Skip to main content

ManifestAnalysis

Struct ManifestAnalysis 

Source
pub struct ManifestAnalysis {
Show 20 fields pub parse_result: Box<dyn ParseResult>, pub uri: Url, pub now: PublishTime, pub ecosystem_id: EcosystemId, pub cached_versions: HashMap<PackageName, PackageVersions>, pub resolved_versions: HashMap<PackageName, ConcreteVersion>, pub resolved_version_candidates: HashMap<PackageName, Vec<ConcreteVersion>>, pub outcomes: DependencyOutcomes, pub vulnerabilities: Option<VulnerabilityMap>, pub latest_status: Option<LatestStatusMap>, pub fallback_status: Option<LatestStatusMap>, pub cooldown_fallback_view: Option<HashMap<PackageName, PackageVersions>>, pub gossip_findings: HashMap<PackageName, GossipFindings>, pub licenses: HashMap<PackageName, Vec<String>>, pub license_policy: LicensePolicy, pub license_source: LicenseSource, pub network: NetworkMode, pub fetch_failed: HashSet<PackageName>, pub registry_unreachable: bool, pub license_fetch_incomplete: bool,
}
Expand description

One manifest’s fully-assembled classification inputs.

The parsed dependencies, every lock-file/registry/OSV-derived map VersionData borrows, and the two registry/license-fetch incompleteness signals check/update both need for their own exit-code decisions.

Built by analyze_manifest; call Self::version_data to get the borrowed VersionData view deps_core::Ecosystem::generate_diagnostics and deps_core::edit::collect_update_edits/deps_core::edit::plan_vulnerability_fix all take.

Fields§

§parse_result: Box<dyn ParseResult>

The parsed manifest.

§uri: Url

The manifest’s file URI (derived from the path analyze_manifest was given).

§now: PublishTime

The instant this analysis ran, captured once (fix-cycle item 9/security L3).

analyze_manifest’s own fallback-candidate OSV round (FR-010) and deps-cli update’s planner (plan_updates) must evaluate cooldown_disposition against the SAME now — two independent PublishTime::now() calls straddling the OSV round could, under backward clock skew, let the planner see a dependency as Blocked that the OSV-gating pass never verified a fallback for (fallback_status would then read None, degrading to NotApplicable and writing an unverified fallback). Callers building plan_updates’s now argument should use this field rather than calling PublishTime::now() again.

§ecosystem_id: EcosystemId

The manifest’s ecosystem.

§cached_versions: HashMap<PackageName, PackageVersions>

Latest known versions and full version lists from the registry.

§resolved_versions: HashMap<PackageName, ConcreteVersion>

Versions actually resolved in the lock file.

§resolved_version_candidates: HashMap<PackageName, Vec<ConcreteVersion>>

Every lock-file-resolved version for a package name, when more than one is retained (issue #649).

§outcomes: DependencyOutcomes

Yanked/deprecation/fetch-failure/no-comparable-versions findings from the fetch.

§vulnerabilities: Option<VulnerabilityMap>

OSV scan results, when the scan ran (enabled and not offline).

§latest_status: Option<LatestStatusMap>

Phase B’s per-key “latest” check result (issue #1517), when the check ran (enabled and not offline) — populated regardless of AnalysisScope, since update’s default mode needs this even though it opts out of both licenses and vulnerabilities. See deps_core::osv::LatestStatusMap for the map’s fail-closed-on-absence contract.

§fallback_status: Option<LatestStatusMap>

Spec 075 FR-010: a separate OSV verdict map for every occurrence’s cooldown-fallback candidate, keyed identically to Self::latest_status but populated from a fallback-substituted version view — NEVER merged into Self::latest_status, since LatestStatusMap has no version key and a merge would silently overwrite latest’s own verdict. None when AnalysisScope::cooldown_fallback is false, the OSV check is disabled/offline, or no dependency has a stored fallback candidate to verify (NFR-004: this round costs zero extra network calls in that case).

§cooldown_fallback_view: Option<HashMap<PackageName, PackageVersions>>

Spec 075 FR-010’s fallback-substituted view of Self::cached_versions (only latest swapped for each dependency’s stored cooldown-fallback candidate, when one exists) — the exact view this OSV round already built to verify a fallback candidate against, retained here so deps-cli update’s planner (plan_updates) can reuse it instead of recomputing an identical cooldown_fallback_view from scratch (issue #1551 finding 3). Same gate as Self::fallback_status: None when AnalysisScope::cooldown_fallback is false, or no dependency’s cooldown_disposition actually differs from Self::cached_versions (NFR-004: nothing to substitute).

§gossip_findings: HashMap<PackageName, GossipFindings>

Already-computed GOSSIP findings (spec 074/075 FR-006), retained here instead of being discarded after the registry fetch — fixes check’s dead with_gossip_prefetch branch (ManifestAnalysis::version_data never called it before this field existed), so check and update consult the same deps_core::lsp_helpers::cooldown_disposition precedence end to end. Empty when GOSSIP is disabled/offline/unsupported, never absent.

§licenses: HashMap<PackageName, Vec<String>>

License data backfilled from the registry fetch (tier 1) and the tier-3 prefetch, keyed by raw package name.

§license_policy: LicensePolicy

The resolved SPDX allow/deny license policy for this run.

§license_source: LicenseSource

How license strings were sourced (registry-declared SPDX vs. free text).

§network: NetworkMode

The deps_core::NetworkMode set for this run.

§fetch_failed: HashSet<PackageName>

Raw package names whose registry fetch errored or timed out (FetchResult::fetch_failed, captured before apply_fetch_outcomes consumes it) — the two-signal input deps-cli update --security-only’s Unfixable classification needs (FR-011): a dependency is Unfixable when it appears here or has no Self::cached_versions entry.

§registry_unreachable: bool

Whether at least one dependency’s version registry fetch failed while not offline.

§license_fetch_incomplete: bool

Whether at least one dependency’s tier-3 license fetch timed out while not offline.

Implementations§

Source§

impl ManifestAnalysis

Source

pub fn version_data(&self) -> VersionData<'_>

The borrowed VersionData view over this analysis’s maps.

Source

pub fn has_unverified_latest_check( &self, formatter: &dyn EcosystemFormatter, package_filter: &[String], ignore_rules: &IgnoreRules, ) -> bool

Whether any deps_core::lsp_helpers::RequirementStatus::Outdated dependency actually in scope for this run’s plan (per package_filter/ignore_rules, issue #1517 critique S4) came back LatestVerdict::Unverified (issue #1517) — a transient OSV failure/timeout, or the check never having run at all despite being enabled. Callers (deps-cli update’s default mode) treat this the same as Self::registry_unreachable: abort the whole run rather than silently omitting just the affected dependency from the plan, since an unverifiable check must never be mistaken for a clean one.

package_filter is matched via crate::update::is_requested, and ignore_rules via crate::update::ignore::IgnoreRules::matches_name (a name-only match, deliberately not crate::update::ignore::IgnoreRules::skip_reason’s kind-scoped one: this abort-check runs before any concrete current/target pair exists to classify an UpdateKind from). A dependency this widens past scope (a kind-scoped ignore rule that would not actually have matched this update) is not a regression: deps_core::edit::collect_update_candidates applies the exact same latest_verdict gate per-candidate independently, so an unverified latest for it still surfaces as Skipped(NotSafelyEditable(LatestUnverified)) in the final plan (a nonzero exit) rather than silently vanishing — this check only controls whether the whole run aborts early with a clearer message, not whether the unverified dependency itself is ever caught.

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self> ⓘ

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self> ⓘ

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IntoEither for T

Source§

fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ

Converts self into a Left variant of Either<Self, Self> if into_left is true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
where F: FnOnce(&Self) -> bool,

Converts self into a Left variant of Either<Self, Self> if into_left(&self) returns true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

impl<T> Pointable for T

Source§

const ALIGN: usize

The alignment of pointer.
Source§

type Init = T

The type for initializers.
Source§

unsafe fn init(init: <T as Pointable>::Init) -> usize

Initializes a with the given initializer. Read more
Source§

unsafe fn deref<'a>(ptr: usize) -> &'a T

Dereferences the given pointer. Read more
Source§

unsafe fn deref_mut<'a>(ptr: usize) -> &'a mut T

Mutably dereferences the given pointer. Read more
Source§

unsafe fn drop(ptr: usize)

Drops the object pointed to by the given pointer. Read more
Source§

impl<T> PolicyExt for T
where T: ?Sized,

Source§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow only if self and other return Action::Follow. Read more
Source§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow if either self or other returns Action::Follow. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self> ⓘ
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self> ⓘ

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more