Skip to content

feat(bazel): Add option to filter the dependency tree - #12518

Open
nnobelis wants to merge 1 commit into
oss-review-toolkit:mainfrom
boschglobal:nnobelis/bazel_filter_dependency_tree
Open

nnobelis wants to merge 1 commit into
oss-review-toolkit:mainfrom
boschglobal:nnobelis/bazel_filter_dependency_tree

Conversation

@nnobelis

Copy link
Copy Markdown
Member

Add a new allowedDependenciesPath configuration option that points to a file listing the dependencies (by apparentName) that are allowed to remain in the dependency tree. Any dependency not present in that file, together with its own subtree, is removed from the resolved BazelModule before further processing.

This is useful to prune dependencies that are not relevant for the analysis, for example test-only or platform-specific dependencies that would otherwise pollute the dependency graph."

Note

The implementation in this PR was suggested in a ORT Community meeting.

@nnobelis
nnobelis requested a review from a team as a code owner September 25, 2026 08:29
@sschuberth

Copy link
Copy Markdown
Member

Could you please also explain why the same cannot be achieved with scope / path excludes in combination with skipExcluded for the analyzer?

Comment thread plugins/package-managers/bazel/src/main/kotlin/Bazel.kt Fixed
@codecov

codecov Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 59.21%. Comparing base (59c8e0f) to head (57fdbbe).
⚠️ Report is 12 commits behind head on main.

Additional details and impacted files
@@            Coverage Diff            @@
##               main   #12518   +/-   ##
=========================================
  Coverage     59.21%   59.21%           
+ Complexity     1893     1891    -2     
=========================================
  Files           366      366           
  Lines         13838    13838           
  Branches       1462     1462           
=========================================
  Hits           8194     8194           
  Misses         5114     5114           
  Partials        530      530           
Flag Coverage Δ
funTest-external-tools 16.14% <ø> (+<0.01%) ⬆️
funTest-no-external-tools 29.30% <ø> (-0.08%) ⬇️
test-ubuntu-26.04 42.61% <ø> (+0.01%) ⬆️
test-windows-2025 42.59% <ø> (+0.01%) ⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.
@nnobelis
nnobelis force-pushed the nnobelis/bazel_filter_dependency_tree branch from 4147f9f to 84fc7a4 Compare September 25, 2026 09:18
@nnobelis

Copy link
Copy Markdown
Member Author

Could you please also explain why the same cannot be achieved with scope / path excludes in combination with skipExcluded for the analyzer?

I need to reach out to the customer to find what what their requirements again: I think they had some architecture specific packages that could not simply be excluded by scope / path excludes.

Comment thread plugins/package-managers/bazel/src/main/kotlin/Bazel.kt Outdated
Comment thread plugins/package-managers/bazel/src/main/kotlin/Bazel.kt Outdated
Comment thread plugins/package-managers/bazel/src/main/kotlin/Bazel.kt Outdated
@nnobelis
nnobelis force-pushed the nnobelis/bazel_filter_dependency_tree branch from 84fc7a4 to d050c61 Compare September 25, 2026 09:59
Add a new `allowedDependenciesPath` configuration option that points to
a file listing the dependencies (by `apparentName`) that are allowed to
remain in the dependency tree. Any dependency not present in that file,
together with its own subtree, is removed from the resolved
`BazelModule` before further processing.

This is useful to prune dependencies that are not relevant for the
analysis, for example test-only or platform-specific dependencies
that would otherwise pollute the dependency graph."

Signed-off-by: Nicolas Nobelis <nicolas.nobelis@bosch.com>
@nnobelis
nnobelis force-pushed the nnobelis/bazel_filter_dependency_tree branch from d050c61 to 57fdbbe Compare September 25, 2026 10:41
@sschuberth
sschuberth requested a review from a team September 25, 2026 11:04
@fviernau

Copy link
Copy Markdown
Member

I have a hunch the use of this feature may be mostly by Bosch itself.
So, after a while it will probably hard for any non-internal to figure out the use case.
To mitigate this in some light weight way, would it help to create an ORT issue with a feature request were the use
case is described, and link the PR to it?

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

4 participants