Skip to content

Don't report Pip for conda component - #1879

Merged
Ryan Brandenburg (ryanbrandenburg) merged 3 commits into
mainfrom
users/rybrande/CondaNotPip
Sep 25, 2026
Merged

Ryan Brandenburg (ryanbrandenburg) merged 3 commits into
mainfrom
users/rybrande/CondaNotPip

Conversation

@ryanbrandenburg

@ryanbrandenburg Ryan Brandenburg (ryanbrandenburg) commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

I noticed that when I was testing things out I wasn't getting as many CondaComponents reported as I expected and realized that was because they were being reported as PipComponents. When I looked into why that was I gave this code snippet some deeper thought and decided that I don't believe it makes sense anymore.

The presence of Python as a dependency can't tell us what kind of package manager is used for a component, we already have the "manager" field for that. The current code leads to weird stuff like:

"httpcore 1.0.9 - pip [DownloadUrl:https://pkgs.dev.azure.com/msazure/_packaging/DFP/Conda/repo/conda-forge/noarch/httpcore-1.0.9-pyh29332c3_0.conda]": [
          "python 3.12.13 - Conda [Build:h8ab3286_1_cpython Channel:https://pkgs.dev.azure.com/msazure/_packaging/DFP/Conda/repo/conda-forge Subdir:linux-64]",
          "h11 0.16.0 - pip [DownloadUrl:https://pkgs.dev.azure.com/msazure/_packaging/DFP/Conda/repo/conda-forge/noarch/h11-0.16.0-pyhcf101f3_1.conda]",
          "h2 4.4.1 - pip [DownloadUrl:https://pkgs.dev.azure.com/msazure/_packaging/DFP/Conda/repo/conda-forge/noarch/h2-4.4.1-pyhcf101f3_0.conda]",
          "sniffio 1.3.1 - pip [DownloadUrl:https://pkgs.dev.azure.com/msazure/_packaging/DFP/Conda/repo/conda-forge/noarch/sniffio-1.3.1-pyhd8ed1ab_2.conda]",
          "anyio 4.14.2 - pip [DownloadUrl:https://pkgs.dev.azure.com/msazure/_packaging/DFP/Conda/repo/conda-forge/noarch/anyio-4.14.2-pyhcf101f3_0.conda]",
          "certifi 2026.7.22 - pip [DownloadUrl:https://pkgs.dev.azure.com/msazure/_packaging/DFP/Conda/repo/conda-forge/noarch/certifi-2026.7.22-pyhd8ed1ab_0.conda]"
        ],

where we've got a component which reported itself in the lockfile as "conda", is downloaded from the conda forge, and has a conda extension, but that we're reporting as pip. After my change this same dependency looks like this:

"httpcore 1.0.9 - Conda [Build:pyh29332c3_0 Channel:https://pkgs.dev.azure.com/msazure/_packaging/DFP/Conda/repo/conda-forge Subdir:noarch]": [
          "python 3.12.13 - Conda [Build:h8ab3286_1_cpython Channel:https://pkgs.dev.azure.com/msazure/_packaging/DFP/Conda/repo/conda-forge Subdir:linux-64]",
          "h11 0.16.0 - Conda [Build:pyhcf101f3_1 Channel:https://pkgs.dev.azure.com/msazure/_packaging/DFP/Conda/repo/conda-forge Subdir:noarch]",
          "h2 4.4.1 - Conda [Build:pyhcf101f3_0 Channel:https://pkgs.dev.azure.com/msazure/_packaging/DFP/Conda/repo/conda-forge Subdir:noarch]",
          "sniffio 1.3.1 - Conda [Build:pyhd8ed1ab_2 Channel:https://pkgs.dev.azure.com/msazure/_packaging/DFP/Conda/repo/conda-forge Subdir:noarch]",
          "anyio 4.14.2 - Conda [Build:pyhcf101f3_0 Channel:https://pkgs.dev.azure.com/msazure/_packaging/DFP/Conda/repo/conda-forge Subdir:noarch]",
          "certifi 2026.7.22 - Conda [Build:pyhd8ed1ab_0 Channel:https://pkgs.dev.azure.com/msazure/_packaging/DFP/Conda/repo/conda-forge Subdir:noarch]"
        ],

It's still supported for the Condalock to have pip components in it, they're just identified by "manager": "pip".

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The remaining XML summary issue is a minor documentation nit and does not block approval.

Review effort: Lite
Findings: 1 Low severity

Open (1)
What changed in this PR

Updates Conda lockfile classification to use the explicit manager field, preventing Conda packages with Python dependencies from being reported as Pip components.

Changes:

  • Classifies only manager: pip entries as PipComponent.
  • Bumps the detector version to 4.
  • Updates regression tests and circular-dependency coverage.
File Description
test/​Microsoft.ComponentDetection.Detectors.Tests/​CondaLockComponentDetectorTests.cs Updates classification and regression tests.
src/​Microsoft.ComponentDetection.Detectors/​conda/​CondaLockComponentDetector.cs Bumps the detector version.
src/​Microsoft.ComponentDetection.Detectors/​conda/​CondaDependencyResolver.cs Uses package manager metadata for component selection.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Copilot AI review requested due to automatic review settings September 25, 2026 17:14
@github-actions

Copy link
Copy Markdown

👋 Hi! It looks like you modified some files in the Detectors folder.
You may need to bump the detector versions if any of the following scenarios apply:

  • The detector detects more or fewer components than before
  • The detector generates different parent/child graph relationships than before
  • The detector generates different devDependencies values than before

If none of the above scenarios apply, feel free to ignore this comment 🙂

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

No unresolved issues were identified.

Review effort: Lite
Findings: None

Resolved since last review (1)

@ryanbrandenburg
Ryan Brandenburg (ryanbrandenburg) merged commit 6321ef1 into main Sep 25, 2026
15 of 16 checks passed
@ryanbrandenburg
Ryan Brandenburg (ryanbrandenburg) deleted the users/rybrande/CondaNotPip branch September 25, 2026 18:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants