-
Notifications
You must be signed in to change notification settings - Fork 574
io_bazel_rules_closure@1.0.0 #6142
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Conversation
|
Hello @bazelbuild/bcr-maintainers, modules without existing maintainers (io_bazel_rules_closure) have been updated in this PR. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Code Review
This pull request adds the io_bazel_rules_closure module at version 1.0.0. The overall structure adheres to the Bazel Central Registry (BCR) policies. However, there is a critical issue in MODULE.bazel regarding the use of use_repo_rule that will prevent this module from being used as a dependency. Please see the detailed comment below.
| ) | ||
|
|
||
| http_file( | ||
| name = "libpng_amd64_deb", |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Are these debs prod.dependencies? I'm asking since there is a steady volume of security issues found in these libraries and having them enter your build as an http_file dep of a ruleset would be unexpected at least for me.
Are there BCR versions of these libs that you could depend on instead?
| @@ -0,0 +1,151 @@ | |||
| module( | |||
| name = "io_bazel_rules_closure", | |||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Looking into the future, wouldn't stackb_rules_closure be a more meaningful name?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
+1 for stackb_rules_closure
Release: https://github.com/stackb/rules_closure/releases/tag/v1.0.0
Automated by Publish to BCR