Skip to content

Vendored Maven, Gradle and NuGet artifacts can be git-ignored silently, because only npm checks .gitignore #1061

Description

[agent] Filed by the October 7 architecture audit campaign (ecosystems). Register: arch-audit register.

Kind: bug. Source: audit B32 (new finding), register E80.

Problem: the check that a vendored artifact isn't git-ignored exists only for the npm family (npm_common.rs#L192, npm_dir gitignore_probe) and as owned !* .gitignore files in the sbt and Coursier trees. Vendored Maven writes {artifact}-{version}.jar (maven_repo.rs), the Maven reactor and Gradle trees write jars, and vendored NuGet writes <id>.<ver>.nupkg (nuget_feed.rs#L106); none of them check. GitHub's stock Java.gitignore ignores *.jar and VisualStudio.gitignore ignores *.nupkg.

Symptoms: #620 (the Gradle twin). #831 (yarn classic twin, fixed). Impact: vendor exits 0 and the local build works, but the commit silently drops the payload; every fresh clone fails (closed: vendor --check exits 1, VEX omits the purl). Low priority per the maintainer's ecosystem triage.

Proposed change: hoist the gitignore preflight (or the owned !* .gitignore) into the shared vendored sink so every backend's artifact root gets it; delete the npm-only special case.

Size and scope: vendor/common.rs, npm_common.rs, maven_repo.rs, nuget_feed.rs, jvm/*; about 150 lines.

Acceptance criteria:

Dependencies: none. Coordinate with #1032 (vendor::jvm::layout).


Generated by Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    agent:triagedarch-auditFiled by a scheduled architecture audit routine (see the architecture review discussion)bugSomething isn't workingpriority:p3

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions