pub struct CheckFinding {
pub ecosystem: EcosystemId,
pub manifest_path: PathBuf,
pub dependency_name: Option<String>,
pub requirement: Option<String>,
pub category: Category,
pub code: Option<String>,
pub advisory_url: Option<String>,
pub advisory_severity: Option<VulnSeverity>,
pub severity: Severity,
pub range: Range,
pub message: String,
}Expand description
One reported issue, derived 1:1 from a Diagnostic generate_diagnostics produced.
Fields§
§ecosystem: EcosystemIdWhich ecosystem’s manifest this finding came from.
manifest_path: PathBufPath to the manifest, relative to the walked root when discovered by crate::walk.
Passed through crate::sanitize::sanitize_path_for_display (#1299) at to_finding
construction time, so a raw ANSI escape byte or bidi-override character embedded in
the walked path never reaches the table or JSON sink unescaped. Every other
deps-cli warning sink sanitizes at its own construction boundary the same way — see
that module’s doc.
dependency_name: Option<String>The dependency’s declared name, when a manifest occurrence’s range matched the
diagnostic’s own range. None for a document-level finding not anchored to one
dependency (e.g. an offline/dependency-count notice). Passed through
deps_core::lsp_helpers::redact_name_for_diagnostic (#1242, #1246), so this is
never the raw manifest value.
requirement: Option<String>The dependency’s declared version requirement, when known. Passed through
deps_core::lsp_helpers::redact_requirement_for_diagnostic (#1258, #1300), so this
is never the raw manifest value either.
category: CategoryThe classified category (see Category).
code: Option<String>The diagnostic’s own code, when it carried a string one (spec 062 review S3,
issue #1075): a vulnerability diagnostic’s code is an OSV advisory id
(RUSTSEC-.../GHSA-...), finer-grained than Self::category; the workspace’s
other stable diagnostic-code constants (UNSATISFIABLE_DIAGNOSTIC_CODE, etc.) are
1:1 with a category, so carrying them here changes nothing beyond echoing
category. None when classify fell back to matching the diagnostic’s message
text instead of its code (Outdated/Yanked/Other).
advisory_url: Option<String>The advisory’s own https://osv.dev/vulnerability/{id} page, when Self::code is
an OSV advisory id — sourced from the diagnostic’s code_description.href (already
Uri-parsed and validated by deps_core::lsp_helpers::diagnostics:: push_vulnerability_diagnostics before it ever reaches a Diagnostic), not
re-derived from code — the authoritative URL OSV itself gave us, rather than a
second, redundant formula that could drift from it. None whenever code_description
is absent (every non-advisory finding, and the rare case where OSV’s own url failed
Uri parsing upstream).
advisory_severity: Option<VulnSeverity>The OSV-derived severity bucket for Self::code, when it names an advisory this
manifest’s OSV scan actually fetched (issue #1077 C2) — looked up by advisory id from
the same scan results generate_diagnostics consumed, not re-derived from
Self::severity (the three-bucket Severity code already collapsed into is too
coarse to recover a CVSS-style grade from). None for every non-advisory finding, and
for an advisory code this run’s scan did not itself fetch (e.g. a stale code from a
formatter that does not source it from a live scan).
severity: SeverityThe diagnostic’s severity.
range: RangeThe diagnostic’s range within the manifest.
message: StringThe diagnostic’s human-readable message.
Trait Implementations§
Source§impl Clone for CheckFinding
impl Clone for CheckFinding
Auto Trait Implementations§
impl Freeze for CheckFinding
impl RefUnwindSafe for CheckFinding
impl Send for CheckFinding
impl Sync for CheckFinding
impl Unpin for CheckFinding
impl UnsafeUnpin for CheckFinding
impl UnwindSafe for CheckFinding
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more