so the impact is bounded and repairable.
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #644 +/- ##
==========================================
- Coverage 92.11% 92.09% -0.02%
==========================================
Files 45 45
Lines 10675 10682 +7
Branches 1932 1935 +3
==========================================
+ Hits 9833 9838 +5
- Misses 842 844 +2
Flags with carried forward coverage won't be shown. Click here to find out more.
🚀 New features to boost your workflow:
|
Description
When a Gradle project does not set the
groupproperty, the JS client threw "Artifact coordinates should have a non-empty group ID" instead of scanning the manifest. Mirror the Java client's fallback: default to "unknown" for empty group and "0.0.0" for empty version.Resolves: TC-6400
Checklist
Additional information
Summary by Sourcery
Handle missing Gradle project metadata so manifest scanning succeeds with stable fallback coordinates.
Bug Fixes:
Tests: