Expand description
Verdict classification: deciding what a dependency’s status is.
Every function here answers “what is true about this dependency” — outdated, yanked,
vulnerable, unsatisfiable, deprecated, fetch-failed — from data already in hand. None of it
knows when to ask a registry, how to report progress, or what to do if its input changes
mid-flight: those are orchestration concerns each driving adapter (deps-lsp, deps-cli,
…) owns for itself. See specs/062-cli-check-mode/architecture-decision.md §3.2 for the
full split rationale (issue #1059).
Modules§
- diff
- Merging a completed registry fetch’s deprecation and no-comparable-versions findings into a document’s outcome map.
- fetch
- Registry fetch fan-out: concurrent version fetching and per-package classification.
- license
- Tier-3 license pre-fetch fan-out: adapter-agnostic dispatch to
deps_core::Ecosystem::fetch_license(issue #660/#688/#697, spec 010 plan §1 tier 3). - osv
- Vulnerability-scan target construction and fix-target-verification decision logic.
- resolved
- Lock-file and in-use dependency version resolution.