#[non_exhaustive]pub enum DependencySource {
Registry,
Git {
url: String,
rev: Option<String>,
},
Path {
path: String,
},
Url {
url: String,
},
Sdk {
sdk: String,
},
Workspace,
CustomRegistry {
url: String,
},
AlternateRegistry {
index: String,
mirrors_crates_io: bool,
},
}Expand description
Dependency source location (shared across all ecosystems).
Covers the union of all source types across Cargo, npm, PyPI, Go, Dart, Bundler, Maven, and Gradle ecosystems.
Variants (Non-exhaustive)§
This enum is marked as non-exhaustive
Registry
Default package registry (crates.io, npm, PyPI, pub.dev, rubygems.org, Maven Central).
Git
Git repository dependency.
Fields
Path
Local filesystem path dependency.
Url
Direct URL to artifact (PyPI wheels, npm tarballs).
Sdk
SDK-provided dependency (Dart: sdk: flutter).
Workspace
Workspace-inherited dependency (Cargo: workspace = true).
CustomRegistry
Custom/alternative registry, named by an unresolved alias or raw index URL
(Bundler custom sources, an unresolved Cargo registry = "my-corp").
This variant’s meaning is unchanged by AlternateRegistry’s
addition: it always means “not yet resolved to a concrete index this LSP can query” —
url may hold a bare alias ("my-corp") or a URL string, but never a value this LSP
has validated and can fetch against. See AlternateRegistry
for the resolved counterpart.
url itself is stored raw (unresolved alias or a literal registry-index, possibly
carrying user:pass@ userinfo or a credential-bearing query string) — never redact
this field in place, since dedup_dependencies_by_source’s collision check and other
equality-based logic must keep comparing the real value. DependencySource’s own
Debug impl redacts it via RedactedUrl before it can reach a log line; any
future caller rendering url into hover/diagnostics text (currently latent — nothing
does today) must redact it the same way rather than relying on Debug alone.
Fields
AlternateRegistry
A custom/alternative registry resolved to a concrete, fetchable index URL.
Distinct from CustomRegistry so “resolved” is a type-level
state instead of string-sniffing an unresolved alias vs. a URL. Produced only by a
parser that validated index against its own registry-configuration source (e.g.
deps-cargo’s .cargo/config.toml resolution) — deps-core itself never constructs
this variant. index is the sparse+ prefix-stripped, https-only index URL —
userinfo is rejected by validate_index_url before a URL can resolve to this variant,
but a credential-bearing query string is not stripped there and CAN still be present
(#935); DependencySource’s own Debug impl redacts index via RedactedUrl
so a tracing::warn!(?source, ...) call site can never leak one. index is not
itself an authorization decision — see the originating crate’s config-resolution
module for how (and whether) a request against it is authenticated.
Fields
index: StringThe resolved index URL, validated and normalized by the originating parser —
redacted only when Debug-formatted (see the variant’s own doc).
mirrors_crates_io: booltrue exactly when this source was reached via a [source.crates-io] replace-with chain (Cargo [source] mirroring, spec
.local/specs/023-cargo-custom-registries/plan-1b.md §1.3) — as opposed to an
explicit registry/registry-index naming a genuinely different, private
registry.
Affects presentation and advisory gating only, never routing: Cargo verifies
per-version checksum equality against crates.io for a mirror, so its content is
exactly as trustworthy as crates.io’s own for vulnerability-scanning and hover-link
purposes, even though the fetch itself still goes to index, not to crates.io.
See crate::lsp_helpers::SourcePolicy::source_is_public_registry_content.
Implementations§
Source§impl DependencySource
impl DependencySource
Sourcepub fn is_registry(&self) -> bool
pub fn is_registry(&self) -> bool
Returns true if this dependency comes from any registry (default or custom).
Registry dependencies support version fetching and update checks. Git, Path, Url, Sdk, and Workspace dependencies do not.
Sourcepub fn is_version_resolvable(&self) -> bool
pub fn is_version_resolvable(&self) -> bool
Returns true if this LSP can resolve version data for this source against the registry client it actually queries.
Registry resolves to the ecosystem’s default public registry
(crates.io, npm, PyPI, …), which every deps-* crate implements a
client for. CustomRegistry names a private/alternative registry
(e.g. Bundler source "https://gems.mycorp.com", Cargo
registry = "my-corp") that this LSP has no client for — known
limitation, tracked until private-registry client support exists.
Diagnostics and hover must not silently fall back to checking a
CustomRegistry dependency’s name against the public registry, so
this deliberately diverges from is_registry() and returns false
for it, alongside Git/Path/Url/Sdk/Workspace sources.
Also false for AlternateRegistry, even though it is resolved: this method answers
“does the generic Registry trait (crates.io-shaped, one client per ecosystem)
resolve this”, not “is version data reachable at all”. An ecosystem whose registry
implements per-source routing (deps-cargo’s CargoRegistry) must use
crate::lsp_helpers::SourcePolicy::can_resolve_source instead, which defaults
to this method and is the only override point — see that method’s docs.
Trait Implementations§
Source§impl Clone for DependencySource
impl Clone for DependencySource
Source§impl Debug for DependencySource
Hand-written, not derived (#935): a derived Debug would have printed Git.url,
Url.url, CustomRegistry.url, and AlternateRegistry.index raw — every one of them
can carry a credential (userinfo or a query-string secret) that never gets a chance to be
stripped, since none of these fields is validated/redacted before construction on every
code path (see DependencySource::AlternateRegistry and
DependencySource::CustomRegistry’s own docs). Any tracing::warn!(?source, ...) or
{source:?} call site — a common, idiomatic alternative to a hand-rolled Display — must
not be able to reopen this leak, so it is closed once here at the type level instead of at
each logging call site. Every variant and field is still shown (this is not a summary);
only URL-bearing field values are routed through RedactedUrl first.
impl Debug for DependencySource
Hand-written, not derived (#935): a derived Debug would have printed Git.url,
Url.url, CustomRegistry.url, and AlternateRegistry.index raw — every one of them
can carry a credential (userinfo or a query-string secret) that never gets a chance to be
stripped, since none of these fields is validated/redacted before construction on every
code path (see DependencySource::AlternateRegistry and
DependencySource::CustomRegistry’s own docs). Any tracing::warn!(?source, ...) or
{source:?} call site — a common, idiomatic alternative to a hand-rolled Display — must
not be able to reopen this leak, so it is closed once here at the type level instead of at
each logging call site. Every variant and field is still shown (this is not a summary);
only URL-bearing field values are routed through RedactedUrl first.
impl Eq for DependencySource
Source§impl PartialEq for DependencySource
impl PartialEq for DependencySource
impl StructuralPartialEq for DependencySource
Auto Trait Implementations§
impl Freeze for DependencySource
impl RefUnwindSafe for DependencySource
impl Send for DependencySource
impl Sync for DependencySource
impl Unpin for DependencySource
impl UnsafeUnpin for DependencySource
impl UnwindSafe for DependencySource
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§fn equivalent(&self, key: &K) -> bool
fn equivalent(&self, key: &K) -> bool
key and return true if they are equal.