Class: Dependabot::GoModules::Package::PackageDetailsFetcher

Inherits:
Object
  • Object
show all
Extended by:
T::Sig
Defined in:
lib/dependabot/go_modules/package/package_details_fetcher.rb

Constant Summary collapse

RESOLVABILITY_ERROR_REGEXES =
T.let(
  [
    # Package url/proxy doesn't include any redirect meta tags
    /no go-import meta tags/,
    # Package url 404s
    /404 Not Found/,
    /Repository not found/,
    /unrecognized import path/,
    /malformed module path/,
    # (Private) module could not be fetched
    /module .*: git ls-remote .*: exit status 128/m
  ].freeze,
  T::Array[Regexp]
)
INVALID_VERSION_REGEX =

The module was retracted from the proxy OR the version of Go required is greater than what Dependabot supports OR other go.mod version errors

/(go: loading module retractions for)|(version "[^"]+" invalid)/m
PSEUDO_VERSION_REGEX =
/\b\d{14}-[0-9a-f]{12}$/

Instance Attribute Summary collapse

Instance Method Summary collapse

Constructor Details

#initialize(dependency:, dependency_files:, credentials:) ⇒ PackageDetailsFetcher

Returns a new instance of PackageDetailsFetcher.



48
49
50
51
52
53
54
# File 'lib/dependabot/go_modules/package/package_details_fetcher.rb', line 48

def initialize(dependency:, dependency_files:, credentials:)
  @dependency = dependency
  @dependency_files = dependency_files
  @credentials = credentials

  @source_type = T.let(nil, T.nilable(String))
end

Instance Attribute Details

#credentialsObject (readonly)

Returns the value of attribute credentials.



63
64
65
# File 'lib/dependabot/go_modules/package/package_details_fetcher.rb', line 63

def credentials
  @credentials
end

#dependencyObject (readonly)

Returns the value of attribute dependency.



57
58
59
# File 'lib/dependabot/go_modules/package/package_details_fetcher.rb', line 57

def dependency
  @dependency
end

#dependency_filesObject (readonly)

Returns the value of attribute dependency_files.



60
61
62
# File 'lib/dependabot/go_modules/package/package_details_fetcher.rb', line 60

def dependency_files
  @dependency_files
end

Instance Method Details

#fetch_available_versionsObject



67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
# File 'lib/dependabot/go_modules/package/package_details_fetcher.rb', line 67

def fetch_available_versions
  SharedHelpers.in_a_temporary_directory do
    SharedHelpers.with_git_configured(credentials: credentials) do
      manifest = parse_manifest

      # Set up an empty go.mod so 'go list -m' won't attempt to download dependencies. This
      # appears to be a side effect of operating with modules included in GOPRIVATE. We'll
      # retain any exclude directives to omit those versions.
      File.write("go.mod", "module dummy\n")
      manifest["Exclude"]&.each do |r|
        SharedHelpers.run_shell_command("go mod edit -exclude=#{r['Path']}@#{r['Version']}")
      end

      # Turn off the module proxy for private dependencies
      dependency_name = AzureDevopsPathNormalizer.normalize(dependency.name)
      versions_json = SharedHelpers.run_shell_command(
        "go list -m -versions -json #{dependency_name}",
        fingerprint: "go list -m -versions -json <dependency_name>"
      )
      version_strings = JSON.parse(versions_json)["Versions"]

      return [package_release(version: T.must(dependency.version))] if version_strings.nil?

      version_info = version_strings.select { |v| version_class.correct?(v) }
                                    .map { |version| version }

      package_releases = []

      version_info.map do |version|
        package_releases << package_release(
          version: version
        )
      end

      return package_releases
    end
  end
rescue SharedHelpers::HelperSubprocessFailed => e
  retry_count ||= 0
  retry_count += 1
  retry if transitory_failure?(e) && retry_count < 2

  ResolvabilityErrors.handle(e.message)
  [package_release(version: T.must(dependency.version))]
end

#go_modObject



122
123
124
125
126
127
128
129
130
131
132
133
134
135
# File 'lib/dependabot/go_modules/package/package_details_fetcher.rb', line 122

def go_mod
  @go_mod ||= T.let(
    begin
      req_file = dependency.requirements.first&.fetch(:file, nil)
      if req_file
        dependency_files.find { |f| f.name == req_file }
      else
        dependency_files.find { |f| f.name == "go.mod" } ||
          dependency_files.find { |f| f.name.end_with?("/go.mod") }
      end
    end,
    T.nilable(Dependabot::DependencyFile)
  )
end

#package_details(releases) ⇒ Object



168
169
170
171
172
173
174
175
176
# File 'lib/dependabot/go_modules/package/package_details_fetcher.rb', line 168

def package_details(releases)
  @package_details ||= T.let(
    Dependabot::Package::PackageDetails.new(
      dependency: dependency,
      releases: releases.reverse.uniq(&:version)
    ),
    T.nilable(Dependabot::Package::PackageDetails)
  )
end

#package_release(version:) ⇒ Object



142
143
144
145
146
147
# File 'lib/dependabot/go_modules/package/package_details_fetcher.rb', line 142

def package_release(version:)
  Dependabot::Package::PackageRelease.new(
    version: GoModules::Version.new(version),
    details: { "version_string" => version }
  )
end

#parse_manifestObject



150
151
152
153
154
155
156
157
# File 'lib/dependabot/go_modules/package/package_details_fetcher.rb', line 150

def parse_manifest
  SharedHelpers.in_a_temporary_directory do
    File.write("go.mod", T.must(go_mod).content)
    json = SharedHelpers.run_shell_command("go mod edit -json")

    JSON.parse(json) || {}
  end
end

#transitory_failure?(error) ⇒ Boolean

Returns:

  • (Boolean)


115
116
117
118
119
# File 'lib/dependabot/go_modules/package/package_details_fetcher.rb', line 115

def transitory_failure?(error)
  return true if error.message.include?("EOF")

  error.message.include?("Internal Server Error")
end

#version_classObject



160
161
162
# File 'lib/dependabot/go_modules/package/package_details_fetcher.rb', line 160

def version_class
  dependency.version_class
end