[{"data":1,"prerenderedAt":687},["ShallowReactive",2],{"navigation_docs":3,"-guides-exclude-dependency-scopes":114,"-guides-exclude-dependency-scopes-surround":682},[4,23,85,99],{"title":5,"path":6,"stem":7,"children":8},"Getting Started","\u002Fgetting-started","1.getting-started",[9,13,18],{"title":10,"path":6,"stem":11,"icon":12},"Getting started","1.getting-started\u002Findex","i-lucide-rocket",{"title":14,"path":15,"stem":16,"icon":17},"Try the demo","\u002Fgetting-started\u002Ftry-the-demo","1.getting-started\u002F1.try-the-demo","i-lucide-monitor-play",{"title":19,"path":20,"stem":21,"icon":22},"Quickstart","\u002Fgetting-started\u002Fquickstart","1.getting-started\u002F2.quickstart","i-lucide-play",{"title":24,"path":25,"stem":26,"children":27},"Guides","\u002Fguides","2.guides",[28,31,37,42,47,53,58,63,68,74,80],{"title":24,"path":25,"stem":29,"icon":30},"2.guides\u002Findex","i-lucide-map",{"title":32,"path":33,"stem":34,"icon":35,"group":36},"Connect a GitHub repository","\u002Fguides\u002Fconnect-a-github-repository","2.guides\u002F01.connect-a-github-repository","i-lucide-git-branch","Connect a project",{"title":38,"path":39,"stem":40,"icon":41,"group":36},"Analyze a project without GitHub","\u002Fguides\u002Fanalyze-a-project-without-github","2.guides\u002F02.analyze-a-project-without-github","i-lucide-upload",{"title":43,"path":44,"stem":45,"icon":46,"group":36},"Exclude dependency scopes","\u002Fguides\u002Fexclude-dependency-scopes","2.guides\u002F04.exclude-dependency-scopes","i-lucide-filter",{"title":48,"path":49,"stem":50,"icon":51,"group":52},"Scan from GitHub Actions","\u002Fguides\u002Fscan-from-github-actions","2.guides\u002F05.scan-from-github-actions","i-lucide-workflow","Automate",{"title":54,"path":55,"stem":56,"icon":57,"group":52},"Scan from another CI","\u002Fguides\u002Fscan-from-another-ci","2.guides\u002F06.scan-from-another-ci","i-lucide-square-terminal",{"title":59,"path":60,"stem":61,"icon":62,"group":52},"Manage API keys","\u002Fguides\u002Fmanage-api-keys","2.guides\u002F07.manage-api-keys","i-lucide-key-round",{"title":64,"path":65,"stem":66,"icon":67,"group":52},"Create many projects at once","\u002Fguides\u002Fcreate-many-projects-at-once","2.guides\u002F08.create-many-projects-at-once","i-lucide-layers",{"title":69,"path":70,"stem":71,"icon":72,"group":73},"Export reports and SBOMs","\u002Fguides\u002Fexport-reports-and-sboms","2.guides\u002F11.export-reports-and-sboms","i-lucide-download","Act on the results",{"title":75,"path":76,"stem":77,"icon":78,"group":79},"Organizations and plans","\u002Fguides\u002Forganizations-and-plans","2.guides\u002F13.organizations-and-plans","i-lucide-building-2","Organization and team",{"title":81,"path":82,"stem":83,"icon":84,"group":79},"Invite your team","\u002Fguides\u002Finvite-your-team","2.guides\u002F14.invite-your-team","i-lucide-users",{"title":86,"path":87,"stem":88,"children":89},"Core Concepts","\u002Fcore-concepts","3.core-concepts",[90,94],{"title":91,"path":87,"stem":92,"icon":93},"Core concepts","3.core-concepts\u002Findex","i-lucide-lightbulb",{"title":95,"path":96,"stem":97,"icon":98},"The health score","\u002Fcore-concepts\u002Fhealth-score","3.core-concepts\u002F1.health-score","i-lucide-gauge",{"title":100,"path":101,"stem":102,"children":103},"Reference","\u002Freference","5.reference",[104,107],{"title":100,"path":101,"stem":105,"icon":106},"5.reference\u002Findex","i-lucide-book-marked",{"title":108,"path":109,"stem":110,"children":111,"icon":113},"Supported ecosystems","\u002Freference\u002Fecosystems","5.reference\u002F1.ecosystems\u002Findex",[112],{"title":108,"path":109,"stem":110,"icon":113},"i-lucide-package",{"id":115,"title":43,"body":116,"description":675,"extension":676,"links":677,"meta":678,"navigation":679,"path":44,"seo":680,"stem":45,"__hash__":681},"docs\u002F2.guides\u002F04.exclude-dependency-scopes.md",{"type":117,"value":118,"toc":665},"minimark",[119,123,126,131,134,232,235,239,242,305,317,320,383,391,395,398,501,504,531,535,556,563,576,580,583,646,649,653],[120,121,122],"p",{},"Every project decides, when it is created, which dependency scopes it analyzes.