pub enum UnfixableReason {
NoVerifiedFix,
FetchFailedOrAbsent,
Yanked {
target: ConcreteVersion,
},
UnsupportedRequirementShape {
target: ConcreteVersion,
},
OversizedRequirement {
target: ConcreteVersion,
},
}Expand description
Why a --security-only candidate could not be fixed.
The three variants that reject a specific, known fix target (#1614) carry it inline, so
--security-only output can report the rejected version instead of nothing; the two that
mean no fix target was ever established carry none.
Variants§
NoVerifiedFix
No independently-verified fix target exists: no advisory has a claimable fix, the fix
target failed the safety gate, or deps_core::edit’s internal fix-target verification
could not confirm it — see deps_core::edit::VulnFixSkip (FR-010).
FetchFailedOrAbsent
The dependency’s registry fetch failed/timed out, or produced no PackageVersions
entry at all — the FR-011 two-signal, load-bearing rule.
Yanked
The fix target is present in the registry’s yanked list with a status that
deps_core::RemovalStatus::blocks_resolution (FR-012).
Fields
target: ConcreteVersionThe yanked fix target that was rejected.
UnsupportedRequirementShape
The declared requirement has a shape the formatter has no single unambiguous rewrite
for (e.g. a compound comma-separated Cargo requirement, #1566) and a requirement
matcher exists that has already confirmed the declared requirement does not admit the
fix target — distinct from Outcome::RequiresLockfileUpdate, which means the
requirement already admits the fix and nothing needs rewriting at all. Conflating the
two would tell the operator to regenerate the lock file for a dependency that is still
vulnerable (#1566 S1).
Fields
target: ConcreteVersionThe confirmed-excluded fix target.
OversizedRequirement
The declared requirement’s raw text exceeds deps_core::lsp_helpers::MAX_REQUIREMENT_LEN
(deps_core::lsp_helpers::requirement_is_oversized, #1472’s CWE-400 defense-in-depth
bound) — a size-based fail-closed guard applied before a requirement matcher is ever
compiled, never itself a confirmed exclusion. Distinct from
Self::UnsupportedRequirementShape (#1578 S1): that variant means a matcher actually
ran and confirmed the declared requirement excludes the fix target, while this one means
the matcher never ran at all, so an oversized requirement that would in fact have
admitted the fix is still reported here rather than as
Outcome::RequiresLockfileUpdate — conflating the two would let a false “confirmed
excluded” claim reach the operator for a case that was never actually checked.
Fields
target: ConcreteVersionThe fix target the oversized requirement was never checked against.
Trait Implementations§
Source§impl Clone for UnfixableReason
impl Clone for UnfixableReason
Source§impl Debug for UnfixableReason
impl Debug for UnfixableReason
impl Eq for UnfixableReason
Source§impl PartialEq for UnfixableReason
impl PartialEq for UnfixableReason
impl StructuralPartialEq for UnfixableReason
Auto Trait Implementations§
impl Freeze for UnfixableReason
impl RefUnwindSafe for UnfixableReason
impl Send for UnfixableReason
impl Sync for UnfixableReason
impl Unpin for UnfixableReason
impl UnsafeUnpin for UnfixableReason
impl UnwindSafe for UnfixableReason
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§fn equivalent(&self, key: &K) -> bool
fn equivalent(&self, key: &K) -> bool
key and return true if they are equal.Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more