Skip to content

Parse registry redirection configuration #106

Description

@andrew

On v0.12.2 and current main, configuration that redirects a package manager to a different registry is not parseable. Using Go 1.27.1:

r, err := manifests.Parse(".npmrc", []byte("registry=https://nexus.internal/repository/npm-group/\n@acme:registry=https://nexus.internal/repository/acme/\n"))
fmt.Printf("%+v err=%v\n", r, err)
// <nil> err=unknown manifest file: .npmrc

Sources covers source declarations written inside a manifest, so a Bundler source block or a Cargo registry named in Cargo.toml is retained. Redirection that lives beside the manifest is invisible, which means two repositories with identical manifests can resolve every dependency from different hosts and parse identically. The files are already partly in reach: DiscoverVendors globs .cargo/config and .cargo/config.toml to find directory sources.

Formats worth covering:

  • .npmrc and .yarnrc.yml, including scoped registry keys
  • pip.conf and pip.ini, index-url and extra-index-url
  • .cargo/config.toml, [source.*] with replace-with
  • Bundler mirror.* settings in .bundle/config

Each entry needs the registry URL, the scope or package pattern it applies to when there is one, whether it replaces the default or supplements it, and the file it came from.

These files carry credentials: .npmrc holds _authToken and _auth, and pip and Cargo index URLs can embed a username and password. Parsing must not return them. Token keys should be skipped, and userinfo stripped from any URL before it reaches a caller, so a result is safe to log or store alongside the rest of a scan.

A new Kind looks right here, since these are neither manifests nor lockfiles and should not produce Dependencies. Public Parse tests should cover each file with fixtures, including a credentialed URL and an _authToken line, asserting neither appears in the result.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions