Thanks to visit codestin.com
Credit goes to github.com

Skip to content

Conversation

@hogo6002
Copy link
Contributor

@hogo6002 hogo6002 commented Jul 25, 2025

  • enables call analysis on all scanning types
  • adds "Jar" call analysis option
  • enables Java reachability enricher if call analysis config includes JAR
  • annotates all vulnerabilities from unreachable packages as uncalled
  • adds unit tests for Java archive scanning with call analysis enabled

@hogo6002 hogo6002 marked this pull request as ready for review July 29, 2025 03:59
@hogo6002 hogo6002 requested a review from another-rex July 29, 2025 03:59
@hogo6002
Copy link
Contributor Author

PR is ready for code review. The unit tests will be fixed after google/osv-scalibr#946 merges in.

@codecov-commenter
Copy link

codecov-commenter commented Jul 29, 2025

Codecov Report

❌ Patch coverage is 81.57895% with 7 lines in your changes missing coverage. Please review.
✅ Project coverage is 67.16%. Comparing base (a8c97f3) to head (eceb53f).

Files with missing lines Patch % Lines
pkg/osvscanner/osvscanner.go 30.00% 5 Missing and 2 partials ⚠️
Additional details and impacted files
@@            Coverage Diff             @@
##             main    #2113      +/-   ##
==========================================
- Coverage   67.52%   67.16%   -0.37%     
==========================================
  Files         169      169              
  Lines       16248    16326      +78     
==========================================
- Hits        10972    10965       -7     
- Misses       4601     4678      +77     
- Partials      675      683       +8     

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@another-rex
Copy link
Collaborator

Is this still blocked on windows tests after you made the change in osv-scalibr?

@hogo6002
Copy link
Contributor Author

Is this still blocked on windows tests after you made the change in osv-scalibr?

It's pending on osv-scalibr version update in osv-scanner

@hogo6002 hogo6002 merged commit 6f95142 into google:main Aug 13, 2025
13 of 15 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants