[{"data":1,"prerenderedAt":326},["ShallowReactive",2],{"navigation_docs":3,"-reference-ecosystems":114,"-reference-ecosystems-surround":323},[4,23,85,99],{"title":5,"path":6,"stem":7,"children":8},"Getting Started","\u002Fgetting-started","1.getting-started",[9,13,18],{"title":10,"path":6,"stem":11,"icon":12},"Getting started","1.getting-started\u002Findex","i-lucide-rocket",{"title":14,"path":15,"stem":16,"icon":17},"Try the demo","\u002Fgetting-started\u002Ftry-the-demo","1.getting-started\u002F1.try-the-demo","i-lucide-monitor-play",{"title":19,"path":20,"stem":21,"icon":22},"Quickstart","\u002Fgetting-started\u002Fquickstart","1.getting-started\u002F2.quickstart","i-lucide-play",{"title":24,"path":25,"stem":26,"children":27},"Guides","\u002Fguides","2.guides",[28,31,37,42,47,53,58,63,68,74,80],{"title":24,"path":25,"stem":29,"icon":30},"2.guides\u002Findex","i-lucide-map",{"title":32,"path":33,"stem":34,"icon":35,"group":36},"Connect a GitHub repository","\u002Fguides\u002Fconnect-a-github-repository","2.guides\u002F01.connect-a-github-repository","i-lucide-git-branch","Connect a project",{"title":38,"path":39,"stem":40,"icon":41,"group":36},"Analyze a project without GitHub","\u002Fguides\u002Fanalyze-a-project-without-github","2.guides\u002F02.analyze-a-project-without-github","i-lucide-upload",{"title":43,"path":44,"stem":45,"icon":46,"group":36},"Exclude dependency scopes","\u002Fguides\u002Fexclude-dependency-scopes","2.guides\u002F04.exclude-dependency-scopes","i-lucide-filter",{"title":48,"path":49,"stem":50,"icon":51,"group":52},"Scan from GitHub Actions","\u002Fguides\u002Fscan-from-github-actions","2.guides\u002F05.scan-from-github-actions","i-lucide-workflow","Automate",{"title":54,"path":55,"stem":56,"icon":57,"group":52},"Scan from another CI","\u002Fguides\u002Fscan-from-another-ci","2.guides\u002F06.scan-from-another-ci","i-lucide-square-terminal",{"title":59,"path":60,"stem":61,"icon":62,"group":52},"Manage API keys","\u002Fguides\u002Fmanage-api-keys","2.guides\u002F07.manage-api-keys","i-lucide-key-round",{"title":64,"path":65,"stem":66,"icon":67,"group":52},"Create many projects at once","\u002Fguides\u002Fcreate-many-projects-at-once","2.guides\u002F08.create-many-projects-at-once","i-lucide-layers",{"title":69,"path":70,"stem":71,"icon":72,"group":73},"Export reports and SBOMs","\u002Fguides\u002Fexport-reports-and-sboms","2.guides\u002F11.export-reports-and-sboms","i-lucide-download","Act on the results",{"title":75,"path":76,"stem":77,"icon":78,"group":79},"Organizations and plans","\u002Fguides\u002Forganizations-and-plans","2.guides\u002F13.organizations-and-plans","i-lucide-building-2","Organization and team",{"title":81,"path":82,"stem":83,"icon":84,"group":79},"Invite your team","\u002Fguides\u002Finvite-your-team","2.guides\u002F14.invite-your-team","i-lucide-users",{"title":86,"path":87,"stem":88,"children":89},"Core Concepts","\u002Fcore-concepts","3.core-concepts",[90,94],{"title":91,"path":87,"stem":92,"icon":93},"Core concepts","3.core-concepts\u002Findex","i-lucide-lightbulb",{"title":95,"path":96,"stem":97,"icon":98},"The health score","\u002Fcore-concepts\u002Fhealth-score","3.core-concepts\u002F1.health-score","i-lucide-gauge",{"title":100,"path":101,"stem":102,"children":103},"Reference","\u002Freference","5.reference",[104,107],{"title":100,"path":101,"stem":105,"icon":106},"5.reference\u002Findex","i-lucide-book-marked",{"title":108,"path":109,"stem":110,"children":111,"icon":113},"Supported ecosystems","\u002Freference\u002Fecosystems","5.reference\u002F1.ecosystems\u002Findex",[112],{"title":108,"path":109,"stem":110,"icon":113},"i-lucide-package",{"id":115,"title":108,"body":116,"description":316,"extension":317,"links":318,"meta":319,"navigation":320,"path":109,"seo":321,"stem":110,"__hash__":322},"docs\u002F5.reference\u002F1.ecosystems\u002Findex.md",{"type":117,"value":118,"toc":308},"minimark",[119,123,127,234,237,244,248,254,260,263,267,270,297,301],[120,121,122],"p",{},"Deptools reads five ecosystems. If your project declares its dependencies\nanother way, it cannot be analyzed yet.",[124,125,108],"h2",{"id":126},"supported-ecosystems",[128,129,130,143],"table",{},[131,132,133],"thead",{},[134,135,136,140],"tr",{},[137,138,139],"th",{},"Ecosystem",[137,141,142],{},"Build files read",[144,145,146,161,178,202,218],"tbody",{},[134,147,148,155],{},[149,150,151],"td",{},[152,153,154],"strong",{},"Maven",[149,156,157],{},[158,159,160],"code",{},"pom.xml",[134,162,163,168],{},[149,164,165],{},[152,166,167],{},"Gradle",[149,169,170,173,174,177],{},[158,171,172],{},"build.gradle",", or ",[158,175,176],{},"build.gradle.kts"," for the Kotlin DSL",[134,179,180,185],{},[149,181,182],{},[152,183,184],{},"npm",[149,186,187,190,191,194,195,198,199],{},[158,188,189],{},"package.json",", with ",[158,192,193],{},"package-lock.json",", ",[158,196,197],{},"yarn.lock"," or ",[158,200,201],{},"pnpm-lock.yaml",[134,203,204,209],{},[149,205,206],{},[152,207,208],{},"sbt",[149,210,211,214,215],{},[158,212,213],{},"build.sbt",", and the Scala files under ",[158,216,217],{},"project\u002F",[134,219,220,225],{},[149,221,222],{},[152,223,224],{},"Composer",[149,226,227,230,231],{},[158,228,229],{},"composer.json"," and ",[158,232,233],{},"composer.lock",[120,235,236],{},"yarn and pnpm are read through their lockfiles. There is no separate yarn or\npnpm ecosystem to pick, both are npm projects.",[120,238,239,240,243],{},"A project analyzes the module chosen at creation, and the creation form asks you\nwhich one. A repository that holds several modules can take one project per\nmodule, or a single project on ",[152,241,242],{},"Entire repository",", which reads them all.",[124,245,247],{"id":246},"how-the-ecosystem-is-detected","How the ecosystem is detected",[120,249,250,251,253],{},"A repository can declare more than one. When it does, Deptools proposes the JVM\necosystem first, then Composer, then npm, and the ",[152,252,139],{}," field of the\ncreation form lets you pick another.",[120,255,256,257,259],{},"That order exists because a PHP application almost always ships a\n",[158,258,189],{}," for its front end assets. Testing npm first would route a\nComposer project to the wrong parser.",[120,261,262],{},"The ecosystem is fixed once the project is created. To change it, delete the\nproject and create it again.",[124,264,266],{"id":265},"what-is-read-to-resolve-versions","What is read to resolve versions",[120,268,269],{},"A build file names a dependency, and not always the version that ends up\ninstalled. How Deptools reaches the resolved version differs per ecosystem.",[271,272,273,280,286],"ul",{},[274,275,276,279],"li",{},[152,277,278],{},"Maven and Gradle"," resolve from the build files themselves. Deptools follows\nproperty variables, BOM and platform imports, version catalogs, Gradle\nconstraints, and the versions carried by plugins such as Kotlin, Spring Boot,\nQuarkus, Micronaut and Android.",[274,281,282,285],{},[152,283,284],{},"npm and Composer"," resolve from the lockfile. On npm an analysis without one\nstill runs, but Deptools then resolves the tree from the registry, so the\nversions it reports are the ones a fresh install would pick rather than the\nones you ship. Commit your lockfile to remove that gap.",[274,287,288,290,291,293,294,296],{},[152,289,208],{}," is read statically, from ",[158,292,213],{}," and the Scala files under\n",[158,295,217],{},".",[124,298,300],{"id":299},"scores-are-calibrated-per-ecosystem","Scores are calibrated per ecosystem",[120,302,303,304,296],{},"Reference values are set per ecosystem, because the populations are not\ncomparable. Maven, Gradle and sbt share one calibration, npm and Composer each\nhave their own. A 7.4 on npm and a 7.4 on Maven are not the same statement. See\n",[305,306,307],"a",{"href":96},"the health score",{"title":309,"searchDepth":310,"depth":310,"links":311},"",2,[312,313,314,315],{"id":126,"depth":310,"text":108},{"id":246,"depth":310,"text":247},{"id":265,"depth":310,"text":266},{"id":299,"depth":310,"text":300},"Which ecosystems Deptools reads, the build files it looks for, and how it picks one when a repository declares several.","md",null,{},{"icon":113},{"title":108,"description":316},"-pX6KnBu7Y11fafchM3NEaa28KJr38Dj1OcS6YSbUno",[324,318],{"title":100,"path":101,"stem":105,"description":325,"icon":106,"children":-1},"The ecosystems Deptools reads, and the build files it looks for in your repository.",1787263156233]