Skip to content

Include nested components in version diffs - #454

Open
sueun-dev wants to merge 1 commit into
CycloneDX:mainfrom
sueun-dev:codex/fix-nested-component-diff-20260925
Open

sueun-dev wants to merge 1 commit into
CycloneDX:mainfrom
sueun-dev:codex/fix-nested-component-diff-20260925

Conversation

@sueun-dev

Copy link
Copy Markdown

ComponentVersionDiff only compares the top-level Bom.Components lists. A version change inside an assembly is omitted: in a local CLI build, changing a nested library from version 1 to 2 prints None, even though both input BOMs validate.

Walk the nested Components lists before the existing group/name/version comparison. The tests cover nested additions, removals, changes and unchanged versions, movement into an assembly, flat components, and exclusion of pedigree ancestors.

Checked on Linux arm64 with .NET 8 and 10:

  • New regressions: 9 failures and 5 passes before, 14 passes after, per framework.
  • dotnet clean && dotnet build --no-restore /WarnAsError && dotnet test --no-restore: build succeeds with no warnings; 2,884 tests pass and one existing memory test is skipped per framework.
  • The local CLI comparison passes all 20 JSON/XML cases after the fix, versus 4 before. The 40 input fixtures validate; a malformed control is rejected.

DocFX 2.78.3 completes with the same 13 warnings before and after, including NU1902 warnings for Microsoft.Build.Tasks.Git. The Windows matrix was not run locally.

Signed-off-by: sueun-dev <57546981+sueun-dev@users.noreply.github.com>
@sueun-dev
sueun-dev requested a review from a team as a code owner September 25, 2026 16:32

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant