[agent] Filed by the October 7 architecture audit campaign (ecosystems). Register: arch-audit register.
Kind: bug. Source: audit B32 (new finding), register E80.
Problem: the check that a vendored artifact isn't git-ignored exists only for the npm family (npm_common.rs#L192, npm_dir gitignore_probe) and as owned !* .gitignore files in the sbt and Coursier trees. Vendored Maven writes {artifact}-{version}.jar (maven_repo.rs), the Maven reactor and Gradle trees write jars, and vendored NuGet writes <id>.<ver>.nupkg (nuget_feed.rs#L106); none of them check. GitHub's stock Java.gitignore ignores *.jar and VisualStudio.gitignore ignores *.nupkg.
Symptoms: #620 (the Gradle twin). #831 (yarn classic twin, fixed). Impact: vendor exits 0 and the local build works, but the commit silently drops the payload; every fresh clone fails (closed: vendor --check exits 1, VEX omits the purl). Low priority per the maintainer's ecosystem triage.
Proposed change: hoist the gitignore preflight (or the owned !* .gitignore) into the shared vendored sink so every backend's artifact root gets it; delete the npm-only special case.
Size and scope: vendor/common.rs, npm_common.rs, maven_repo.rs, nuget_feed.rs, jvm/*; about 150 lines.
Acceptance criteria:
Dependencies: none. Coordinate with #1032 (vendor::jvm::layout).
Generated by Claude Code
[agent] Filed by the October 7 architecture audit campaign (ecosystems). Register: arch-audit register.
Kind: bug. Source: audit B32 (new finding), register E80.
Problem: the check that a vendored artifact isn't git-ignored exists only for the npm family (
npm_common.rs#L192,npm_dirgitignore_probe) and as owned!*.gitignorefiles in the sbt and Coursier trees. Vendored Maven writes{artifact}-{version}.jar(maven_repo.rs), the Maven reactor and Gradle trees write jars, and vendored NuGet writes<id>.<ver>.nupkg(nuget_feed.rs#L106); none of them check. GitHub's stockJava.gitignoreignores*.jarandVisualStudio.gitignoreignores*.nupkg.Symptoms: #620 (the Gradle twin). #831 (yarn classic twin, fixed). Impact:
vendorexits 0 and the local build works, but the commit silently drops the payload; every fresh clone fails (closed:vendor --checkexits 1, VEX omits the purl). Low priority per the maintainer's ecosystem triage.Proposed change: hoist the gitignore preflight (or the owned
!*.gitignore) into the shared vendored sink so every backend's artifact root gets it; delete the npm-only special case.Size and scope:
vendor/common.rs,npm_common.rs,maven_repo.rs,nuget_feed.rs,jvm/*; about 150 lines.Acceptance criteria:
.gitignore.Dependencies: none. Coordinate with #1032 (
vendor::jvm::layout).Generated by Claude Code