\nThe default excludes your test tooling and nothing else. This page explains what\na scope is, what each ecosystem offers, what is worth excluding, and why a\ndependency you expected is not in your graph.",[120,124,125],{},"The choice cannot be changed later, so make it before you confirm the project.",[127,128,130],"h2",{"id":129},"what-a-scope-is","What a scope is",[120,132,133],{},"A scope is the label your build file puts on a dependency to say when it is\nneeded: to compile, at runtime, only to run tests. Each ecosystem writes it in\nits own way.",[135,136,137,150],"table",{},[138,139,140],"thead",{},[141,142,143,147],"tr",{},[144,145,146],"th",{},"Ecosystem",[144,148,149],{},"Where the scope is written",[151,152,153,171,189,203,217],"tbody",{},[141,154,155,159],{},[156,157,158],"td",{},"Maven",[156,160,161,162,166,167,170],{},"the ",[163,164,165],"code",{},"\u003Cscope>"," tag of the dependency, plus the ",[163,168,169],{},"\u003Coptional>"," flag",[141,172,173,176],{},[156,174,175],{},"Gradle",[156,177,178,179,182,183,182,186],{},"the configuration name, ",[163,180,181],{},"implementation",", ",[163,184,185],{},"testImplementation",[163,187,188],{},"kapt",[141,190,191,194],{},[156,192,193],{},"npm",[156,195,196,197,182,200],{},"the block that holds the entry, ",[163,198,199],{},"dependencies",[163,201,202],{},"devDependencies",[141,204,205,208],{},[156,206,207],{},"sbt",[156,209,210,211,182,214],{},"the configuration suffix, ",[163,212,213],{},"% Test",[163,215,216],{},"% Provided",[141,218,219,222],{},[156,220,221],{},"Composer",[156,223,224,225,228,229],{},"the block, ",[163,226,227],{},"require"," or ",[163,230,231],{},"require-dev",[120,233,234],{},"Deptools maps every declaration onto one scope key, then filters on that key\nwhile reading your build file. An excluded dependency never enters the graph, and neither does anything involved in analysis or scoring.",[127,236,238],{"id":237},"what-is-excluded-by-default","What is excluded by default",[120,240,241],{},"The creation form starts with only your test\u002Fdev tooling excluded. Everything else is\nanalyzed.",[135,243,244,256],{},[138,245,246],{},[141,247,248,250,253],{},[144,249,146],{},[144,251,252],{},"Scopes offered",[144,254,255],{},"Excluded by default",[151,257,258,268,277,287,295],{},[141,259,260,262,265],{},[156,261,158],{},[156,263,264],{},"Compile, Runtime, Provided, Test, Optional",[156,266,267],{},"Test",[141,269,270,272,275],{},[156,271,175],{},[156,273,274],{},"Compile, Runtime Only, Compile Only, Annotation Processor, Test, Optional",[156,276,267],{},[141,278,279,281,284],{},[156,280,193],{},[156,282,283],{},"Production, Development, Optional, Peer",[156,285,286],{},"Development",[141,288,289,291,293],{},[156,290,207],{},[156,292,264],{},[156,294,267],{},[141,296,297,299,302],{},[156,298,221],{},[156,300,301],{},"Require, Require Dev",[156,303,304],{},"Require Dev",[120,306,307,308,312,313,316],{},"In the creation form, under ",[309,310,311],"strong",{},"Dependency scopes to analyze",", a checked box means\nthe scope is analyzed. The two most common choices are shown directly, and the\nrest sit under ",[309,314,315],{},"Advanced scopes",".",[120,318,319],{},"Four things the table does not show:",[321,322,323,330,340,370],"ul",{},[324,325,326,329],"li",{},[309,327,328],{},"Provided and Compile Only are analyzed."," A dependency supplied by your\ncontainer or your application server still executes in production, so a\nvulnerability on it is real. You have to uncheck it deliberately.",[324,331,332,339],{},[309,333,334,335,338],{},"Maven ",[163,336,337],{},"system"," is never analyzed",", whatever you check. It points at a JAR\nfile on a local path, which no registry can resolve.",[324,341,342,345,346,349,350,182,353,356,357,360,361,364,365,356,367,369],{},[309,343,344],{},"Composer platform packages are never analyzed",", whatever you check. ",[163,347,348],{},"php",",\n",[163,351,352],{},"ext-*",[163,354,355],{},"lib-*"," and ",[163,358,359],{},"composer-*"," describe the runtime your code needs, not\npackages a registry resolves. The rule is structural, a requirement with no\n",[163,362,363],{},"\u002F"," is a platform package, and it applies to ",[163,366,227],{},[163,368,231],{},"\nalike. The analysis reports no error for them, so their absence is expected.",[324,371,372,375,376,379,380],{},[309,373,374],{},"The API applies no default."," This column describes the form alone. A project\ncreated through the API with no ",[163,377,378],{},"excluded_scopes"," analyzes every scope, test\ntooling included. See ",[381,382,64],"a",{"href":65},[384,385],"u-color-mode-image",{"alt":386,"className":387,"dark":389,"light":390},"Dependency scope selector with the advanced scopes expanded and a warning badge on the unchecked Compile scope",[388],"wide-capture","\u002Fimages\u002Fdocs\u002Fguides\u002Fexclude-dependency-scopes-1-advanced-scopes-dark.webp","\u002Fimages\u002Fdocs\u002Fguides\u002Fexclude-dependency-scopes-1-advanced-scopes-light.webp",[127,392,394],{"id":393},"choose-your-exclusions","Choose your exclusions",[120,396,397],{},"One question decides most cases: does this dependency run in production? If it\ndoes, analyze it.",[135,399,400,410],{},[138,401,402],{},[141,403,404,407],{},[144,405,406],{},"Scope",[144,408,409],{},"What to do",[151,411,412,425,438,451,461,471,481],{},[141,413,414,422],{},[156,415,416,182,418,182,420],{},[309,417,267],{},[309,419,286],{},[309,421,304],{},[156,423,424],{},"Leave it excluded. It never ships. Include it if you also want to track your build and test tooling, which is a real attack surface, but expect a much larger graph and a score that mixes both.",[141,426,427,435],{},[156,428,429,182,432],{},[309,430,431],{},"Provided",[309,433,434],{},"Compile Only",[156,436,437],{},"Leave it included. Your code runs against those APIs in production, the container only supplies the implementation.",[141,439,440,448],{},[156,441,442,182,445],{},[309,443,444],{},"Runtime",[309,446,447],{},"Runtime Only",[156,449,450],{},"Leave it included. A JDBC driver ships with your application.",[141,452,453,458],{},[156,454,455],{},[309,456,457],{},"Annotation Processor",[156,459,460],{},"Exclude it if you only measure what ships. Code generators run at build time and are not on the runtime classpath.",[141,462,463,468],{},[156,464,465],{},[309,466,467],{},"Optional",[156,469,470],{},"On the JVM it marks a dependency your consumers will not inherit, but which is still on your own classpath. On npm it marks platform specific binaries, installed whenever they can be. Exclude it when you publish a library and want to count what your consumers actually receive.",[141,472,473,478],{},[156,474,475],{},[309,476,477],{},"Peer",[156,479,480],{},"Provided by the project that installs yours. Exclude it when you publish a library.",[141,482,483,494],{},[156,484,485,182,488,182,491],{},[309,486,487],{},"Compile",[309,489,490],{},"Production",[309,492,493],{},"Require",[156,495,496,497,500],{},"Never uncheck it. The form flags it with ",[163,498,499],{},"removes most deps",", and an analysis without it measures nothing.",[120,502,503],{},"Excluding a scope narrows what the analysis sees. It does not make a project\nsafer. Two projects that exclude different scopes are not comparable either,\nsince their scores are computed on different graphs.",[505,506,507,508,510,511,513,514,182,517,513,519,182,521,513,523,526,527,530],"note",{},"Through the API, ",[163,509,378],{}," takes a scope key, not the label used on this\npage. ",[163,512,286],{}," is ",[163,515,516],{},"dev",[163,518,304],{},[163,520,231],{},[163,522,457],{},[163,524,525],{},"annotationProcessor",". The keys of the five vocabularies are listed\nin ",[381,528,529],{"href":65},"create many projects at once",", the only\nendpoint that accepts the field.",[127,532,534],{"id":533},"exclusions-are-set-once","Exclusions are set once",[120,536,537,538,182,541,544,545,548,549,552,553,555],{},"The scope selection is fixed at creation, on GitHub projects and on CI upload\nprojects