Skip to main content

AnalysisScope

Struct AnalysisScope 

Source
pub struct AnalysisScope {
    pub licenses: bool,
    pub vulnerabilities: bool,
    pub gossip: bool,
    pub cooldown_fallback: bool,
}
Expand description

Which of analyze_manifest’s independent, network-touching phases (beyond the mandatory registry version fetch) actually run.

Code review finding 6: before this type existed, analyze_manifest always ran both the tier-3 license prefetch and the OSV scan, even for deps-cli update’s default mode — which reads neither ManifestAnalysis::licenses nor ManifestAnalysis::vulnerabilities at all — wasting a network round trip per dependency and burning shared rate-limit budgets (e.g. Swift’s 60 req/h unauthenticated GitHub budget) on every plain deps-cli update run.

§Examples

use deps_cli::analyze::AnalysisScope;

let update_default_mode = AnalysisScope::update_default();
assert!(!update_default_mode.licenses);
assert!(!update_default_mode.vulnerabilities);
assert!(update_default_mode.gossip);
assert!(update_default_mode.cooldown_fallback);

let update_security_only = AnalysisScope::vulnerabilities_only();
assert!(!update_security_only.licenses);
assert!(update_security_only.vulnerabilities);
assert!(!update_security_only.gossip);
assert!(!update_security_only.cooldown_fallback);

Fields§

§licenses: bool

Whether to run the tier-3 license prefetch (Dart/Swift/Gradle/Deno — a no-op for every other ecosystem regardless of this flag). Only crate::report::check_manifest reads license data; no update mode does.

§vulnerabilities: bool

Whether to run the OSV vulnerability scan, subject to the existing diagnostics.vulnerabilities_enabled/network.offline policy gates either way. check and update --security-only both need this; update’s default mode does not.

§gossip: bool

Whether to run the spec 074 GOSSIP prefetch, subject to the existing [gossip].enabled policy gate either way (issue #1521 item 4). Deliberately independent of [freshness].enabled — spec 074 FR-002/FR-009/NFR-004 enumerate GOSSIP’s gates exhaustively ([gossip].enabled, not offline, a deps_dev_system-covered ecosystem, a public-registry-content source) and never include freshness; GOSSIP and the local freshness.cooldown_secs heuristic are deliberately independent signals (NFR-004), mirroring deps-lsp’s own run_gossip_prefetch, which likewise gates only on is_gossip_enabled()/offline. false under update --security-only: that mode’s fix target comes from the advisory’s recommended_fix(), never the freshness/GOSSIP-filtered registry pick (FR-014), so the prefetch’s result would never be read — an avoidable network call.

§cooldown_fallback: bool

Whether to run spec 075 FR-010’s extra, uncapped OSV round verifying every occurrence’s cooldown-fallback candidate. Only true for update’s default mode: check never writes a fallback candidate (spec 075 §1 Out of Scope) and --security-only’s fix target always comes from the advisory, never a freshness/GOSSIP-filtered pick — so neither reads ManifestAnalysis::fallback_status, and running this round for them would be a wasted network call (NFR-004).

Implementations§

Source§

impl AnalysisScope

Source

pub const fn all() -> Self

Both phases run — crate::report::check_manifest’s scope, and the default for any caller that reads everything ManifestAnalysis can carry.

Source

pub const fn vulnerabilities_only() -> Self

Only the OSV scan runs — deps-cli update --security-only’s scope. gossip is false (issue #1521 item 4): see Self::gossip’s doc.

Source

pub const fn update_default() -> Self

Neither the license nor the vulnerability-classification phase runs — deps-cli update’s default-mode scope. Named for that one caller (not none(), its pre-#1517 name) since analyze_manifest still unconditionally runs the OSV latest-check (issue #1517) regardless of this scope: update’s default mode must never write a flagged/unverified latest into the manifest, so that check is not one of the two phases this scope can opt out of. gossip is true: default mode is exactly the consumer spec 074’s cooldown filter exists for. cooldown_fallback is true: spec 075’s fallback-candidate OSV round.

Trait Implementations§

Source§

impl Clone for AnalysisScope

Source§

fn clone(&self) -> Self

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Copy for AnalysisScope

Source§

impl Debug for AnalysisScope

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self> ⓘ

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self> ⓘ

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IntoEither for T

Source§

fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ

Converts self into a Left variant of Either<Self, Self> if into_left is true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
where F: FnOnce(&Self) -> bool,

Converts self into a Left variant of Either<Self, Self> if into_left(&self) returns true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

impl<T> Pointable for T

Source§

const ALIGN: usize

The alignment of pointer.
Source§

type Init = T

The type for initializers.
Source§

unsafe fn init(init: <T as Pointable>::Init) -> usize

Initializes a with the given initializer. Read more
Source§

unsafe fn deref<'a>(ptr: usize) -> &'a T

Dereferences the given pointer. Read more
Source§

unsafe fn deref_mut<'a>(ptr: usize) -> &'a mut T

Mutably dereferences the given pointer. Read more
Source§

unsafe fn drop(ptr: usize)

Drops the object pointed to by the given pointer. Read more
Source§

impl<T> PolicyExt for T
where T: ?Sized,

Source§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow only if self and other return Action::Follow. Read more
Source§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow if either self or other returns Action::Follow. Read more
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self> ⓘ
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self> ⓘ

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more