Merge upstream:main
This commit is contained in:
@@ -68,3 +68,114 @@ describe("ComponentDetection.makePackageUrl", () => {
|
|||||||
expect(packageUrl).toBe("");
|
expect(packageUrl).toBe("");
|
||||||
});
|
});
|
||||||
});
|
});
|
||||||
|
|
||||||
|
describe("ComponentDetection.processComponentsToManifests", () => {
|
||||||
|
test("adds package as direct dependency when no top level referrers", () => {
|
||||||
|
const componentsFound = [
|
||||||
|
{
|
||||||
|
component: {
|
||||||
|
name: "test-package",
|
||||||
|
version: "1.0.0",
|
||||||
|
packageUrl: {
|
||||||
|
Scheme: "pkg",
|
||||||
|
Type: "npm",
|
||||||
|
Name: "test-package",
|
||||||
|
Version: "1.0.0"
|
||||||
|
},
|
||||||
|
id: "test-package 1.0.0 - npm"
|
||||||
|
},
|
||||||
|
isDevelopmentDependency: false,
|
||||||
|
topLevelReferrers: [], // Empty = direct dependency
|
||||||
|
locationsFoundAt: ["package.json"]
|
||||||
|
}
|
||||||
|
];
|
||||||
|
|
||||||
|
const manifests = ComponentDetection.processComponentsToManifests(componentsFound);
|
||||||
|
|
||||||
|
expect(manifests).toHaveLength(1);
|
||||||
|
expect(manifests[0].name).toBe("package.json");
|
||||||
|
expect(manifests[0].directDependencies()).toHaveLength(1);
|
||||||
|
expect(manifests[0].indirectDependencies()).toHaveLength(0);
|
||||||
|
expect(manifests[0].countDependencies()).toBe(1);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("adds package as indirect dependency when has top level referrers", () => {
|
||||||
|
const componentsFound = [
|
||||||
|
{
|
||||||
|
component: {
|
||||||
|
name: "test-package",
|
||||||
|
version: "1.0.0",
|
||||||
|
packageUrl: {
|
||||||
|
Scheme: "pkg",
|
||||||
|
Type: "npm",
|
||||||
|
Name: "test-package",
|
||||||
|
Version: "1.0.0"
|
||||||
|
},
|
||||||
|
id: "test-package 1.0.0 - npm"
|
||||||
|
},
|
||||||
|
isDevelopmentDependency: false,
|
||||||
|
topLevelReferrers: [
|
||||||
|
{
|
||||||
|
name: "parent-package",
|
||||||
|
version: "1.0.0",
|
||||||
|
packageUrl: {
|
||||||
|
Scheme: "pkg",
|
||||||
|
Type: "npm",
|
||||||
|
Name: "parent-package",
|
||||||
|
Version: "1.0.0"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
],
|
||||||
|
locationsFoundAt: ["package.json"]
|
||||||
|
}
|
||||||
|
];
|
||||||
|
|
||||||
|
const manifests = ComponentDetection.processComponentsToManifests(componentsFound);
|
||||||
|
|
||||||
|
expect(manifests).toHaveLength(1);
|
||||||
|
expect(manifests[0].name).toBe("package.json");
|
||||||
|
expect(manifests[0].directDependencies()).toHaveLength(0);
|
||||||
|
expect(manifests[0].indirectDependencies()).toHaveLength(1);
|
||||||
|
expect(manifests[0].countDependencies()).toBe(1);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("adds package as direct dependency when top level referrer is itself", () => {
|
||||||
|
const componentsFound = [
|
||||||
|
{
|
||||||
|
component: {
|
||||||
|
name: "test-package",
|
||||||
|
version: "1.0.0",
|
||||||
|
packageUrl: {
|
||||||
|
Scheme: "pkg",
|
||||||
|
Type: "npm",
|
||||||
|
Name: "test-package",
|
||||||
|
Version: "1.0.0"
|
||||||
|
},
|
||||||
|
id: "test-package 1.0.0 - npm"
|
||||||
|
},
|
||||||
|
isDevelopmentDependency: false,
|
||||||
|
topLevelReferrers: [
|
||||||
|
{
|
||||||
|
name: "test-package",
|
||||||
|
version: "1.0.0",
|
||||||
|
packageUrl: {
|
||||||
|
Scheme: "pkg",
|
||||||
|
Type: "npm",
|
||||||
|
Name: "test-package",
|
||||||
|
Version: "1.0.0"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
],
|
||||||
|
locationsFoundAt: ["package.json"]
|
||||||
|
}
|
||||||
|
];
|
||||||
|
|
||||||
|
const manifests = ComponentDetection.processComponentsToManifests(componentsFound);
|
||||||
|
|
||||||
|
expect(manifests).toHaveLength(1);
|
||||||
|
expect(manifests[0].name).toBe("package.json");
|
||||||
|
expect(manifests[0].directDependencies()).toHaveLength(1);
|
||||||
|
expect(manifests[0].indirectDependencies()).toHaveLength(0);
|
||||||
|
expect(manifests[0].countDependencies()).toBe(1);
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|||||||
+26
-8
@@ -68,14 +68,17 @@ export default class ComponentDetection {
|
|||||||
|
|
||||||
public static async getManifestsFromResults(): Promise<Manifest[] | undefined> {
|
public static async getManifestsFromResults(): Promise<Manifest[] | undefined> {
|
||||||
core.info("Getting manifests from results");
|
core.info("Getting manifests from results");
|
||||||
|
const results = await fs.readFileSync(this.outputPath, 'utf8');
|
||||||
|
var json: any = JSON.parse(results);
|
||||||
|
return this.processComponentsToManifests(json.componentsFound);
|
||||||
|
}
|
||||||
|
|
||||||
|
public static processComponentsToManifests(componentsFound: any[]): Manifest[] {
|
||||||
// Parse the result file and add the packages to the package cache
|
// Parse the result file and add the packages to the package cache
|
||||||
const packageCache = new PackageCache();
|
const packageCache = new PackageCache();
|
||||||
const packages: Array<ComponentDetectionPackage> = [];
|
const packages: Array<ComponentDetectionPackage> = [];
|
||||||
|
|
||||||
const results = await fs.readFileSync(this.outputPath, 'utf8');
|
componentsFound.forEach(async (component: any) => {
|
||||||
|
|
||||||
var json: any = JSON.parse(results);
|
|
||||||
json.componentsFound.forEach(async (component: any) => {
|
|
||||||
// Skip components without packageUrl
|
// Skip components without packageUrl
|
||||||
if (!component.component.packageUrl) {
|
if (!component.component.packageUrl) {
|
||||||
core.debug(`Skipping component detected without packageUrl: ${JSON.stringify({
|
core.debug(`Skipping component detected without packageUrl: ${JSON.stringify({
|
||||||
@@ -113,6 +116,7 @@ export default class ComponentDetection {
|
|||||||
}
|
}
|
||||||
|
|
||||||
const referrerUrl = ComponentDetection.makePackageUrl(referrer.packageUrl);
|
const referrerUrl = ComponentDetection.makePackageUrl(referrer.packageUrl);
|
||||||
|
referrer.packageUrlString = referrerUrl
|
||||||
|
|
||||||
// Skip if the generated packageUrl is empty
|
// Skip if the generated packageUrl is empty
|
||||||
if (!referrerUrl) {
|
if (!referrerUrl) {
|
||||||
@@ -135,20 +139,32 @@ export default class ComponentDetection {
|
|||||||
const manifests: Array<Manifest> = [];
|
const manifests: Array<Manifest> = [];
|
||||||
|
|
||||||
// Check the locationsFoundAt for every package and add each as a manifest
|
// Check the locationsFoundAt for every package and add each as a manifest
|
||||||
packages.forEach(async (pkg: ComponentDetectionPackage) => {
|
this.addPackagesToManifests(packages, manifests);
|
||||||
pkg.locationsFoundAt.forEach(async (location: any) => {
|
|
||||||
|
return manifests;
|
||||||
|
}
|
||||||
|
|
||||||
|
private static addPackagesToManifests(packages: Array<ComponentDetectionPackage>, manifests: Array<Manifest>): void {
|
||||||
|
packages.forEach((pkg: ComponentDetectionPackage) => {
|
||||||
|
pkg.locationsFoundAt.forEach((location: any) => {
|
||||||
if (!manifests.find((manifest: Manifest) => manifest.name == location)) {
|
if (!manifests.find((manifest: Manifest) => manifest.name == location)) {
|
||||||
const manifest = new Manifest(location, location);
|
const manifest = new Manifest(location, location);
|
||||||
manifests.push(manifest);
|
manifests.push(manifest);
|
||||||
}
|
}
|
||||||
if (pkg.topLevelReferrers.length == 0) {
|
|
||||||
|
// Filter out self-references from topLevelReferrers
|
||||||
|
const nonSelfReferrers = pkg.topLevelReferrers.filter((referrer: any) => {
|
||||||
|
if (!referrer.packageUrlString) return false;
|
||||||
|
return referrer.packageUrlString !== pkg.packageUrlString;
|
||||||
|
});
|
||||||
|
|
||||||
|
if (nonSelfReferrers.length == 0) {
|
||||||
manifests.find((manifest: Manifest) => manifest.name == location)?.addDirectDependency(pkg, ComponentDetection.getDependencyScope(pkg));
|
