pub struct AnalysisScope {
pub licenses: bool,
pub vulnerabilities: bool,
pub gossip: bool,
pub cooldown_fallback: bool,
}Expand description
Which of analyze_manifest’s independent, network-touching phases (beyond the mandatory
registry version fetch) actually run.
Code review finding 6: before this type existed, analyze_manifest always ran both the
tier-3 license prefetch and the OSV scan, even for deps-cli update’s default mode — which
reads neither ManifestAnalysis::licenses nor ManifestAnalysis::vulnerabilities at all —
wasting a network round trip per dependency and burning shared rate-limit budgets (e.g.
Swift’s 60 req/h unauthenticated GitHub budget) on every plain deps-cli update run.
§Examples
use deps_cli::analyze::AnalysisScope;
let update_default_mode = AnalysisScope::update_default();
assert!(!update_default_mode.licenses);
assert!(!update_default_mode.vulnerabilities);
assert!(update_default_mode.gossip);
assert!(update_default_mode.cooldown_fallback);
let update_security_only = AnalysisScope::vulnerabilities_only();
assert!(!update_security_only.licenses);
assert!(update_security_only.vulnerabilities);
assert!(!update_security_only.gossip);
assert!(!update_security_only.cooldown_fallback);Fields§
§licenses: boolWhether to run the tier-3 license prefetch (Dart/Swift/Gradle/Deno — a no-op for every
other ecosystem regardless of this flag). Only crate::report::check_manifest reads
license data; no update mode does.
vulnerabilities: boolWhether to run the OSV vulnerability scan, subject to the existing
diagnostics.vulnerabilities_enabled/network.offline policy gates either way. check
and update --security-only both need this; update’s default mode does not.
gossip: boolWhether to run the spec 074 GOSSIP prefetch, subject to the existing [gossip].enabled
policy gate either way (issue #1521 item 4). Deliberately independent of
[freshness].enabled — spec 074 FR-002/FR-009/NFR-004 enumerate GOSSIP’s gates
exhaustively ([gossip].enabled, not offline, a deps_dev_system-covered ecosystem, a
public-registry-content source) and never include freshness; GOSSIP and the local
freshness.cooldown_secs heuristic are deliberately independent signals (NFR-004),
mirroring deps-lsp’s own run_gossip_prefetch, which likewise gates only on
is_gossip_enabled()/offline. false under update --security-only: that mode’s fix
target comes from the advisory’s recommended_fix(), never the freshness/GOSSIP-filtered
registry pick (FR-014), so the prefetch’s result would never be read — an avoidable
network call.
cooldown_fallback: boolWhether to run spec 075 FR-010’s extra, uncapped OSV round verifying every occurrence’s
cooldown-fallback candidate. Only true for update’s default mode: check never
writes a fallback candidate (spec 075 §1 Out of Scope) and --security-only’s fix
target always comes from the advisory, never a freshness/GOSSIP-filtered pick — so
neither reads ManifestAnalysis::fallback_status, and running this round for them
would be a wasted network call (NFR-004).
Implementations§
Source§impl AnalysisScope
impl AnalysisScope
Sourcepub const fn all() -> Self
pub const fn all() -> Self
Both phases run — crate::report::check_manifest’s scope, and the default for any
caller that reads everything ManifestAnalysis can carry.
Sourcepub const fn vulnerabilities_only() -> Self
pub const fn vulnerabilities_only() -> Self
Only the OSV scan runs — deps-cli update --security-only’s scope. gossip is false
(issue #1521 item 4): see Self::gossip’s doc.
Sourcepub const fn update_default() -> Self
pub const fn update_default() -> Self
Neither the license nor the vulnerability-classification phase runs —
deps-cli update’s default-mode scope. Named for that one caller (not none(),
its pre-#1517 name) since analyze_manifest still unconditionally runs the OSV
latest-check (issue #1517) regardless of this scope: update’s default mode
must never write a flagged/unverified latest into the manifest, so that check is
not one of the two phases this scope can opt out of. gossip is true: default mode
is exactly the consumer spec 074’s cooldown filter exists for. cooldown_fallback is
true: spec 075’s fallback-candidate OSV round.
Trait Implementations§
Source§impl Clone for AnalysisScope
impl Clone for AnalysisScope
impl Copy for AnalysisScope
Auto Trait Implementations§
impl Freeze for AnalysisScope
impl RefUnwindSafe for AnalysisScope
impl Send for AnalysisScope
impl Sync for AnalysisScope
impl Unpin for AnalysisScope
impl UnsafeUnpin for AnalysisScope
impl UnwindSafe for AnalysisScope
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more