Skip to content

XRAY-160045 - Use the Maven wrapper in the fix stage - #1425

Draft
Jordanh1996 wants to merge 1 commit into
jfrog:v2_mainfrom
Jordanh1996:fix/XRAY-160045-maven-fix-stage-use-wrapper
Draft

Jordanh1996 wants to merge 1 commit into
jfrog:v2_mainfrom
Jordanh1996:fix/XRAY-160045-maven-fix-stage-use-wrapper

Conversation

@Jordanh1996

Copy link
Copy Markdown
Contributor

https://jfrog-int.atlassian.net/browse/XRAY-160045

Background

A project that commits a Maven wrapper often builds on agents with no system Maven installed — the wrapper is there so that none is needed. On those agents the scan succeeds, but autofix fails with exec: "mvn": executable file not found in $PATH and no fix pull requests are opened. The only workaround is JF_SKIP_AUTOFIX, which turns the fix stage off entirely.

Description

NewMavenPackageHandler built its java.DepTreeParams without UseWrapper, so maven-dep-tree ran as plain mvn in the fix stage, while the audit path passes the flag through in RunInstallAndAudit. It now carries scanDetails.UseWrapper, read with the != nil && * idiom used elsewhere for optional *bool config.

Tests

TestNewMavenPackageHandlerUsesWrapper — writes a stub mvnw and asserts the handler execs it; fails without the change.

Real scan-repository run against GitHub and Xray on a wrapper-only Maven project with mvn removed from PATH: before, the fix stage fails with the error above and opens no pull requests; after, both stages run ./mvnw and the expected fix pull requests are created.


  • All tests passed. If this feature is not already covered by the tests, I added new tests.
  • This pull request is on the dev branch.
  • I used gofmt for formatting the code before submitting the pull request.
  • Update documentation about new features / new supported technologies

🤖 Generated with Claude Code

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Sep 22, 2026

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true

Comment @coderabbitai help to get the list of available commands.

This branch is waiting to be deployed

1 waiting deployment
frogbot — c3fd5d20 Waiting Sep 22, 2026 by Jordanh1996 via scan-pull-request #2504
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant