Skip to content

Fix OSS Index Audit again#2706

Merged
trask merged 3 commits intoopen-telemetry:mainfrom
trask:fix-audit
Mar 20, 2026
Merged

Fix OSS Index Audit again#2706
trask merged 3 commits intoopen-telemetry:mainfrom
trask:fix-audit

Conversation

@trask
Copy link
Copy Markdown
Member

@trask trask commented Mar 19, 2026

No description provided.

@trask trask requested a review from a team as a code owner March 19, 2026 23:57
Copilot AI review requested due to automatic review settings March 19, 2026 23:57
Copy link
Copy Markdown
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the repository-wide Gradle Java conventions to adjust how the Sonatype OSS Index audit task is configured, aiming to make audits more reliable across environments.

Changes:

  • Exclude compileOnly dependencies from OSS Index auditing.
  • Stop defaulting OSS Index credentials to empty strings; read credentials directly from environment variables instead.

Comment thread buildSrc/src/main/kotlin/otel.java-conventions.gradle.kts Outdated
Comment thread buildSrc/src/main/kotlin/otel.java-conventions.gradle.kts Outdated
@trask trask added this pull request to the merge queue Mar 20, 2026
Merged via the queue into open-telemetry:main with commit e875e14 Mar 20, 2026
34 of 36 checks passed
@trask trask deleted the fix-audit branch March 20, 2026 17:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants