Skip to content

Support per-dependency package identities in Parse - #115

Open
abhinavgautam01 wants to merge 1 commit into
git-pkgs:mainfrom
abhinavgautam01:dependency-package-identity
Open

abhinavgautam01 wants to merge 1 commit into
git-pkgs:mainfrom
abhinavgautam01:dependency-package-identity

Conversation

@abhinavgautam01

Copy link
Copy Markdown
Contributor

Fixes #111

Problem

Parse builds every dependency's PURL from the file's ecosystem and overwrites any PURL the parser supplied. Declarations already keeps a parser-supplied PURL, so the two collections behave differently. Mixed-ecosystem files get the wrong identity. For example, npm:lodash in deno.json comes out as pkg:deno/lodash instead of pkg:npm/lodash.

Changes

Two optional fields on Dependency and Declaration. Both changes are additive: no Parse signature or existing field type changes.

field meaning
Ecosystem string PURL type when it differs from the file's ecosystem. Empty means the file's ecosystem.
NoPURL bool Source-only entry with no known package identity, such as a direct download URL.

Dependencies and Declarations now resolve PURLs with the same rule:

  1. NoPURL leaves the PURL empty. The entry keeps its location in Source.
  2. A parser-supplied PURL is preserved as written.
  3. Otherwise the PURL is built from Ecosystem, falling back to the file's ecosystem.

The existing version rule is unchanged: manifest PURLs leave out the version, lockfile and supplement PURLs include it and declaration PURLs never do. No existing parser sets these fields, so output for every parser that does not opt in is unchanged.

deno.json npm: imports and the npm section of deno.lock now opt in with Ecosystem: "npm". JSR packages keep the deno fallback.

entry before after
deno.json npm:lodash pkg:deno/lodash pkg:npm/lodash
deno.lock npm lodash pkg:deno/lodash@4.17.21 pkg:npm/lodash@4.17.21
deno.json jsr:@std/path pkg:deno/%40std%2Fpath unchanged

No new coordinate normalization was added. Everything still goes through purl.BuildPURLString. The README documents the new fields and the resolution order.

Tests

All tests go through public Parse:

  • TestDependencyPackageIdentity and TestDeclarationPackageIdentity use a test-only parser registered for manifest and lockfile filenames. It covers the fallback, an Ecosystem override, an explicit PURL, a NoPURL jar URL that keeps its Source and NoPURL overriding a PURL. Each case is checked with and without versions.
  • TestManifestDependencyAndDeclarationIdentitiesMatch checks that manifest dependencies and their declarations resolve to the same identity.
  • TestDenoNPMImportPURLs asserts the exact PURLs for deno.json and deno.lock.

Every new test fails without the manifests.go and deno.go changes. go build ./..., go vet ./..., go test -race ./... and golangci-lint run all pass.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Support per-dependency package identities in mixed-ecosystem manifests

1 participant