From 9a4b9bbf9b3bb23fdc1ace01244491892e076d9d Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Sun, 20 Sep 2026 02:22:41 +0000 Subject: [PATCH 1/2] Bump github.com/git-pkgs/manifests from 0.12.0 to 0.12.2 Bumps [github.com/git-pkgs/manifests](https://github.com/git-pkgs/manifests) from 0.12.0 to 0.12.2. - [Release notes](https://github.com/git-pkgs/manifests/releases) - [Commits](https://github.com/git-pkgs/manifests/compare/v0.12.0...v0.12.2) --- updated-dependencies: - dependency-name: github.com/git-pkgs/manifests dependency-version: 0.12.2 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] --- go.mod | 4 +--- go.sum | 14 ++------------ 2 files changed, 3 insertions(+), 15 deletions(-) diff --git a/go.mod b/go.mod index 0053aae..3ed41c1 100644 --- a/go.mod +++ b/go.mod @@ -12,7 +12,7 @@ require ( github.com/git-pkgs/forge v0.10.0 github.com/git-pkgs/licensecheck v0.4.1 github.com/git-pkgs/magic v0.3.1 - github.com/git-pkgs/manifests v0.12.0 + github.com/git-pkgs/manifests v0.12.2 github.com/git-pkgs/outline v0.2.2 github.com/git-pkgs/purl v0.1.20 github.com/git-pkgs/registries v0.9.1 @@ -35,12 +35,10 @@ require ( github.com/git-pkgs/vulns v0.2.3 // indirect github.com/github/go-spdx/v2 v2.7.0 // indirect github.com/google/uuid v1.6.0 // indirect - github.com/kr/text v0.2.0 // indirect github.com/oapi-codegen/nullable v1.2.0 // indirect github.com/oapi-codegen/runtime v1.6.0 // indirect github.com/odvcencio/gotreesitter v0.51.0 // indirect github.com/package-url/packageurl-go v0.1.7 // indirect github.com/pandatix/go-cvss v0.6.4 // indirect golang.org/x/sys v0.48.0 // indirect - gopkg.in/yaml.v3 v3.0.1 // indirect ) diff --git a/go.sum b/go.sum index e1030e5..abd0140 100644 --- a/go.sum +++ b/go.sum @@ -8,7 +8,6 @@ github.com/bazelbuild/buildtools v0.0.0-20260716142318-04cf7de1434f/go.mod h1:PL github.com/bmatcuk/doublestar v1.1.1/go.mod h1:UD6OnuiIn0yFxxA2le/rnRU1G4RaI4UvFv1sNto9p6w= github.com/bmatcuk/doublestar/v4 v4.10.0 h1:zU9WiOla1YA122oLM6i4EXvGW62DvKZVxIe6TYWexEs= github.com/bmatcuk/doublestar/v4 v4.10.0/go.mod h1:xBQ8jztBU6kakFMg+8WGxn0c6z1fTSPVIjEY1Wr7jzc= -github.com/creack/pty v1.1.9/go.mod h1:oKZEueFk5CKHvIhNR5MUki03XCEU+Q6VDXinZuGJ33E= github.com/davecgh/go-spew v1.1.0/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSsI+c5H38= github.com/davecgh/go-spew v1.1.1 h1:vj9j/u1bqnvCEfJOwUhtlOARqs3+rkHYY13jYWTU97c= github.com/davecgh/go-spew v1.1.1/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSsI+c5H38= @@ -28,8 +27,8 @@ github.com/git-pkgs/licensecheck v0.4.1 h1:b5ilmpIpgeeewBFjdhJ4W7jvwPIFsYQ7ujZma github.com/git-pkgs/licensecheck v0.4.1/go.mod h1:cfFO7yHHPeuXsoODHBWyevajH2yWcbfkIFELyG3ZpU0= github.com/git-pkgs/magic v0.3.1 h1:UzjFRyEwJITA/JgznjmIM4VwuBszD2K4Q8XHgkgL+DM= github.com/git-pkgs/magic v0.3.1/go.mod h1:SXOqcsNmbmpZjJZHEEWnwxprbsFvpwWgTAZrgXp4Jm4= -github.com/git-pkgs/manifests v0.12.0 h1:5YQUUKekrx6tOKhC0zdaBBB2+nq6eTB9AqyiR1mYvXk= -github.com/git-pkgs/manifests v0.12.0/go.mod h1:9oe+LQ84i6JmUiKXAmuUUm3OfvFaAR+3AhBUu1KeBYI= +github.com/git-pkgs/manifests v0.12.2 h1:8/8eyc7Z6xwWC3S/bDKKRAFKE2hLuHAN5Sc1Dt1h+UY= +github.com/git-pkgs/manifests v0.12.2/go.mod h1:fCgHIUuGunqJ4do1I8fOXU2IlXvaVMVkD5Vhv03+CNA= github.com/git-pkgs/outline v0.2.2 h1:t415r8dgJg6+PedRfeBf1KdaVTpTTJ50XASm7PbEExM= github.com/git-pkgs/outline v0.2.2/go.mod h1:ys/wKEppQrSP24WvlnSOBA/EkNp3H3c/oL5C6DVQvF4= github.com/git-pkgs/packageurl-go