Repository navigation
Support per-dependency package identities in Parse - #115
Open
abhinavgautam01 wants to merge 1 commit into
Open
abhinavgautam01 wants to merge 1 commit into
abhinavgautam01 wants to merge 1 commit into
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #111
Problem
Parsebuilds every dependency's PURL from the file's ecosystem and overwrites any PURL the parser supplied.Declarationsalready keeps a parser-supplied PURL, so the two collections behave differently. Mixed-ecosystem files get the wrong identity. For example,npm:lodashindeno.jsoncomes out aspkg:deno/lodashinstead ofpkg:npm/lodash.Changes
Two optional fields on
DependencyandDeclaration. Both changes are additive: noParsesignature or existing field type changes.Ecosystem stringNoPURL boolDependenciesandDeclarationsnow resolve PURLs with the same rule:NoPURLleaves the PURL empty. The entry keeps its location inSource.Ecosystem, falling back to the file's ecosystem.The existing version rule is unchanged: manifest PURLs leave out the version, lockfile and supplement PURLs include it and declaration PURLs never do. No existing parser sets these fields, so output for every parser that does not opt in is unchanged.
deno.jsonnpm:imports and thenpmsection ofdeno.locknow opt in withEcosystem: "npm". JSR packages keep thedenofallback.deno.jsonnpm:lodashpkg:deno/lodashpkg:npm/lodashdeno.locknpmlodashpkg:deno/lodash@4.17.21pkg:npm/lodash@4.17.21deno.jsonjsr:@std/pathpkg:deno/%40std%2FpathNo new coordinate normalization was added. Everything still goes through
purl.BuildPURLString. The README documents the new fields and the resolution order.Tests
All tests go through public
Parse:TestDependencyPackageIdentityandTestDeclarationPackageIdentityuse a test-only parser registered for manifest and lockfile filenames. It covers the fallback, anEcosystemoverride, an explicit PURL, aNoPURLjar URL that keeps itsSourceandNoPURLoverriding a PURL. Each case is checked with and without versions.TestManifestDependencyAndDeclarationIdentitiesMatchchecks that manifest dependencies and their declarations resolve to the same identity.TestDenoNPMImportPURLsasserts the exact PURLs fordeno.jsonanddeno.lock.Every new test fails without the
manifests.goanddeno.gochanges.go build ./...,go vet ./...,go test -race ./...andgolangci-lint runall pass.