Skip to main content

Module osv

Module osv 

Source
Expand description

Vulnerability-scan target construction and fix-target-verification decision logic.

Pure classification helpers extracted from deps-lsp’s document/osv_scan.rs: deciding which dependencies to scan and how to resolve a recommended fix target’s verification status. The orchestration around these decisions — the phase-A/await/phase-B-commit shape, the mid-flight staleness guard, and the OsvClient network calls themselves — stays in deps-lsp’s run_osv_scan_phase_a/run_osv_phase_b_and_commit/ run_osv_fix_target_verification, since it owns a progress/staleness lifecycle this crate must not know about (issue #1059).

Functions§

apply_live_fix_target_statuses
Applies a live deps_core::osv::OsvClient::check_candidates result back onto the matching dependency’s fix_target_status.
build_candidate_check_targets
Builds phase B’s candidate-check targets for #1524.
build_latest_check_targets
Builds phase B.1’s latest-check targets for every dependency with a registry-cached latest (issue #1517).
build_scan_targets
Builds the OSV scan targets for one manifest’s dependencies, applying the version-selection policy from architecture.md §3 in order:
collect_fix_target_resolutions
Pure aggregation step of run_osv_fix_target_verification: resolves every vulnerable dependency’s fix target via resolve_fix_target.
osv_name_by_key
Projects targets down to key -> osv_name.