Expand description
Shared parse -> lockfile -> fetch -> OSV pipeline.
Extracted out of crate::report::check_manifest (spec 062) so deps-cli update (spec
068, #1329) can reuse the identical classification inputs check builds, without
duplicating any of it.
check_manifest is now analyze_manifest followed by
generate_diagnostics/to_finding — no behavior change to check itself.
Structs§
- Analysis
Scope - Which of
analyze_manifest’s independent, network-touching phases (beyond the mandatory registry version fetch) actually run. - Manifest
Analysis - One manifest’s fully-assembled classification inputs.
Functions§
- analyze_
manifest - Parses
content, resolves in-use/lock-file versions, and fetches latest registry versions.