pub struct ManifestAnalysis {Show 20 fields
pub parse_result: Box<dyn ParseResult>,
pub uri: Url,
pub now: PublishTime,
pub ecosystem_id: EcosystemId,
pub cached_versions: HashMap<PackageName, PackageVersions>,
pub resolved_versions: HashMap<PackageName, ConcreteVersion>,
pub resolved_version_candidates: HashMap<PackageName, Vec<ConcreteVersion>>,
pub outcomes: DependencyOutcomes,
pub vulnerabilities: Option<VulnerabilityMap>,
pub latest_status: Option<LatestStatusMap>,
pub fallback_status: Option<LatestStatusMap>,
pub cooldown_fallback_view: Option<HashMap<PackageName, PackageVersions>>,
pub gossip_findings: HashMap<PackageName, GossipFindings>,
pub licenses: HashMap<PackageName, Vec<String>>,
pub license_policy: LicensePolicy,
pub license_source: LicenseSource,
pub network: NetworkMode,
pub fetch_failed: HashSet<PackageName>,
pub registry_unreachable: bool,
pub license_fetch_incomplete: bool,
}Expand description
One manifest’s fully-assembled classification inputs.
The parsed dependencies, every lock-file/registry/OSV-derived map VersionData
borrows, and the two registry/license-fetch incompleteness signals check/update both
need for their own exit-code decisions.
Built by analyze_manifest; call Self::version_data to get the borrowed
VersionData view deps_core::Ecosystem::generate_diagnostics and
deps_core::edit::collect_update_edits/deps_core::edit::plan_vulnerability_fix all
take.
Fields§
§parse_result: Box<dyn ParseResult>The parsed manifest.
uri: UrlThe manifest’s file URI (derived from the path analyze_manifest was given).
now: PublishTimeThe instant this analysis ran, captured once (fix-cycle item 9/security L3).
analyze_manifest’s own fallback-candidate OSV round (FR-010) and deps-cli update’s
planner (plan_updates) must evaluate cooldown_disposition against the SAME now —
two independent PublishTime::now() calls straddling the OSV round could, under
backward clock skew, let the planner see a dependency as Blocked that the OSV-gating
pass never verified a fallback for (fallback_status would then read None, degrading
to NotApplicable and writing an unverified fallback). Callers building plan_updates’s
now argument should use this field rather than calling PublishTime::now() again.
ecosystem_id: EcosystemIdThe manifest’s ecosystem.
cached_versions: HashMap<PackageName, PackageVersions>Latest known versions and full version lists from the registry.
resolved_versions: HashMap<PackageName, ConcreteVersion>Versions actually resolved in the lock file.
resolved_version_candidates: HashMap<PackageName, Vec<ConcreteVersion>>Every lock-file-resolved version for a package name, when more than one is retained (issue #649).
outcomes: DependencyOutcomesYanked/deprecation/fetch-failure/no-comparable-versions findings from the fetch.
vulnerabilities: Option<VulnerabilityMap>OSV scan results, when the scan ran (enabled and not offline).
latest_status: Option<LatestStatusMap>Phase B’s per-key “latest” check result (issue #1517), when the check ran (enabled and
not offline) — populated regardless of AnalysisScope, since update’s default mode
needs this even though it opts out of both licenses and vulnerabilities. See
deps_core::osv::LatestStatusMap for the map’s fail-closed-on-absence contract.
fallback_status: Option<LatestStatusMap>Spec 075 FR-010: a separate OSV verdict map for every occurrence’s cooldown-fallback
candidate, keyed identically to Self::latest_status but populated from a
fallback-substituted version view — NEVER merged into Self::latest_status, since
LatestStatusMap has no version key and a merge would silently overwrite latest’s
own verdict. None when AnalysisScope::cooldown_fallback is false, the OSV
check is disabled/offline, or no dependency has a stored fallback candidate to verify
(NFR-004: this round costs zero extra network calls in that case).
cooldown_fallback_view: Option<HashMap<PackageName, PackageVersions>>Spec 075 FR-010’s fallback-substituted view of Self::cached_versions (only
latest swapped for each dependency’s stored cooldown-fallback candidate, when one
exists) — the exact view this OSV round already built to verify a fallback candidate
against, retained here so deps-cli update’s planner (plan_updates) can reuse it
instead of recomputing an identical cooldown_fallback_view from scratch (issue
#1551 finding 3). Same gate as Self::fallback_status: None when
AnalysisScope::cooldown_fallback is false, or no dependency’s cooldown_disposition
actually differs from Self::cached_versions (NFR-004: nothing to substitute).
gossip_findings: HashMap<PackageName, GossipFindings>Already-computed GOSSIP findings (spec 074/075 FR-006), retained here instead of being
discarded after the registry fetch — fixes check’s dead with_gossip_prefetch branch
(ManifestAnalysis::version_data never called it before this field existed), so check
and update consult the same deps_core::lsp_helpers::cooldown_disposition precedence
end to end. Empty when GOSSIP is disabled/offline/unsupported, never absent.
licenses: HashMap<PackageName, Vec<String>>License data backfilled from the registry fetch (tier 1) and the tier-3 prefetch, keyed by raw package name.
license_policy: LicensePolicyThe resolved SPDX allow/deny license policy for this run.
license_source: LicenseSourceHow license strings were sourced (registry-declared SPDX vs. free text).
network: NetworkModeThe deps_core::NetworkMode set for this run.
fetch_failed: HashSet<PackageName>Raw package names whose registry fetch errored or timed out (FetchResult::fetch_failed,
captured before apply_fetch_outcomes consumes it) — the two-signal input
deps-cli update --security-only’s Unfixable classification needs (FR-011): a
dependency is Unfixable when it appears here or has no Self::cached_versions
entry.
registry_unreachable: boolWhether at least one dependency’s version registry fetch failed while not offline.
license_fetch_incomplete: boolWhether at least one dependency’s tier-3 license fetch timed out while not offline.
Implementations§
Source§impl ManifestAnalysis
impl ManifestAnalysis
Sourcepub fn version_data(&self) -> VersionData<'_>
pub fn version_data(&self) -> VersionData<'_>
The borrowed VersionData view over this analysis’s maps.
Sourcepub fn has_unverified_latest_check(
&self,
formatter: &dyn EcosystemFormatter,
package_filter: &[String],
ignore_rules: &IgnoreRules,
) -> bool
pub fn has_unverified_latest_check( &self, formatter: &dyn EcosystemFormatter, package_filter: &[String], ignore_rules: &IgnoreRules, ) -> bool
Whether any deps_core::lsp_helpers::RequirementStatus::Outdated dependency actually
in scope for this run’s plan (per package_filter/ignore_rules, issue #1517 critique
S4) came back LatestVerdict::Unverified (issue #1517) — a transient OSV
failure/timeout, or the check never having run at all despite being enabled. Callers
(deps-cli update’s default mode) treat this the same as
Self::registry_unreachable: abort the whole run rather than silently omitting just
the affected dependency from the plan, since an unverifiable check must never be
mistaken for a clean one.
package_filter is matched via crate::update::is_requested, and ignore_rules via
crate::update::ignore::IgnoreRules::matches_name (a name-only match, deliberately not
crate::update::ignore::IgnoreRules::skip_reason’s kind-scoped one: this abort-check
runs before any concrete current/target pair exists to classify an UpdateKind from).
A dependency this widens past scope (a kind-scoped ignore rule that would not actually
have matched this update) is not a regression: deps_core::edit::collect_update_candidates
applies the exact same latest_verdict gate per-candidate independently, so an
unverified latest for it still surfaces as Skipped(NotSafelyEditable(LatestUnverified))
in the final plan (a nonzero exit) rather than silently vanishing — this check only
controls whether the whole run aborts early with a clearer message, not whether the
unverified dependency itself is ever caught.
Auto Trait Implementations§
impl !RefUnwindSafe for ManifestAnalysis
impl !UnwindSafe for ManifestAnalysis
impl Freeze for ManifestAnalysis
impl Send for ManifestAnalysis
impl Sync for ManifestAnalysis
impl Unpin for ManifestAnalysis
impl UnsafeUnpin for ManifestAnalysis
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more