Class: Dependabot::Python::UpdateChecker

Inherits:
UpdateCheckers::Base
  • Object
show all
Extended by:
T::Sig
Defined in:
lib/dependabot/python/update_checker.rb,
lib/dependabot/python/update_checker/pip_version_resolver.rb,
lib/dependabot/python/update_checker/requirements_updater.rb,
lib/dependabot/python/update_checker/latest_version_finder.rb,
lib/dependabot/python/update_checker/pipenv_version_resolver.rb,
lib/dependabot/python/update_checker/poetry_version_resolver.rb,
lib/dependabot/python/update_checker/pip_compile_version_resolver.rb

Overview

rubocop:disable Metrics/ClassLength

Direct Known Subclasses

PoetryErrorHandler

Defined Under Namespace

Classes: LatestVersionFinder, PipCompileVersionResolver, PipVersionResolver, PipenvVersionResolver, PoetryVersionResolver, RequirementsUpdater

Constant Summary collapse

MAIN_PYPI_INDEXES =
%w(
  https://pypi.python.org/simple/
  https://pypi.org/simple/
).freeze
VERSION_REGEX =
/[0-9]+(?:\.[A-Za-z0-9\-_]+)*/

Instance Method Summary collapse

Instance Method Details

#latest_resolvable_versionObject



48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
# File 'lib/dependabot/python/update_checker.rb', line 48

def latest_resolvable_version
  return latest_resolvable_version_for_git_dependency if git_dependency?

  @latest_resolvable_version ||= T.let(
    if resolver_type == :requirements
      resolver.latest_resolvable_version
    elsif resolver_type == :pip_compile && resolver.resolvable?(version: latest_version)
      latest_version
    else
      resolver.latest_resolvable_version(
        requirement: unlocked_requirement_string
      )
    end,
    T.nilable(Gem::Version)
  )
end

#latest_resolvable_version_with_no_unlockObject



66
67
68
69
70
71
72
73
74
75
76
77
78
79
# File 'lib/dependabot/python/update_checker.rb', line 66

def latest_resolvable_version_with_no_unlock
  return T.cast(dependency.version, T.nilable(Gem::Version)) if git_dependency? && git_commit_checker.pinned?

  @latest_resolvable_version_with_no_unlock ||= T.let(
    if resolver_type == :requirements
      resolver.latest_resolvable_version_with_no_unlock
    else
      resolver.latest_resolvable_version(
        requirement: current_requirement_string
      )
    end,
    T.nilable(Gem::Version)
  )
end

#latest_versionObject



38
39
40
41
42
43
44
45
# File 'lib/dependabot/python/update_checker.rb', line 38

def latest_version
  return latest_version_for_git_dependency if git_dependency?

  @latest_version ||= T.let(
    fetch_latest_version,
    T.nilable(Gem::Version)
  )
end

#lowest_resolvable_security_fix_versionObject



87
88
89
90
91
92
93
94
# File 'lib/dependabot/python/update_checker.rb', line 87

def lowest_resolvable_security_fix_version
  raise "Dependency not vulnerable!" unless vulnerable?

  @lowest_resolvable_security_fix_version ||= T.let(
    fetch_lowest_resolvable_security_fix_version,
    T.nilable(Gem::Version)
  )
end

#lowest_security_fix_versionObject



82
83
84
# File 'lib/dependabot/python/update_checker.rb', line 82

def lowest_security_fix_version
  latest_version_finder.lowest_security_fix_version
end

#requirements_unlocked_or_can_be?Boolean

Returns:

  • (Boolean)


109
110
111
# File 'lib/dependabot/python/update_checker.rb', line 109

def requirements_unlocked_or_can_be?
  !requirements_update_strategy.lockfile_only?
end

#requirements_update_strategyObject



114
115
116
117
118
119
120
# File 'lib/dependabot/python/update_checker.rb', line 114

def requirements_update_strategy
  # If passed in as an option (in the base class) honour that option
  return @requirements_update_strategy if @requirements_update_strategy

  # Otherwise, check if this is a library or not
  library? ? RequirementsUpdateStrategy::WidenRanges : RequirementsUpdateStrategy::BumpVersions
end

#updated_requirementsObject



97
98
99
100
101
102
103
104
105
106
# File 'lib/dependabot/python/update_checker.rb', line 97

def updated_requirements
  return updated_git_requirements if git_dependency?

  RequirementsUpdater.new(
    requirements: requirements,
    latest_resolvable_version: preferred_resolvable_version&.to_s,
    update_strategy: requirements_update_strategy,
    has_lockfile: !(pipfile_lock || poetry_lock).nil?
  ).updated_requirements
end