v0.3.1 h1:WM3RBABQZLaRBxgKyYughc3cVBE8KyQxbSC6Jt5ak7M= @@ -53,10 +52,6 @@ github.com/google/uuid v1.6.0/go.mod h1:TIyPZe4MgqvfeYDBFedMoGGpEw/LqOeaOT+nhxU+ github.com/juju/gnuflag v0.0.0-20171113085948-2ce1bb71843d/go.mod h1:2PavIy+JPciBPrBUjwbNvtwB6RQlve+hkpll6QSNmOE= github.com/klauspost/compress v1.20.0 h1:a3C1ke2ohxFymNlb2HWAHjDeKCI90scRskErZkR0ezA= github.com/klauspost/compress v1.20.0/go.mod h1:LUdAzn7YLVvxLpc7y3V1m40wESHTgc1422pwwBSKYuI= -github.com/kr/pretty v0.3.1 h1:flRD4NNwYAUpkphVc1HcthR4KEIFJ65n8Mw5qdRn3LE= -github.com/kr/pretty v0.3.1/go.mod h1:hoEshYVHaxMs3cyo3Yncou5ZscifuDolrwPKZanG3xk= -github.com/kr/text v0.2.0 h1:5Nx0Ya0ZqY2ygV366QzturHI13Jq95ApcVaJBhpS+AY= -github.com/kr/text v0.2.0/go.mod h1:eLer722TekiGuMkidMxC/pM04lWEeraHUUmBw8l2grE= github.com/oapi-codegen/nullable v1.2.0 h1:VflFkDW980KhBPiFF7nWSyjg+r4Obqj8lXipV0UkP5w= github.com/oapi-codegen/nullable v1.2.0/go.mod h1:KUZ3vUzkmEKY90ksAmit2+5juDIhIZhfDl+0PwOQlFY= github.com/oapi-codegen/runtime v1.6.0 h1:7Xx+GlueD6nRuyKoCPzL434Jfi3BetbiJOrzCHp/VPU= @@ -69,8 +64,6 @@ github.com/pandatix/go-cvss v0.6.4 h1:9w2RCO/Q4UTiJyEgpCHRiVc6CfrsFEnkoX+OtATqKi github.com/pandatix/go-cvss v0.6.4/go.mod h1:/ukvQnYlrKl3o/DVp7/GO2UZyZheuo/maOK0U1nBEhQ= github.com/pmezard/go-difflib v1.0.0 h1:4DBwDE0NGyQoBHbLQYPwSUPoCMWR5BEzIk/f1lZbAQM= github.com/pmezard/go-difflib v1.0.0/go.mod h1:iKH77koFhYxTK1pcRnkKkqfTogsbg7gZNVY4sRDYZ/4= -github.com/rogpeppe/go-internal v1.14.1 h1:UQB4HGPB6osV0SQTLymcB4TgvyWu6ZyliaW0tI/otEQ= -github.com/rogpeppe/go-internal v1.14.1/go.mod h1:MaRKkUm5W0goXpeCfT7UZI6fk/L7L7so1lCWt35ZSgc= github.com/spkg/bom v0.0.0-20160624110644-59b7046e48ad/go.mod h1:qLr4V1qq6nMqFKkMo8ZTx3f+BZEkzsRUY10Xsm2mwU0= github.com/stretchr/objx v0.1.0/go.mod h1:HFkY916IF+rwdDfMAkV7OtwuqBVzrE8GR6GFx+wExME= github.com/stretchr/testify v1.3.0/go.mod h1:M5WIy9Dh21IEIfnGCwXGc5bZfKNJtfHm1UVUgZn+9EI= @@ -84,8 +77,5 @@ golang.org/x/sys v0.48.0 h1:bbX/i/6MgT9BVLM9RT1thmxL04yeTAhbEz4SyadbXoo= golang.org/x/sys v0.48.0/go.mod h1:hNLxWAXmnKAxqDtdwIYC4bM9oQPEecfsnNMuSxOs3og= golang.org/x/term v0.46.0 h1:3+OXuTbaKDgwk8jTi3aSLHRlmWqHEUDUtxnbFigO4YE= golang.org/x/term v0.46.0/go.mod h1:+K02xbkittuwc0Am4abfA3Fc+XRGXkvBXNO88NCXPoc= -gopkg.in/check.v1 v0.0.0-20161208181325-20d25e280405/go.mod h1:Co6ibVJAznAaIkqp8huTwlJQCZ016jof/cbN4VW5Yz0= -gopkg.in/check.v1 v1.0.0-20201130134442-10cb98267c6c h1:Hei/4ADfdWqJk1ZMxUNpqntNwaWcugrBjAiHlqqRiVk= -gopkg.in/check.v1 v1.0.0-20201130134442-10cb98267c6c/go.mod h1:JHkPIbrfpd72SG/EVd6muEfDQjcINNoR0C8j2r3qZ4Q= gopkg.in/yaml.v3 v3.0.1 h1:fxVm/GzAzEWqLHuvctI91KS9hhNmmWOoWu0XTYJS7CA= gopkg.in/yaml.v3 v3.0.1/go.mod h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM= From 51929ba873b5b4acac71c0082efb0ce3cb44e4c2 Mon Sep 17 00:00:00 2001 From: Andrew Nesbitt Date: Sun, 20 Sep 2026 11:33:10 +0100 Subject: [PATCH 2/2] Report dependency source overrides --- brief.go | 25 ++++++++++++----- detect/dependency_manifest_test.go | 43 ++++++++++++++++++++++++++++++ detect/detect.go | 15 +++++++++-- 3 files changed, 75 insertions(+), 8 deletions(-) diff --git a/brief.go b/brief.go index 66f3c6e..f9b6d68 100644 --- a/brief.go +++ b/brief.go @@ -223,12 +223,25 @@ type Stats struct { // DepInfo is a parsed dependency from a manifest file. type DepInfo struct { - Manifest string `json:"manifest"` // project-relative source manifest or lockfile path - Name string `json:"name"` - Version string `json:"version,omitempty"` - PURL string `json:"purl"` - Scope string `json:"scope,omitempty"` // "runtime", "development", "test", "build" - Direct bool `json:"direct"` + Manifest string `json:"manifest"` // project-relative source manifest or lockfile path + Name string `json:"name"` + Version string `json:"version,omitempty"` + PURL string `json:"purl"` + Scope string `json:"scope,omitempty"` // "runtime", "development", "test", "build" + Direct bool `json:"direct"` + Source *DepSource `json:"source,omitempty"` +} + +// DepSource preserves an explicit dependency source override from the +// manifest, e.g. a git URL or a named private registry. It is only set +// when the dependency is not fetched from the ecosystem's default registry. +type DepSource struct { + Kind string `json:"kind"` // "git", "registry", "path", "github", "url" + Value string `json:"value,omitempty"` + Branch string `json:"branch,omitempty"` + Tag string `json:"tag,omitempty"` + Ref string `json:"ref,omitempty"` + Rel string `json:"rel,omitempty"` } // ManifestInfo describes a parsed project manifest or lockfile. diff --git a/detect/dependency_manifest_test.go b/detect/dependency_manifest_test.go index 992d9a7..9da94db 100644 --- a/detect/dependency_manifest_test.go +++ b/detect/dependency_manifest_test.go @@ -53,3 +53,46 @@ source = "registry+https://github.com/rust-lang/crates.io-index" t.Errorf("dependencies have no manifest: %s", data) } } + +func TestDependencySourceOverride(t *testing.T) { + dir := t.TempDir() + writeFile(t, dir, "Cargo.toml", `[package] +name = "app" +version = "0.1.0" +[dependencies] +serde = "1" +forked = { git = "https://github.com/example/forked", branch = "patched" } +internal = { version = "0.2", registry = "corp" } +`) + report := runOn(t, dir) + data, err := json.Marshal(report) + if err != nil { + t.Fatal(err) + } + var output struct { + Dependencies []struct { + Name string + Source *struct { + Kind string + Value string + Branch string + } + } + } + if err := json.Unmarshal(data, &output); err != nil { + t.Fatal(err) + } + byName := make(map[string]*struct{ Kind, Value, Branch string }) + for _, dep := range output.Dependencies { + byName[dep.Name] = dep.Source + } + if got := byName["serde"]; got != nil { + t.Errorf("serde: expected no source override, got %+v", got) + } + if got := byName["forked"]; got == nil || got.Kind != "git" || got.Value != "https://github.com/example/forked" || got.Branch != "patched" { + t.Errorf("forked: got %+v", got) + } + if got := byName["internal"]; got == nil || got.Kind != "registry" || got.Value != "corp" { + t.Errorf("internal: got %+v", got) + } +} diff --git a/detect/detect.go b/detect/detect.go index 3712611..55ded06 100644 --- a/detect/detect.go +++ b/detect/detect.go @@ -1112,14 +1112,25 @@ func (e *Engine) loadDeps() { case manifests.Build: scope = brief.ScopeBuild } - e.parsedDeps = append(e.parsedDeps, brief.DepInfo{ + info := brief.DepInfo{ Manifest: filepath.ToSlash(mf), Name: dep.Name, Version: dep.Version, PURL: dep.PURL, Scope: scope, Direct: dep.Direct, - }) + } + if dep.Source.Kind != "" { + info.Source = &brief.DepSource{ + Kind: string(dep.Source.Kind), + Value: dep.Source.Value, + Branch: dep.Source.Branch, + Tag: dep.Source.Tag, + Ref: dep.Source.Ref, + Rel: dep.Source.Rel, + } + } + e.parsedDeps = append(e.parsedDeps, info) } } }