Clojure dependencies are pinned
clojure/dependencies-pinned@v1
Every dependency in the manifests names a single released version, or the exact commit a git dependency builds from.
| Id | clojure/dependencies-pinned |
| Version | v1 |
| Category | clojure |
| Default severity | warning |
| Interpreter | python3 |
| Timeout | 30 seconds |
| Violations tolerated | 0 |
| Collects | clojure |
Collectors
This guardrail doesn't gather anything itself. It relies on the collectors below, which the CLI runs once per build before any check, and reads what they found from GUARDRAIL_FACTS. If a collector collects nothing, this guardrail is skipped, not failed.
| Collector | Gathers | Inputs it is given |
|---|---|---|
clojure | The Clojure build in the project directory: which tool it uses, the Clojure version it depends on, the source paths and aliases it declares, the repositories it resolves from, and every dependency with its alias, origin and whether it is pinned. | projectDir |
The inputs above are this guardrail's own inputs, passed straight through to the collector. Setting one in buildnote.json changes what is collected, and two guardrails configured the same way share a single collection.
Configuration
{
"guardrails": {
"failOn": "error",
"checks": [
{
"use": "clojure/dependencies-pinned@v1",
"severity": "warning",
"with": {
"projectDir": "."
},
"exemptions": []
}
]
}
}Inputs
| Input | Description | Default | Environment variable |
|---|---|---|---|
projectDir | Directory holding the project, relative to the directory the CLI runs in. | . | GUARDRAIL_INPUT_PROJECTDIR |
How to fix
Name a specific release, and give every git coordinate the sha it resolves to:
{:deps {cheshire/cheshire {:mvn/version "5.13.0"}
io.github.company/queue {:git/url "https://github.com/company/queue"
:git/tag "v1.4.0"
:git/sha "6f3a1c2d9b8e4f7a0c5d2e1b3a4f5c6d7e8f9a0b"}}}RELEASE, LATEST and -SNAPSHOT resolve to whatever the repository serves at the moment the build runs, and a :git/url without a :git/sha resolves to wherever the branch has moved since. Either way, the artifact you ship is not the one that was reviewed.
More in clojure
clojure/no-local-dependencies. No dependency comes from a:local/root, so the build resolves everything from this commit and not from the machine it runs on.clojure/repositories-allowed. Every Maven repository the manifest adds beyond the defaults resolves from a host on the allowed list.clojure/version-declared. The project depends on the Clojure release it builds against, and that release is no older than the configured floor.