{"id":32127726,"url":"https://github.com/fabric8-analytics/fabric8-analytics-vscode-extension","last_synced_at":"2025-10-21T00:32:01.497Z","repository":{"id":40636916,"uuid":"98990237","full_name":"fabric8-analytics/fabric8-analytics-vscode-extension","owner":"fabric8-analytics","description":"Red Hat Dependency Analytics extension","archived":false,"fork":false,"pushed_at":"2025-09-26T10:05:08.000Z","size":31873,"stargazers_count":246,"open_issues_count":17,"forks_count":192,"subscribers_count":17,"default_branch":"main","last_synced_at":"2025-10-18T14:43:27.894Z","etag":null,"topics":["cve","dependency-analytics","ide-extension","insights","nvd","online-flow","security-vulnerability"],"latest_commit_sha":null,"homepage":"https://marketplace.visualstudio.com/items?itemName=redhat.fabric8-analytics","language":"TypeScript","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/fabric8-analytics.png","metadata":{"files":{"readme":"README.md","changelog":"CHANGELOG.md","contributing":"CONTRIBUTING.md","funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2017-08-01T10:39:20.000Z","updated_at":"2025-10-18T13:05:37.000Z","dependencies_parsed_at":"2023-11-15T18:29:54.758Z","dependency_job_id":"6d90cf12-a182-44ce-a97a-349524271c04","html_url":"https://github.com/fabric8-analytics/fabric8-analytics-vscode-extension","commit_stats":null,"previous_names":[],"tags_count":56,"template":false,"template_full_name":null,"purl":"pkg:github/fabric8-analytics/fabric8-analytics-vscode-extension","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/fabric8-analytics%2Ffabric8-analytics-vscode-extension","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/fabric8-analytics%2Ffabric8-analytics-vscode-extension/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/fabric8-analytics%2Ffabric8-analytics-vscode-extension/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/fabric8-analytics%2Ffabric8-analytics-vscode-extension/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/fabric8-analytics","download_url":"https://codeload.github.com/fabric8-analytics/fabric8-analytics-vscode-extension/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/fabric8-analytics%2Ffabric8-analytics-vscode-extension/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":279874575,"owners_count":26238176,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","status":"online","status_checked_at":"2025-10-19T02:00:07.647Z","response_time":64,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["cve","dependency-analytics","ide-extension","insights","nvd","online-flow","security-vulnerability"],"created_at":"2025-10-21T00:31:18.365Z","updated_at":"2025-10-21T00:32:01.491Z","avatar_url":"https://github.com/fabric8-analytics.png","language":"TypeScript","funding_links":[],"categories":[],"sub_categories":[],"readme":"# Red Hat Dependency Analytics\n\n[![Visual Studio Marketplace](https://vsmarketplacebadges.dev/version/redhat.fabric8-analytics.png)](https://marketplace.visualstudio.com/items?itemName=redhat.fabric8-analytics)\n![CI](https://github.com/fabric8-analytics/fabric8-analytics-vscode-extension/workflows/CI/badge.svg?branch=main)\n[![Codecov](https://codecov.io/gh/fabric8-analytics/fabric8-analytics-vscode-extension/branch/main/graph/badge.svg?token=rHIO4KNlJ0)](https://codecov.io/gh/fabric8-analytics/fabric8-analytics-vscode-extension)\n\n\u003cbr \u003eRed Hat's Dependency Analytics (RHDA) extension gives you awareness to security concerns within your software supply chain while you code your application.\nThe Red Hat Dependency Analytics extension uses vulnerability data sources for the most up-to-date vulnerability information available.\n\n\u003cbr \u003eDependency Analytics supports the following project ecosystems:\n- Maven\n- NPM\n- PNPM\n- Yarn (Classic / Berry)\n- Golang\n- Python\n- Gradle (Kotlin / Groovy DSL)\n\n\u003cbr \u003e**NOTE:**\nThe Red Hat Dependency Analytics extension is an online service hosted and maintained by Red Hat.\nRed Hat Dependency Analytics only accesses your manifest files to analyze your application dependencies before displaying the vulnerability report.\n\n## Table of Contents\n- [Red Hat Dependency Analytics](#red-hat-dependency-analytics)\n\t      - [Table of Contents](#table-of-contents)\n\t- [Quick start](#quick-start)\n\t- [Configuration](#configuration)\n\t\t- [Configurable parameters](#configurable-parameters)\n\t- [Features](#features)\n\t- [Using Red Hat Dependency Analytics for CI builds](#using-red-hat-dependency-analytics-for-ci-builds)\n\t- [Known issues](#known-issues)\n\t\t- [Error when using options the `Use Pip Dep Tree` and `Use Python Virtual Environment` simultaneously](#error-when-using-options-the-use-pip-dep-tree-and-use-python-virtual-environment-simultaneously)\n\t\t- [Red Hat Dependency Analytics limitations for Maven and Gradle](#red-hat-dependency-analytics-limitations-for-maven-and-gradle)\n\t- [Learn more about the Red Hat Dependency Analytics platform](#learn-more-about-the-red-hat-dependency-analytics-platform)\n\t- [Data and telemetry](#data-and-telemetry)\n\t- [Support, feedback \\\u0026 questions](#support-feedback--questions)\n\t- [License](#license)\n\n## Quick start\n\n**Prerequisites**\n\nThe extension requires the following package managers to be available in your system. You can provide the binary location in two ways:\n1. Through the system's `PATH` environment variable\n2. By configuring a specific path in the extension settings (e.g., `redHatDependencyAnalytics.mvn.executable.path`)\n\nWhen a specific path is configured in the settings, it takes precedence over the `PATH` environment variable.\n\n| Project Type | Binary | Manifest File |\n|-------------|---------|---------------|\n| Maven | `mvn` | `pom.xml` |\n| NPM | `npm` | `package.json` |\n| PNPM | `pnpm` | `package.json` |\n| Yarn | `yarn` | `package.json` |\n| Golang | `go` | `go.mod` |\n| Python | `python3/pip3` or `python/pip` | `requirements.txt` |\n| Gradle | `gradle` | `build.gradle` |\n\n**Note:** For NPM, PNPM, and Yarn projects, you can use [fnm](https://github.com/Schniz/fnm) or [nvm](https://github.com/nvm-sh/nvm) for Node.js version management. The extension will automatically detect and use the binary path from the `FNM_DIR` or `NVM_DIR` environment variables.\n\n**IMPORTANT:** \n\u003cbr \u003eVisual Studio Code by default executes binaries directly in a terminal found in your system's `PATH` environment.\nYou can configure Visual Studio Code to look somewhere else to run the necessary binaries.\nYou can configure this by accessing the [extension settings](https://code.visualstudio.com/docs/getstarted/settings).\nClick the **Workspace** tab, search for the word _executable_, and specify the absolute path to the binary file you want to use for your project.\n\n**Procedure**\n\n1. Install [Visual Studio Code](https://code.visualstudio.com/) on your workstation.\n2. After the installation finishes, open the Visual Studio Code application.\n3. From the file menu, click **View**, and click **Extensions**.\n4. Search the **Marketplace** for _Red Hat Dependency Analytics_.\n5. Click the **Install** button to install the extension.\n6. To start scanning your application for security vulnerabilities, and view the vulnerability report, you can do one of the following:\n   - Open a manifest file, hover over a dependency marked by the inline Component Analysis, indicated by the wavy-red line under a version number or dependency name, click **Quick Fix**, and click **Detailed Vulnerability Report**.\n   - Open a manifest file, and click the **pie chart** icon ![ Pie chart icon ](icon/report-icon.png).\n   - Right click on a manifest file in the **Explorer** view, and click **Red Hat Dependency Analytics Report...**.\n   - From the vulnerability pop-up alert message, click **Open detailed vulnerability report**.\n\n## Configuration\n\nThe Red Hat Dependency Analytics extension has some configurable parameters that allows you to customize its behavior according to your preferences.\n\n**Procedure**\n\n1. Open the Visual Studio Code application.\n2. From the file menu, click **View**, and click **Extensions**.\n3. Find the installed **Red Hat Dependency Analytics** extension, and click the **Gear** icon.\n4. Click **Extension Settings**.\n\n   ![Red Hat Dependency Analytics extension workspace settings](images/screenshots/extension-workspace-settings.png)\n\n### Configurable parameters\n\n#### Red Hat Dependency Analytics Report File Path:\nSpecify the local path to create the Red Hat Dependency Analytics report file.\nThe default path is `/tmp/redhatDependencyAnalyticsReport.html`.\n\n**IMPORTANT:**\n\nThe `redHatDependencyAnalyticsReportFilePath` setting name has changed to `reportFilePath`.\n\n#### Inline Vulnerability Severity Alerts:\nYou can set the vulnerability severity alert level to `Error` or `Warning` for inline notifications of detected vulnerabilities.\n\n#### Python: \n* `usePythonVirtualEnvironment` : Automates the installation of missing packages in a Python virtual environment.\n* `enablePythonBestEffortsInstallation` : Installs Python packages for the Python version is use, disregarding declared versions.\n  This configuration option requires the _Match Manifest Versions_ option set to `false`, and _Use Python Virtual Environment_ option set to `true`.\n* `usePipDepTree` : Use the `pipdeptree` command-line tool for building the Python dependency tree.\n  This can enhance analysis time.\n\n#### Golang:\n* `useGoMVS` : Use the minimal version selection algorithm to select a set of module versions to use when building Go packages.\n\n#### HTTP Proxy:\n* `httpProxy` : Configure HTTP proxy settings for the extension. There are three options available:\n  - `on`: Always use the HTTP proxy regardless of VS Code's proxy settings\n  - `off`: Never use the HTTP proxy regardless of VS Code's proxy settings\n  - `fallback`: Use VS Code's proxy settings (default behavior)\n\n#### Maven and Gradle Wrappers:\n* `preferWrapper` : Configure whether to use Maven or Gradle wrappers. There are three options available:\n  - `true`: Always use the wrapper regardless of other extensions' wrapper settings\n  - `false`: Never use the wrapper regardless of other extensions' wrapper settings\n  - `fallback`: Use the wrapper settings from the 'Maven for Java' or 'Language Support for Java(TM) by Red Hat' extensions, for Maven or Gradle wrapper settings respectively (`\"maven.executable.preferMavenWrapper\"` and `\"java.import.gradle.wrapper.enabled\"`)\n\n```json\n\"redHatDependencyAnalytics\": {\n    \"mvn\": {\n        \"preferWrapper\": \"true/false/fallback\"\n    },\n    \"gradle\": {\n        \"preferWrapper\": \"true/false/fallback\"\n    }\n}\n```\n\n#### Exclude manifests from analysis: \nSpecify glob patterns for manifests to be ignored for background analysis e.g. `**/test/**/package.json` will ignore all package.json files within `test/` or any subdirectories of it. \n\n**NOTE:** Only forward slash (`/`) is supported as a path separator. Please use forward slash as the path separator even for Windows paths.\n\n## Features\n\n- **Component analysis**\n\t\u003cbr \u003eUpon opening a manifest file, such as a `pom.xml`, `package.json`, `go.mod` or `requirements.txt` file, a vulnerability scan starts the analysis process.\n\tThe scan provides immediate inline feedback on detected security vulnerabilities for your application's, and container's dependencies.\n\tSuch dependencies are appropriately underlined in red, and hovering over it gives you a short summary of the security concern from the available data sources.\n\tThe summary has the full package name, version number, the amount of known security vulnerabilities, and the highest severity status of said vulnerabilities.\n\t\n\t**NOTE:** Add the `target` folder to your `.gitignore` file to exclude it from Git monitoring.\n\n\t![ Animated screenshot showing the inline reporting feature of Red Hat Dependency Analytics ](images/screencasts/component-analysis.gif)\n\n- **Recommendations and remediation** \n    \u003cbr \u003eAfter running a detailed analysis report on a specific component version, you can view recommendations and remediation by using the _Quick Fix..._ menu.\n\tIf there is a Red Hat recommended package version available, you can replace your version with Red Hat's version.\n\n\t![ Animated screenshot showing how to access the _Quick Fix..._ menu, and switching to a Red Hat recommended package version ](images/screencasts/quickfix.gif)\n\n\t\u003cbr \u003e**IMPORTANT:** For Maven projects only, when analyzing a `pom.xml` file.\n\tYou must configure Red Hat's generally available (GA) repository to use the recommendations or remediation.\n\tAdd this repository, `https://maven.repository.redhat.com/ga/`, to your project's configuration.\n\n- **Docker scanning**\n    \u003cbr \u003eUpon opening a Dockerfile, a vulnerability scan starts analyzing the images within the Dockerfile.\n    After the analysis finishes, you can view any recommendations and remediation by clicking the _Quick Fix..._ menu from the highlighted image name.\n\tAny recommendations for an alternative image does not replace the current image.\n\tBy clicking _Switch to..._, you go to Red Hat's Ecosystem Catalog for the recommended image.\n\n\t\u003cbr \u003eYou must have the [`syft`](https://github.com/anchore/syft#installation) and [`skopeo`](https://www.redhat.com/en/topics/containers/what-is-skopeo) binaries installed on your workstation to use the Docker scanning feature.\n\tYou can specify a specific path to these binaries, and others by settings the following parameters:\n\n\t* `syft.executable.path`: Specify the absolute path of `syft` executable\n\t* `syft.config.path`: Specify the absolute path to the Syft configuration file\n\t* `skopeo.executable.path`: Specify the absolute path of `skopeo` executable\n\t* `skopeo.config.path`: Specify the absolute path to the authentication file used by the `skopeo inspect` command\n\t* `docker.executable.path`: Specify the absolute path of `docker` executable\n\t* `podman.executable.path`: Specify the absolute path of `podman` executable\n\t* `image.platform`: Specify the platform used for multi-arch images\n  \n- **Excluding dependencies with `exhortignore`**\n\t\u003cbr \u003eYou can exclude a package from analysis by marking the package for exclusion.\n\tHow you exclude a package varies based on the your project's language:\n\n\t- **Maven**\n\t\u003cbr \u003eIf you want to ignore vulnerabilities for a dependency in a `pom.xml` file, you must add `\u003c!--exhortignore--\u003e` to the end of the line as a comment against the dependency, group id, artifact id, or version scopes of that particular dependency in the manifest file.\n\tFor example:\n    \n\t```xml\n\t\u003cdependency\u003e \u003c!--exhortignore--\u003e\n\t\t\u003cgroupId\u003e...\u003c/groupId\u003e\n\t\t\u003cartifactId\u003e...\u003c/artifactId\u003e\n\t\t\u003cversion\u003e...\u003c/version\u003e\n\t\u003c/dependency\u003e\n\t```\n\n\t- **Node**\n\t\u003cbr \u003eIf you wish to ignore vulnerabilities for a dependency in a `package.json` file, you must add `exhortignore` as a attribute-value pair.\n\tThe value for `exhortignore` is a list of comma-separated vulnerability IDs.\n\tThis list of vulnerabilities are ignored during analysis.\n\tFor example:\n\n\t```json\n\t{\n\t\t\"name\": \"sample\",\n\t\t\"version\": \"1.0.0\",\n\t\t\"description\": \"\",\n\t\t\"main\": \"index.js\",\n\t\t\"keywords\": [],\n\t\t\"author\": \"\",\n\t\t\"license\": \"ISC\",\n\t\t\"dependencies\": {\n\t\t\t\"dotenv\": \"^8.2.0\",\n\t\t\t\"express\": \"^4.17.1\",\n\t\t\t\"jsonwebtoken\": \"^8.5.1\",\n\t\t\t\"mongoose\": \"^5.9.18\"\n\t\t},\n\t\t\"exhortignore\": [\n\t\t\t\"jsonwebtoken\"\n\t\t]\n\t}\n\t```\n\n\t- **Go**\n\t\u003cbr \u003eIf you want to ignore vulnerabilities for a dependency in a `go.mod` file, you must add `// exhortignore` to the end of the line as a comment against the dependency in the manifest file.\n\tFor example:\n\n\t```go\n\trequire (\n\t\tgolang.org/x/sys v1.6.7 // exhortignore\n\t)\n\t```\n\n\t- **Python**\n\t\u003cbr \u003eIf you want to ignore vulnerabilities for a dependency in a `requirements.txt` file, you must add `# exhortignore` to the end of the line as a comment against the dependency in the manifest file.\n\tFor example:\n\n\t```python\n\trequests==2.28.1 # exhortignore\n\t```\n\n\t- **Gradle**\n    \u003cbr \u003eIf you want to ignore vulnerabilities for a dependency in a `build.gradle` file, you must add `// exhortignore` to the end of the line as a comment against the dependency in the manifest file.\n\tFor example:\n\n\t```groovy\n\tplugins {\n\t\tid 'java'\n\t}\n\n\tgroup = 'groupName'\n\tversion = 'version'\n\n\trepositories {\n\t\tmavenCentral()\n\t}\n\n\tdependencies {\n\t\timplementation \"groupId:artifactId:version\" // exhortignore\n\t}\n\n\ttest {\n\t\tuseJUnitPlatform()\n\t}\n\t```\n\n- **Excluding developmental or test dependencies**\n\t\u003cbr \u003eRed Hat Dependency Analytics does not analyze dependencies marked as `dev` or `test`, these dependencies are ignored.\n\t\n\tFor example, setting `test` in the `scope` tag within a `pom.xml` file:\n\n\t```xml\n\t\u003cdependency\u003e\n\t\t\u003cgroupId\u003e...\u003c/groupId\u003e\n\t\t\u003cartifactId\u003e...\u003c/artifactId\u003e\n\t\t\u003cversion\u003e...\u003c/version\u003e\n\t\t\u003cscope\u003etest\u003c/scope\u003e\n\t\u003c/dependency\u003e\n\t```\n\n\tFor example, setting `devDependencies` attributte in the `package.json` file:\n\t\n\t```json\n\t{\n\t\t\"name\": \"sample\",\n\t\t\"version\": \"1.0.0\",\n\t\t\"description\": \"\",\n\t\t\"main\": \"index.js\",\n\t\t\"keywords\": [],\n\t\t\"author\": \"\",\n\t\t\"license\": \"ISC\",\n\t\t\"dependencies\": {\n\t\t\t\"dotenv\": \"^8.2.0\",\n\t\t\t\"express\": \"^4.17.1\",\n\t\t\t\"jsonwebtoken\": \"^8.5.1\",\n\t\t\t\"mongoose\": \"^5.9.18\"\n\t\t},\n\t\t\"devDependencies\": {\n\t\t\t\"axios\": \"^0.19.0\"\n\t\t}\n\t}\n\t```\n\n\tFor example, setting the `exclude` attribute in the `go.mod` file:\n\n\t```go\n\texclude golang.org/x/sys v1.6.7\n\n\texclude (\n\t\tgolang.org/x/sys v1.6.7\n\t)\n\t```\n\n\tFor example, setting a dependency as test in the `build.gradle` file by placing it under one of the test configurations: `testImplementation`, `testCompileOnly`, `testRuntimeOnly`\n\n\t```groovy\n\tdependencies {\n\t\timplementation group: 'org.springframework.boot', name: 'spring-boot-starter-web', version: '2.7.4'\n\t\ttestImplementation group: 'org.springframework.boot', name: 'spring-boot-starter-test', version: '2.7.4'\n\t\ttestCompileOnly 'junit:junit:4.13.1'\n\t\ttestRuntimeOnly 'org.mockito:mockito-core:3.3.3'\n\t}\n\t```\n\n\tFor example, creating an alternative file to `requirements.txt`, like `requirements-dev.txt` or `requirements-test.txt` and adding the dev or test dependencies there instead.\n\t\n- **Red Hat Dependency Analytics report** \n\t\u003cbr \u003eThe Red Hat Dependency Analytics report is a temporary HTML file that exist if the **Red Hat Dependency Analytics Report** tab remains open.\n\tClosing the tab removes the temporary HTML file.\n\tYou can specify the file name by [modifying the _Red Hat Dependency Analytics: Red Hat Dependency Analytics Report File Path_ field](#configuration) in the extension settings.\n\n- **LLM Model safety analysis**\n\t\u003cbr\u003eUpon opening a Python file, LLM models referenced in special comment annotations within the file are scanned to surface safety metrics relating to the LLMs. For example, if you have the following comment in the file:\n\n\t```python\n\t# @rhda\n\t# model=meta-llama/Llama-3.1-8B-Instruct\n\t```\n\tLlama-3.1-8B-Instruct safetry metrics will be shown on-hover as in-editor diagnostics. Code actions will also be provided at the location of the model name which opens up a more detailed HTML report, including instructions on how to integrate known guardrails to improve certain safety metrics.\n\n- **Python and Go package manager behavior**\n    \u003cbr \u003eWhen a user requests a Python or a Go package analysis, Red Hat Dependency Analytics performs the analysis by looking at the version tags from those environments, and not from the manifest files of those environments.\n\tThis can result in the user receiving information that does not match their intended request.\n\tBecause of this behavior, Red Hat Dependency Analytics has a new configurable workspace setting.\n\tBy default, the `Match Manifest Versions` (MATCH_MANIFEST_VERSIONS) setting restricts Red Hat Dependency Analytics from doing an analysis on package versions that do not match the versions defined by the manifest files.\n\tWhen Red Hat Dependency Analytics finds a package version mis-match, an alert message asks the user to switch this setting.\n\tIf the user decides to disable this restriction, Red Hat Dependency Analytics performs the analysis on versions given by the package manager only.\n\tThis setting applies to Python and Go environments.\n\t\n\t\u003cbr \u003eAn alternative workaround exists for Python environments only.\n\tThe user can start Visual Studio Code with the [`EXHORT_PYTHON_VIRTUAL_ENV`](https://github.com/RHEcosystemAppEng/exhort-javascript-api#:~:text=EXHORT_PYTHON_VIRTUAL_ENV) variable set to `true`.\n\tDoing this allows Red Hat Dependency Analytics to install Python packages into a virtual environment to perform the analysis.\n\tThe benefit is having a clean Python environment not influenced by earlier installations, but the downside is a significantly slower analysis process.\n\n## Using Red Hat Dependency Analytics for CI builds\n\nYou can automate the analysis of your application's vulnerabilities within the build and release pipeline.\nRed Hat offers integration with these Continuous Integration (CI) platforms:\n\n- [Red Hat Dependency Analytics Tekton Task](https://hub.tekton.dev/tekton/task/redhat-dependency-analytics)\n- [Red Hat Dependency Analytics Jenkins Plugin](https://plugins.jenkins.io/redhat-dependency-analytics/)\n\n\n## Known issues\n\n### Error when using options the `Use Pip Dep Tree` and `Use Python Virtual Environment` simultaneously\n\n\u003cbr \u003eIn the Python ecosystem, when selecting both `Use Pip Dep Tree` and `Use Python Virtual Environment` options simultaneously, the application gives an error because `pipdeptree` is not configured for the Python's virtual environment.\n\n\u003cbr \u003eFurthermore, there is no practical value in using both configurations together.\nSince these options contradict each other, the expected function of the `Use Pip Dep Tree` option has not effect when used with the `Use Python Virtual Environment` option.\nThe primary goal of the `Use Pip Dep Tree` option is to optimize performance for Python version 3.11 and later.\nHowever, the `Use Python Virtual Environment` option works much slower than running in a local environment, because installations happen within the virtual environment.\nRed Hat recommends only using one of these options, depending on your specific requirements, but not both simultaneously.\n\n### Red Hat Dependency Analytics limitations for Maven and Gradle projects\n\n\u003cbr \u003eWhen a manifest includes dependencies with the `provided` scope in `Maven` or the `compileOnly` and `compileOnlyApi` configurations in `Gradle`, RHDA might not reliably detect vulnerabilities for these dependencies.\nThis is due to the nature of the scopes and configurations where the version of the dependency used during the build process might not necessarily match the version used at runtime.\nThis discrepancy occurs because the dependency is not packaged within the application's JAR file, meaning that the runtime environment must supply the necessary artifacts. This can lead to two potential issues:\n\n* `ClassNotFoundException`: If the runtime environment lacks the required artifacts on its `classpath`, the application will fail to run due to missing classes.\n* `Version Mismatch`: If the runtime environment provides different versions of the artifacts, it can cause application crashes, unexpected security vulnerabilities, or false positives in RHDA vulnerability scans.\n\n\u003cbr \u003eEnsure your runtime environment includes the correct versions of these dependencies to avoid such issues.\n\n## Learn more about the Red Hat Dependency Analytics platform\n\nThe goal of this project is to significantly enhance a developer's experience by providing helpful vulnerability insights for their applications.\n\n- [GitHub Organization](https://github.com/fabric8-analytics)\n\n## Data and telemetry\n\nThe Red Hat Dependency Analytics Extension for Visual Studio Code collects anonymous [usage data](Telemetry.md) and sends it to Red Hat servers to help improve our products and services.\nRead our [privacy statement](https://developers.redhat.com/article/tool-data-collection) to learn more.\nThis extension respects the `redhat.telemetry.enabled` setting, which you can learn more about [here](https://github.com/redhat-developer/vscode-commons#how-to-disable-telemetry-reporting).\n\n## Support, feedback \u0026 questions\n\nThere are two ways you can contact us:\n- You can reach out to us at `rhda-support@redhat.com` with any questions, feedback, and general support.\n- You can also file a [GitHub Issue](https://github.com/fabric8-analytics/fabric8-analytics-vscode-extension/issues).\n\n## License\n\nApache 2.0, See [LICENSE](LICENSE) for more information.\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Ffabric8-analytics%2Ffabric8-analytics-vscode-extension","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Ffabric8-analytics%2Ffabric8-analytics-vscode-extension","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Ffabric8-analytics%2Ffabric8-analytics-vscode-extension/lists"}