Expand description
Vulnerability-scan target construction and fix-target-verification decision logic.
Pure classification helpers extracted from deps-lsp’s document/osv_scan.rs: deciding
which dependencies to scan and how to resolve a recommended fix target’s verification
status. The orchestration around these decisions — the phase-A/await/phase-B-commit shape,
the mid-flight staleness guard, and the OsvClient network calls themselves — stays in
deps-lsp’s run_osv_scan_phase_a/run_osv_phase_b_and_commit/
run_osv_fix_target_verification, since it owns a progress/staleness lifecycle this crate
must not know about (issue #1059).
Functions§
- apply_
live_ fix_ target_ statuses - Applies a live
deps_core::osv::OsvClient::check_candidatesresult back onto the matching dependency’sfix_target_status. - build_
candidate_ check_ targets - Builds phase B’s candidate-check targets for #1524.
- build_
latest_ check_ targets - Builds phase B.1’s latest-check targets for every dependency with a registry-cached latest (issue #1517).
- build_
scan_ targets - Builds the OSV scan targets for one manifest’s dependencies, applying the
version-selection policy from
architecture.md§3 in order: - collect_
fix_ target_ resolutions - Pure aggregation step of
run_osv_fix_target_verification: resolves every vulnerable dependency’s fix target viaresolve_fix_target. - osv_
name_ by_ key - Projects
targetsdown tokey -> osv_name.