manifests.find((manifest: Manifest) => manifest.name == location)?.addDirectDependency(pkg, ComponentDetection.getDependencyScope(pkg));
|
||||||
} else {
|
} else {
|
||||||
manifests.find((manifest: Manifest) => manifest.name == location)?.addIndirectDependency(pkg, ComponentDetection.getDependencyScope(pkg));
|
manifests.find((manifest: Manifest) => manifest.name == location)?.addIndirectDependency(pkg, ComponentDetection.getDependencyScope(pkg));
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
});
|
});
|
||||||
return manifests;
|
|
||||||
}
|
}
|
||||||
|
|
||||||
private static getDependencyScope(pkg: ComponentDetectionPackage) {
|
private static getDependencyScope(pkg: ComponentDetectionPackage) {
|
||||||
@@ -236,10 +252,12 @@ export default class ComponentDetection {
|
|||||||
}
|
}
|
||||||
|
|
||||||
class ComponentDetectionPackage extends Package {
|
class ComponentDetectionPackage extends Package {
|
||||||
|
public packageUrlString: string;
|
||||||
|
|
||||||
constructor(packageUrl: string, public id: string, public isDevelopmentDependency: boolean, public topLevelReferrers: [],
|
constructor(packageUrl: string, public id: string, public isDevelopmentDependency: boolean, public topLevelReferrers: [],
|
||||||
public locationsFoundAt: [], public containerDetailIds: [], public containerLayerIds: []) {
|
public locationsFoundAt: [], public containerDetailIds: [], public containerLayerIds: []) {
|
||||||
super(packageUrl);
|
super(packageUrl);
|
||||||
|
this.packageUrlString = packageUrl;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
+2
@@ -7,6 +7,8 @@ export default class ComponentDetection {
|
|||||||
static runComponentDetection(path: string): Promise<void>;
|
static runComponentDetection(path: string): Promise<void>;
|
||||||
private static getComponentDetectionParameters;
|
private static getComponentDetectionParameters;
|
||||||
static getManifestsFromResults(): Promise<Manifest[] | undefined>;
|
static getManifestsFromResults(): Promise<Manifest[] | undefined>;
|
||||||
|
static processComponentsToManifests(componentsFound: any[]): Manifest[];
|
||||||
|
private static addPackagesToManifests;
|
||||||
private static getDependencyScope;
|
private static getDependencyScope;
|
||||||
static makePackageUrl(packageUrlJson: any): string;
|
static makePackageUrl(packageUrlJson: any): string;
|
||||||
private static getLatestReleaseURL;
|
private static getLatestReleaseURL;
|
||||||
|
|||||||
+23
-9
@@ -36054,12 +36054,16 @@ class ComponentDetection {
|
|||||||
static getManifestsFromResults() {
|
static getManifestsFromResults() {
|
||||||
return __awaiter(this, void 0, void 0, function* () {
|
return __awaiter(this, void 0, void 0, function* () {
|
||||||
core.info("Getting manifests from results");
|
core.info("Getting manifests from results");
|
||||||
|
const results = yield fs_1.default.readFileSync(this.outputPath, 'utf8');
|
||||||
|
var json = JSON.parse(results);
|
||||||
|
return this.processComponentsToManifests(json.componentsFound);
|
||||||
|
});
|
||||||
|
}
|
||||||
|
static processComponentsToManifests(componentsFound) {
|
||||||
// Parse the result file and add the packages to the package cache
|
// Parse the result file and add the packages to the package cache
|
||||||
const packageCache = new dependency_submission_toolkit_1.PackageCache();
|
const packageCache = new dependency_submission_toolkit_1.PackageCache();
|
||||||
const packages = [];
|
const packages = [];
|
||||||
const results = yield fs_1.default.readFileSync(this.outputPath, 'utf8');
|
componentsFound.forEach((component) => __awaiter(this, void 0, void 0, function* () {
|
||||||
var json = JSON.parse(results);
|
|
||||||
json.componentsFound.forEach((component) => __awaiter(this, void 0, void 0, function* () {
|
|
||||||
// Skip components without packageUrl
|
// Skip components without packageUrl
|
||||||
if (!component.component.packageUrl) {
|
if (!component.component.packageUrl) {
|
||||||
core.debug(`Skipping component detected without packageUrl: ${JSON.stringify({
|
core.debug(`Skipping component detected without packageUrl: ${JSON.stringify({
|
||||||
@@ -36091,6 +36095,7 @@ class ComponentDetection {
|
|||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
const referrerUrl = ComponentDetection.makePackageUrl(referrer.packageUrl);
|
const referrerUrl = ComponentDetection.makePackageUrl(referrer.packageUrl);
|
||||||
|
referrer.packageUrlString = referrerUrl;
|
||||||
// Skip if the generated packageUrl is empty
|
// Skip if the generated packageUrl is empty
|
||||||
if (!referrerUrl) {
|
if (!referrerUrl) {
|
||||||
core.debug(`Skipping referrer with invalid packageUrl for component: ${pkg.id}`);
|
core.debug(`Skipping referrer with invalid packageUrl for component: ${pkg.id}`);
|
||||||
@@ -36110,22 +36115,30 @@ class ComponentDetection {
|
|||||||
// Create manifests
|
// Create manifests
|
||||||
const manifests = [];
|
const manifests = [];
|
||||||
// Check the locationsFoundAt for every package and add each as a manifest
|
// Check the locationsFoundAt for every package and add each as a manifest
|
||||||
packages.forEach((pkg) => __awaiter(this, void 0, void 0, function* () {
|
this.addPackagesToManifests(packages, manifests);
|
||||||
pkg.locationsFoundAt.forEach((location) => __awaiter(this, void 0, void 0, function* () {
|
return manifests;
|
||||||
|
}
|
||||||
|
static addPackagesToManifests(packages, manifests) {
|
||||||
|
packages.forEach((pkg) => {
|
||||||
|
pkg.locationsFoundAt.forEach((location) => {
|
||||||
var _a, _b;
|
var _a, _b;
|
||||||
if (!manifests.find((manifest) => manifest.name == location)) {
|
if (!manifests.find((manifest) => manifest.name == location)) {
|
||||||
const manifest = new dependency_submission_toolkit_1.Manifest(location, location);
|
const manifest = new dependency_submission_toolkit_1.Manifest(location, location);
|
||||||
manifests.push(manifest);
|
manifests.push(manifest);
|
||||||
}
|
}
|
||||||
if (pkg.topLevelReferrers.length == 0) {
|
// Filter out self-references from topLevelReferrers
|
||||||
|
const nonSelfReferrers = pkg.topLevelReferrers.filter((referrer) => {
|
||||||
|
if (!referrer.packageUrlString)
|
||||||
|
return false;
|
||||||
|
return referrer.packageUrlString !== pkg.packageUrlString;
|
||||||
|
});
|
||||||
|
if (nonSelfReferrers.length == 0) {
|
||||||
(_a = manifests.find((manifest) => manifest.name == location)) === null || _a === void 0 ? void 0 : _a.addDirectDependency(pkg, ComponentDetection.getDependencyScope(pkg));
|
(_a = manifests.find((manifest) => manifest.name == location)) === null || _a === void 0 ? void 0 : _a.addDirectDependency(pkg, ComponentDetection.getDependencyScope(pkg));
|
||||||
}
|
}
|
||||||
else {
|
else {
|
||||||
(_b = manifests.find((manifest) => manifest.name == location)) === null || _b === void 0 ? void 0 : _b.addIndirectDependency(pkg, ComponentDetection.getDependencyScope(pkg));
|
(_b = manifests.find((manifest) => manifest.name == location)) === null || _b === void 0 ? void 0 : _b.addIndirectDependency(pkg, ComponentDetection.getDependencyScope(pkg));
|
||||||
}
|
}
|
||||||
}));
|
});
|
||||||
}));
|
|
||||||
return manifests;
|
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
static getDependencyScope(pkg) {
|
static getDependencyScope(pkg) {
|
||||||
@@ -36216,6 +36229,7 @@ class ComponentDetectionPackage extends dependency_submission_toolkit_1.Package
|
|||||||
this.locationsFoundAt = locationsFoundAt;
|
this.locationsFoundAt = locationsFoundAt;
|
||||||
this.containerDetailIds = containerDetailIds;
|
this.containerDetailIds = containerDetailIds;
|
||||||
this.containerLayerIds = containerLayerIds;
|
this.containerLayerIds = containerLayerIds;
|
||||||
|
this.packageUrlString = packageUrl;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
+1
-1
File diff suppressed because one or more lines are too long
Reference in New Issue
Block a user