Hello Constantin, tarcv <[email protected]> writes:
> So, what do you think about changing the Groovy build recipe to shade > in those libraries and thus match what upstream build process does? > And if you approve the shading, do I need to make Groovy package > output still reference store paths of the libraries that are shaded? > As otherwise, the only way to find out about the dependencies (for > example, to check for usages of vulnerable packages) is to inspect the > package recipe or Groovy build derivation. I am not an expert on this subject, but it appears that Groovy upstream is doing the shading of those libraries programmatically at the bytecode level in a build step using the Jarjar tool, so my naive approach would be to replicate this process on the Guix side, meaning declare ASM, Antlr, Picocli as ‘native-inputs’ and introduce a ‘shading’ phase in the build process that include those shaded libraries in the groovy compiler output. I haven't dig into the details so take this naive suggestion with caution. Thanks for working on this! Feel free to send updates on your progress. ;-) -- Mathieu Lirzin
