Skip to content

fix(discovery): exclude build-wrapper infra paths in git-mode - #2

Open
sorted-ai-bot wants to merge 1 commit into
mainfrom
fix/discovery-git-mode-infra-exclusion
Open

sorted-ai-bot wants to merge 1 commit into
mainfrom
fix/discovery-git-mode-infra-exclusion

Conversation

@sorted-ai-bot

Copy link
Copy Markdown
Collaborator

Summary

  • Git-mode discovery (git ls-files) did not apply the build-wrapper / infrastructure directory exclusions that walk-mode applied. As a result, files under .mvn/wrapper, gradle/wrapper, vendor, node_modules, .git, and .gradle were scanned in real (git-tracked) projects and reported as false positives — e.g. a vendored Maven wrapper main class flagged as dead code.
  • Root cause: the exclusion list lived only in findJavaFilesWalk; findJavaFilesGit filtered solely by path prefix. Asymmetry between the two discovery paths.
  • Fix: extract a shared isExcludedInfraPath helper and apply it in BOTH discovery paths so they are symmetric. Matching is by exact path SEGMENT (a project literally named e.g. mvnutil or mygradlestuff is NOT excluded; a wrapper dir is excluded only when its parent is gradle).
  • Adds discovery_test.go: table-driven unit tests for excluded vs not-excluded paths, plus an integration test for each discovery path (walk and git).

Verification

  • spring-boot-docker: 3 false positives → 0 findings.
  • Genuine true positives preserved: spring-boot-rest-example still 2 (a never-published Spring event), spring-petclinic still 0.
  • go build ./... && go vet ./... green; new discovery tests pass.

This is a precision fix on the read-only Java scanner. No behavior change for application projects that were already clean.

Git-mode discovery (git ls-files) did not apply the build-wrapper and
infrastructure exclusions that walk-mode applied, so files under
.mvn/wrapper, gradle/wrapper, vendor, node_modules, .git, and .gradle
were scanned and reported as false positives (e.g. a vendored Maven
wrapper main class flagged as dead code).

Extract the exclusion predicate into a shared isExcludedInfraPath helper
and apply it in both git-mode and walk-mode so the two discovery paths
are symmetric. Matching is by exact path segment (a project literally
named e.g. mvnutil is not excluded).

Adds discovery_test.go covering both excluded and not-excluded cases and
an integration test for each discovery path.

Verified: spring-boot-docker FP cleared (0 findings); genuine true
positives preserved (spring-boot-rest-example 2, spring-petclinic 0);
build/vet/test green.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants