Class: Dependabot::GoModules::Package::PackageDetailsFetcher

Inherits:
Object
  • Object
show all
Extended by:
T::Sig
Defined in:
lib/dependabot/go_modules/package/package_details_fetcher.rb

Constant Summary collapse

RESOLVABILITY_ERROR_REGEXES =
T.let(
  [
    # Package url/proxy doesn't include any redirect meta tags
    /no go-import meta tags/,
    # Package url 404s
    /404 Not Found/,
    /Repository not found/,
    /unrecognized import path/,
    /malformed module path/,
    # (Private) module could not be fetched
    /module .*: git ls-remote .*: exit status 128/m
  ].freeze,
  T::Array[Regexp]
)
INVALID_VERSION_REGEX =

The module was retracted from the proxy OR the version of Go required is greater than what Dependabot supports OR other go.mod version errors

/(go: loading module retractions for)|(version "[^"]+" invalid)/m
PSEUDO_VERSION_REGEX =
/\b\d{14}-[0-9a-f]{12}$/

Instance Attribute Summary collapse

Instance Method Summary collapse

Constructor Details

#initialize(dependency:, dependency_files:, credentials:) ⇒ PackageDetailsFetcher

Returns a new instance of PackageDetailsFetcher.



48
49
50
51
52
53
54
# File 'lib/dependabot/go_modules/package/package_details_fetcher.rb', line 48

def initialize(dependency:, dependency_files:, credentials:)
  @dependency = dependency
  @dependency_files = dependency_files
  @credentials = credentials

  @source_type = T.let(nil, T.nilable(String))
end

Instance Attribute Details

#credentialsObject (readonly)

Returns the value of attribute credentials.



63
64
65
# File 'lib/dependabot/go_modules/package/package_details_fetcher.rb', line 63

def credentials
  @credentials
end

#dependencyObject (readonly)

Returns the value of attribute dependency.



57
58
59
# File 'lib/dependabot/go_modules/package/package_details_fetcher.rb', line 57

def dependency
  @dependency
end

#dependency_filesObject (readonly)

Returns the value of attribute dependency_files.



60
61
62
# File 'lib/dependabot/go_modules/package/package_details_fetcher.rb', line 60

def dependency_files
  @dependency_files
end

Instance Method Details

#fetch_available_versionsObject



67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
# File 'lib/dependabot/go_modules/package/package_details_fetcher.rb', line 67

def fetch_available_versions
  SharedHelpers.in_a_temporary_directory do
    SharedHelpers.with_git_configured(credentials: credentials) do
      manifest = parse_manifest

      # Set up an empty go.mod so 'go list -m' won't attempt to download dependencies. This
      # appears to be a side effect of operating with modules included in GOPRIVATE. We'll
      # retain any exclude directives to omit those versions.
      File.write("go.mod", "module dummy\n")
      manifest["Exclude"]&.each do |r|
        SharedHelpers.run_shell_command("go mod edit -exclude=#{r['Path']}@#{r['Version']}")
      end

      # Turn off the module proxy for private dependencies
      dependency_name = AzureDevopsPathNormalizer.normalize(dependency.name)
      versions_json = SharedHelpers.run_shell_command(
        "go list -m -versions -json #{dependency_name}",
        fingerprint: "go list -m -versions -json <dependency_name>"
      )
      version_strings = JSON.parse(versions_json)["Versions"]

      return [package_release(version: T.must(dependency.version))] if version_strings.nil?

      version_info = version_strings.select { |v| version_class.correct?(v) }
                                    .map { |version| version }

      package_releases = []

      version_info.map do |version|
        package_releases << package_release(
          version: version
        )
      end

      return package_releases
    end
  end
rescue SharedHelpers::HelperSubprocessFailed => e
  retry_count ||= 0
  retry_count += 1
  retry if transitory_failure?(e) && retry_count < 2

  ResolvabilityErrors.handle(e.message)
  [package_release(version: T.must(dependency.version))]
end

#go_modObject



122
123
124
# File 'lib/dependabot/go_modules/package/package_details_fetcher.rb', line 122

def go_mod
  @go_mod ||= T.let(dependency_files.find { |f| f.name == "go.mod" }, T.nilable(Dependabot::DependencyFile))
end

#package_details(releases) ⇒ Object



157
158
159
160
161
162
163
164
165
# File 'lib/dependabot/go_modules/package/package_details_fetcher.rb', line 157

def package_details(releases)
  @package_details ||= T.let(
    Dependabot::Package::PackageDetails.new(
      dependency: dependency,
      releases: releases.reverse.uniq(&:version)
    ),
    T.nilable(Dependabot::Package::PackageDetails)
  )
end

#package_release(version:) ⇒ Object



131
132
133
134
135
136
# File 'lib/dependabot/go_modules/package/package_details_fetcher.rb', line 131

def package_release(version:)
  Dependabot::Package::PackageRelease.new(
    version: GoModules::Version.new(version),
    details: { "version_string" => version }
  )
end

#parse_manifestObject



139
140
141
142
143
144
145
146
# File 'lib/dependabot/go_modules/package/package_details_fetcher.rb', line 139

def parse_manifest
  SharedHelpers.in_a_temporary_directory do
    File.write("go.mod", T.must(go_mod).content)
    json = SharedHelpers.run_shell_command("go mod edit -json")

    JSON.parse(json) || {}
  end
end

#transitory_failure?(error) ⇒ Boolean

Returns:

  • (Boolean)


115
116
117
118
119
# File 'lib/dependabot/go_modules/package/package_details_fetcher.rb', line 115

def transitory_failure?(error)
  return true if error.message.include?("EOF")

  error.message.include?("Internal Server Error")
end

#version_classObject



149
150
151
# File 'lib/dependabot/go_modules/package/package_details_fetcher.rb', line 149

def version_class
  dependency.version_class
end