Class: Dependabot::GoModules::Package::PackageDetailsFetcher

Inherits:
Object
  • Object
show all
Extended by:
T::Sig
Defined in:
lib/dependabot/go_modules/package/package_details_fetcher.rb

Constant Summary collapse

RESOLVABILITY_ERROR_REGEXES =
T.let(
  [
    # Package url/proxy doesn't include any redirect meta tags
    /no go-import meta tags/,
    # Package url 404s
    /404 Not Found/,
    /Repository not found/,
    /unrecognized import path/,
    /malformed module path/,
    # (Private) module could not be fetched
    /module .*: git ls-remote .*: exit status 128/m
  ].freeze,
  T::Array[Regexp]
)
INVALID_VERSION_REGEX =

The module was retracted from the proxy OR the version of Go required is greater than what Dependabot supports OR other go.mod version errors

/(go: loading module retractions for)|(version "[^"]+" invalid)/m
PSEUDO_VERSION_REGEX =
/\b\d{14}-[0-9a-f]{12}$/

Instance Attribute Summary collapse

Instance Method Summary collapse

Constructor Details

#initialize(dependency:, dependency_files:, credentials:) ⇒ PackageDetailsFetcher

Returns a new instance of PackageDetailsFetcher.



47
48
49
50
51
52
53
# File 'lib/dependabot/go_modules/package/package_details_fetcher.rb', line 47

def initialize(dependency:, dependency_files:, credentials:)
  @dependency = dependency
  @dependency_files = dependency_files
  @credentials = credentials

  @source_type = T.let(nil, T.nilable(String))
end

Instance Attribute Details

#credentialsObject (readonly)

Returns the value of attribute credentials.



62
63
64
# File 'lib/dependabot/go_modules/package/package_details_fetcher.rb', line 62

def credentials
  @credentials
end

#dependencyObject (readonly)

Returns the value of attribute dependency.



56
57
58
# File 'lib/dependabot/go_modules/package/package_details_fetcher.rb', line 56

def dependency
  @dependency
end

#dependency_filesObject (readonly)

Returns the value of attribute dependency_files.



59
60
61
# File 'lib/dependabot/go_modules/package/package_details_fetcher.rb', line 59

def dependency_files
  @dependency_files
end

Instance Method Details

#fetch_available_versionsObject



66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
# File 'lib/dependabot/go_modules/package/package_details_fetcher.rb', line 66

def fetch_available_versions
  SharedHelpers.in_a_temporary_directory do
    SharedHelpers.with_git_configured(credentials: credentials) do
      manifest = parse_manifest

      # Set up an empty go.mod so 'go list -m' won't attempt to download dependencies. This
      # appears to be a side effect of operating with modules included in GOPRIVATE. We'll
      # retain any exclude directives to omit those versions.
      File.write("go.mod", "module dummy\n")
      manifest["Exclude"]&.each do |r|
        SharedHelpers.run_shell_command("go mod edit -exclude=#{r['Path']}@#{r['Version']}")
      end

      # Turn off the module proxy for private dependencies
      versions_json = SharedHelpers.run_shell_command(
        "go list -m -versions -json #{dependency.name}",
        fingerprint: "go list -m -versions -json <dependency_name>"
      )
      version_strings = JSON.parse(versions_json)["Versions"]

      return [package_release(version: T.must(dependency.version))] if version_strings.nil?

      version_info = version_strings.select { |v| version_class.correct?(v) }
                                    .map { |version| version }

      package_releases = []

      version_info.map do |version|
        package_releases << package_release(
          version: version
        )
      end

      return package_releases
    end
  end
rescue SharedHelpers::HelperSubprocessFailed => e
  retry_count ||= 0
  retry_count += 1
  retry if transitory_failure?(e) && retry_count < 2

  ResolvabilityErrors.handle(e.message)
  [package_release(version: T.must(dependency.version))]
end

#go_modObject



120
121
122
# File 'lib/dependabot/go_modules/package/package_details_fetcher.rb', line 120

def go_mod
  @go_mod ||= T.let(dependency_files.find { |f| f.name == "go.mod" }, T.nilable(Dependabot::DependencyFile))
end

#package_details(releases) ⇒ Object



155
156
157
158
159
160
161
162
163
# File 'lib/dependabot/go_modules/package/package_details_fetcher.rb', line 155

def package_details(releases)
  @package_details ||= T.let(
    Dependabot::Package::PackageDetails.new(
      dependency: dependency,
      releases: releases.reverse.uniq(&:version)
    ),
    T.nilable(Dependabot::Package::PackageDetails)
  )
end

#package_release(version:) ⇒ Object



129
130
131
132
133
134
# File 'lib/dependabot/go_modules/package/package_details_fetcher.rb', line 129

def package_release(version:)
  Dependabot::Package::PackageRelease.new(
    version: GoModules::Version.new(version),
    details: { "version_string" => version }
  )
end

#parse_manifestObject



137
138
139
140
141
142
143
144
# File 'lib/dependabot/go_modules/package/package_details_fetcher.rb', line 137

def parse_manifest
  SharedHelpers.in_a_temporary_directory do
    File.write("go.mod", T.must(go_mod).content)
    json = SharedHelpers.run_shell_command("go mod edit -json")

    JSON.parse(json) || {}
  end
end

#transitory_failure?(error) ⇒ Boolean

Returns:

  • (Boolean)


113
114
115
116
117
# File 'lib/dependabot/go_modules/package/package_details_fetcher.rb', line 113

def transitory_failure?(error)
  return true if error.message.include?("EOF")

  error.message.include?("Internal Server Error")
end

#version_classObject



147
148
149
# File 'lib/dependabot/go_modules/package/package_details_fetcher.rb', line 147

def version_class
  dependency.version_class
end