fix(parsers): resolve pnpm workspace deps against ancestor lockfile - #340
Merged
Merged
Conversation
A workspace member's package.json has no sibling lockfile, so its declared dependency constraints were emitted as specifier-versioned phantom components (is-even@^1.0.0) that inflated OSV matches. Manifest dependency declarations are now superseded by the nearest covering lockfile in any ancestor directory, matching how pnpm/npm/yarn workspaces resolve members through the workspace-root lockfile. pnpm importer dependency values that are bare specifier strings (pnpm 12 workspace importers) likewise resolve against the lockfile's recorded versions instead of becoming component versions; tags and partial ranges resolve by name, and unresolvable specifiers produce no component. Closes #339
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Closes #339
hooray scan projecton a pnpm workspace no longer emitsspecifier-versioned phantom components (
is-even@^1.0.0) that inflatedOSV matches (reporter: 10 true findings → 83).
package.jsonhas no siblinglockfile, so
parse_package_jsontreated its declared constraints asresolved components. Manifest declarations are now superseded by the
nearest covering lockfile in any ancestor directory — the
workspace-root
pnpm-lock.yaml/package-lock.json/yarn.lock/bun.lockthat actually resolved the member's dependencies.specifier strings resolve against the lockfile's recorded versions
instead of becoming component versions; tags (
latest) and partialranges (
1.x) resolve by name, and unresolvable specifiers produce nocomponent.
Verification
apps/webimporters): before →is-even@1.0.0,is-even@^1.0.0,is-odd@3.0.1; after → exactlyis-even@1.0.0,is-odd@3.0.1.cargo test --locked --all-targets --all-features— 708 passed,0 failed, including new regressions:
input::tests::workspace_manifest_deps_are_covered_by_ancestor_lockfile(nested manifest + root lockfile → resolved versions only) and
parsers::pnpm::tests::pnpm_workspace_importer_specifiers_resolve_to_locked_versions(bare specifier/tag/range importer values in a two-document lockfile).
cargo fmt --check,cargo check --locked --all-targets --all-features,cargo clippy --locked --all-targets --all-features -- -D warnings— clean.cargo llvm-cov --fail-under-lines 90— 90.12% lines.cargo deny check advisories bans licenses sources— all ok.