Hello Constantin,

tarcv <[email protected]> writes:

> So, what do you think about changing the Groovy build recipe to shade
> in those libraries and thus match what upstream build process does?
> And if you approve the shading, do I need to make Groovy package
> output still reference store paths of the libraries that are shaded?
> As otherwise, the only way to find out about the dependencies (for
> example, to check for usages of vulnerable packages) is to inspect the
> package recipe or Groovy build derivation.

I am not an expert on this subject, but it appears that Groovy upstream
is doing the shading of those libraries programmatically at the bytecode
level in a build step using the Jarjar tool, so my naive approach would
be to replicate this process on the Guix side, meaning declare ASM,
Antlr, Picocli as ‘native-inputs’ and introduce a ‘shading’ phase in the
build process that include those shaded libraries in the groovy compiler
output.

I haven't dig into the details so take this naive suggestion with
caution.

Thanks for working on this! Feel free to send updates on your
progress. ;-)

-- 
Mathieu Lirzin


Reply via email to