Class: Dependabot::NpmAndYarn::DependencyGrapher::PnpmRelationshipResolver
- Inherits:
-
Object
- Object
- Dependabot::NpmAndYarn::DependencyGrapher::PnpmRelationshipResolver
- Extended by:
- T::Sig
- Defined in:
- lib/dependabot/npm_and_yarn/dependency_grapher/pnpm_relationship_resolver.rb
Instance Method Summary collapse
-
#initialize(lockfile) ⇒ PnpmRelationshipResolver
constructor
A new instance of PnpmRelationshipResolver.
- #relationships ⇒ Object
Constructor Details
#initialize(lockfile) ⇒ PnpmRelationshipResolver
Returns a new instance of PnpmRelationshipResolver.
14 15 16 |
# File 'lib/dependabot/npm_and_yarn/dependency_grapher/pnpm_relationship_resolver.rb', line 14 def initialize(lockfile) @lockfile = lockfile end |
Instance Method Details
#relationships ⇒ Object
19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 |
# File 'lib/dependabot/npm_and_yarn/dependency_grapher/pnpm_relationship_resolver.rb', line 19 def relationships parsed = YAML.safe_load(T.must(@lockfile.content)) || {} # v9+ uses "snapshots" for resolved dependency details; v6 uses "packages" entries = parsed.fetch("snapshots", nil) || parsed.fetch("packages", {}) entries.each_with_object({}) do |(key, details), rels| next unless details.is_a?(Hash) # Keys are "/name@version" (v6) or "name@version" (v9) name_version = key.sub(%r{^/}, "") children = details.fetch("dependencies", {}) next if children.nil? || children.empty? # Strip any pnpm suffix metadata (e.g., parenthesized peer dep info) name_version = name_version.sub(/\(.*\)$/, "") # pnpm dependencies are already resolved: {"name": "version"} # Strip any peer metadata suffixes like "7.49.0(react@18.2.0)" resolved_children = children.filter_map do |child_name, child_version| clean_version = child_version.to_s.sub(/\(.*\)$/, "") next if clean_version.empty? "#{child_name}@#{clean_version}" end rels[name_version] ||= [] rels[name_version].concat(resolved_children).uniq! end end |