Class: Dependabot::NpmAndYarn::UpdateChecker

Inherits:
UpdateCheckers::Base
  • Object
show all
Defined in:
lib/dependabot/npm_and_yarn/update_checker.rb,
lib/dependabot/npm_and_yarn/update_checker/registry_finder.rb,
lib/dependabot/npm_and_yarn/update_checker/library_detector.rb,
lib/dependabot/npm_and_yarn/update_checker/version_resolver.rb,
lib/dependabot/npm_and_yarn/update_checker/requirements_updater.rb,
lib/dependabot/npm_and_yarn/update_checker/latest_version_finder.rb,
lib/dependabot/npm_and_yarn/update_checker/subdependency_version_resolver.rb

Defined Under Namespace

Classes: LatestVersionFinder, LibraryDetector, RegistryFinder, RequirementsUpdater, SubdependencyVersionResolver, VersionResolver

Instance Method Summary collapse

Instance Method Details

#latest_resolvable_previous_version(updated_version) ⇒ Object



57
58
59
# File 'lib/dependabot/npm_and_yarn/update_checker.rb', line 57

def latest_resolvable_previous_version(updated_version)
  version_resolver.latest_resolvable_previous_version(updated_version)
end

#latest_resolvable_versionObject



26
27
28
29
30
31
32
33
34
35
36
37
# File 'lib/dependabot/npm_and_yarn/update_checker.rb', line 26

def latest_resolvable_version
  return unless latest_version

  @latest_resolvable_version ||=
    if dependency.top_level?
      version_resolver.latest_resolvable_version
    else
      # If the dependency is indirect its version is constrained  by the
      # requirements placed on it by dependencies lower down the tree
      subdependency_version_resolver.latest_resolvable_version
    end
end

#latest_resolvable_version_with_no_unlockObject



47
48
49
50
51
52
53
54
55
# File 'lib/dependabot/npm_and_yarn/update_checker.rb', line 47

def latest_resolvable_version_with_no_unlock
  return latest_resolvable_version unless dependency.top_level?

  if git_dependency?
    return latest_resolvable_version_with_no_unlock_for_git_dependency
  end

  latest_version_finder.latest_version_with_no_unlock
end

#latest_versionObject



17
18
19
20
21
22
23
24
# File 'lib/dependabot/npm_and_yarn/update_checker.rb', line 17

def latest_version
  @latest_version ||=
    if git_dependency?
      latest_version_for_git_dependency
    else
      latest_version_details&.fetch(:version)
    end
end

#lowest_resolvable_security_fix_versionObject



39
40
41
42
43
44
45
# File 'lib/dependabot/npm_and_yarn/update_checker.rb', line 39

def lowest_resolvable_security_fix_version
  raise "Dependency not vulnerable!" unless vulnerable?
  return latest_resolvable_version unless dependency.top_level?

  # TODO: Might want to check resolvability here?
  latest_version_finder.lowest_security_fix_version
end

#requirements_update_strategyObject



83
84
85
86
87
88
89
90
91
# File 'lib/dependabot/npm_and_yarn/update_checker.rb', line 83

def requirements_update_strategy
  # If passed in as an option (in the base class) honour that option
  if @requirements_update_strategy
    return @requirements_update_strategy.to_sym
  end

  # Otherwise, widen ranges for libraries and bump versions for apps
  library? ? :widen_ranges : :bump_versions
end

#updated_requirementsObject



61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
# File 'lib/dependabot/npm_and_yarn/update_checker.rb', line 61

def updated_requirements
  resolvable_version =
    if preferred_resolvable_version.is_a?(version_class)
      preferred_resolvable_version.to_s
    elsif preferred_resolvable_version.nil?
      nil
    else
      # If the preferred_resolvable_version came back as anything other
      # than a version class or `nil` it must be because this is a git
      # dependency, for which we don't check resolvability.
      latest_version_details&.fetch(:version, nil)&.to_s
    end

  @updated_requirements ||=
    RequirementsUpdater.new(
      requirements: dependency.requirements,
      updated_source: updated_source,
      latest_resolvable_version: resolvable_version,
      update_strategy: requirements_update_strategy
    ).updated_requirements
end