You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
What would you like to be added:
Syft currently has a hard coded cut off for max recursive depth for searching for a parent pom. There is some room where the code could be written to detect cycles, but it was unclear at the time of writing the pom parent look up if that cycles can be exited in this way.
Why is this needed:
More options of searching maven for pom documents with the correct information
Hey @spiffcs -- #2769 will sorta fix this, but there still is a relatively large parent depth of 10 by default. Do you think we should get rid of the depth altogether? Either way, we need to leave the parameter for backwards compatiblity, I think, until Syft 2.0.
Actually, I revisited this behavior in #2769 and disabled the depth check by default, since the code was already checking for cycles, so I think this can be considered fixed by that PR.
What would you like to be added:
Syft currently has a hard coded cut off for max recursive depth for searching for a parent pom. There is some room where the code could be written to detect cycles, but it was unclear at the time of writing the pom parent look up if that cycles can be exited in this way.
Why is this needed:
More options of searching maven for pom documents with the correct information
Additional context:
#2274 (comment)
The text was updated successfully, but these errors were encountered: