From 28112ed57882548b9d33c159df2d3d9a17491cf3 Mon Sep 17 00:00:00 2001 From: Courtney Claessens Date: Tue, 7 Mar 2023 10:13:57 -0500 Subject: [PATCH] READY TO SHIP [2023-03-06] - Removes go.sum support in dependency graph and dependabot doc (#33112) Co-authored-by: mc <42146119+mchammer01@users.noreply.github.com> --- .../about-the-dependency-graph.md | 2 +- .../dependabot/dependabot-alerts-dependency-scope.md | 4 ++-- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/content/code-security/supply-chain-security/understanding-your-software-supply-chain/about-the-dependency-graph.md b/content/code-security/supply-chain-security/understanding-your-software-supply-chain/about-the-dependency-graph.md index c5214ea0dd87..9fd3cb232e85 100644 --- a/content/code-security/supply-chain-security/understanding-your-software-supply-chain/about-the-dependency-graph.md +++ b/content/code-security/supply-chain-security/understanding-your-software-supply-chain/about-the-dependency-graph.md @@ -86,7 +86,7 @@ The recommended formats explicitly define which versions are used for all direct {%- ifversion github-actions-in-dependency-graph %} | {% data variables.product.prodname_actions %} workflows [1] | YAML | `.yml`, `.yaml` | `.yml`, `.yaml` | {%- endif %} -| Go modules | Go | `go.sum` | `go.mod`, `go.sum` | +| Go modules | Go | `go.mod`| `go.mod`{% ifversion ghes < 3.9 or ghae < 3.9 %}, `go.sum`{% endif %} | | Maven | Java, Scala | `pom.xml` | `pom.xml` | | npm | JavaScript | `package-lock.json` | `package-lock.json`, `package.json`| | pip | Python | `requirements.txt`, `pipfile.lock` | `requirements.txt`, `pipfile`, `pipfile.lock`, `setup.py`[2] | diff --git a/data/reusables/dependabot/dependabot-alerts-dependency-scope.md b/data/reusables/dependabot/dependabot-alerts-dependency-scope.md index 4983fce6dae9..8da582f415f8 100644 --- a/data/reusables/dependabot/dependabot-alerts-dependency-scope.md +++ b/data/reusables/dependabot/dependabot-alerts-dependency-scope.md @@ -4,8 +4,8 @@ The table below summarizes whether dependency scope is supported for various eco |:---|:---:|:---:|:---|{% ifversion dependency-graph-dart-support %} | Dart | pub | pubspec.yaml | ✔ | | Dart | pub | pubspec.lock | ✔ |{% endif %} -| Go | Go modules | go.mod | No, defaults to runtime | -| Go | Go modules | go.sum | No, defaults to runtime | +| Go | Go modules | go.mod | No, defaults to runtime |{% ifversion ghes < 3.9 or ghae < 3.9 %} +| Go | Go modules | go.sum | No, defaults to runtime |{% endif %} | Java | Maven | pom.xml | ✔ `test` maps to development, else scope defaults to runtime | | JavaScript | npm | package.json | ✔ | | JavaScript | npm | package-lock.json | ✔ |