alike. ",[309,539,540],{},"Settings",[309,542,543],{},"General"," shows it under ",[309,546,547],{},"Dependency scope\nconfiguration",", analyzed scopes on one side and excluded ones struck through on\nthe other, above the line ",[309,550,551],{},"Fixed at project creation",". An update through the\nAPI that carries ",[163,554,378],{}," is refused.",[120,557,558,559,562],{},"The selection is part of what identifies a project configuration, together with\nthe repository, the branch, the module and the build system. So the same build\nfile can be analyzed twice, side by side, by two projects with different\nexclusions: one that measures what you ship, one that also measures your test\ntooling. Only an identical configuration is refused, with ",[309,560,561],{},"A project with this\nrepository configuration already exists in this organization",". Each project\ncounts toward the limit of your plan.",[120,564,565,566,182,569,572,573,316],{},"Elsewhere in the app, the current selection is summarized in one line on the\nproject card, in the project list, in the project header and on the dashboard:\n",[163,567,568],{},"All scopes included",[163,570,571],{},"Test scope excluded",", or ",[163,574,575],{},"2 scopes excluded",[127,577,579],{"id":578},"why-a-dependency-is-missing-from-your-graph","Why a dependency is missing from your graph",[120,581,582],{},"Work down this list, in order:",[584,585,586,597,603,612,628,634,640],"ol",{},[324,587,588,591,592,182,594,596],{},[309,589,590],{},"It is declared in an excluded scope."," Open ",[309,593,540],{},[309,595,543],{}," and\nread the excluded side. This is the answer most of the time.",[324,598,599,602],{},[309,600,601],{},"It is only reached through an excluded dependency."," Exclusion removes the\nwhole subtree, not just the declaration.",[324,604,605,611],{},[309,606,607,608,610],{},"It is a Maven ",[163,609,337],{}," dependency."," Never analyzed, and not a checkbox.",[324,613,614,617,618,182,620,182,622,624,625,627],{},[309,615,616],{},"It is a Composer platform package."," ",[163,619,348],{},[163,621,352],{},[163,623,355],{}," and\n",[163,626,359],{}," are never analyzed, and no analysis error is reported for them.",[324,629,630,633],{},[309,631,632],{},"It is declared in another module."," The project analyzes the module chosen\nat creation.",[324,635,636,639],{},[309,637,638],{},"It is declared on another branch."," The project follows the branch chosen\nat creation.",[324,641,642,645],{},[309,643,644],{},"Deptools could not resolve it."," The analysis errors reported on the\nOverview tab name the cause.",[120,647,648],{},"The reverse case has one common cause. Filtering happens per declaration, so a\npackage declared both in an analyzed scope and in an excluded one stays in the\ngraph, and so does a package that an analyzed dependency pulls in on its own.\nExcluding a scope removes declarations, never a package by name.",[127,650,652],{"id":651},"next-steps","Next steps",[321,654,655,660],{},[324,656,657,659],{},[381,658,32],{"href":33}," for the\nthree other settings that are fixed at creation.",[324,661,662,664],{},[381,663,95],{"href":96}," for what the dependencies you\nkeep are measured on.",{"title":666,"searchDepth":667,"depth":667,"links":668},"",2,[669,670,671,672,673,674],{"id":129,"depth":667,"text":130},{"id":237,"depth":667,"text":238},{"id":393,"depth":667,"text":394},{"id":533,"depth":667,"text":534},{"id":578,"depth":667,"text":579},{"id":651,"depth":667,"text":652},"Control your dependency graph scope. Choose which dependency scopes are included in your analysis and score.","md",null,{},{"icon":46,"group":36},{"title":43,"description":675},"ZEESk9nwXZ69Urf-kxxqpbDxLI5FVF32BjfK8QcuTdE",[683,685],{"title":38,"path":39,"stem":40,"description":684,"icon":41,"group":36,"children":-1},"Push your build files from any pipeline when your code does not live on GitHub.com.",{"title":48,"path":49,"stem":50,"description":686,"icon":51,"group":52,"children":-1},"Add the Deptools action to a workflow and fail the build when quality gates are not met.",1787263156893]