Skip to main content

deps_cli/
lib.rs

1#![recursion_limit = "256"]
2
3//! Library surface for `deps-cli`'s `check` subcommand.
4//!
5//! Split out from `main.rs` so integration tests can drive the walk/classify/report
6//! pipeline directly, without spawning a subprocess. Every version verdict is produced by
7//! calling into [`deps_engine::classify`] and [`deps_core::Ecosystem::generate_diagnostics`]
8//! — the identical path `deps-lsp` uses — so this crate never reimplements outdated/yanked/
9//! vulnerable/unsatisfiable/deprecated classification itself (spec 062 FR-005).
10
11pub mod analyze;
12pub mod cli;
13pub mod config;
14pub mod exit;
15pub mod format;
16pub mod report;
17mod sanitize;
18pub mod update;
19pub mod walk;
20
21// Wrapper exposed only under non-default `fuzzing` feature (#1404) so `fuzz/`'s
22// `deps_cli_config` target can reach the otherwise-private `deps.toml` parser; mirrors
23// `deps-gradle`'s `fuzz_parse_pom_licenses`.
24#[cfg(feature = "fuzzing")]
25#[doc(hidden)]
26pub use config::fuzz_parse_config;
27
28/// Manifest file size cap, shared by `check`'s and `update`'s manifest reads and `update`'s
29/// TOCTOU re-read (FR-019).
30///
31/// Mirrors `deps-lsp`'s `document::loader::MAX_FILE_SIZE`
32/// (`fs_probe::read_to_string_capped`'s own TOCTOU-safe cap, not reachable from this crate).
33pub const MAX_MANIFEST_FILE_SIZE: u64 = 10_000_000;