On v0.12.2 and current main, configuration that redirects a package manager to a different registry is not parseable. Using Go 1.27.1:
r, err := manifests.Parse(".npmrc", []byte("registry=https://nexus.internal/repository/npm-group/\n@acme:registry=https://nexus.internal/repository/acme/\n"))
fmt.Printf("%+v err=%v\n", r, err)
// <nil> err=unknown manifest file: .npmrc
Sources covers source declarations written inside a manifest, so a Bundler source block or a Cargo registry named in Cargo.toml is retained. Redirection that lives beside the manifest is invisible, which means two repositories with identical manifests can resolve every dependency from different hosts and parse identically. The files are already partly in reach: DiscoverVendors globs .cargo/config and .cargo/config.toml to find directory sources.
Formats worth covering:
.npmrc and .yarnrc.yml, including scoped registry keys
pip.conf and pip.ini, index-url and extra-index-url
.cargo/config.toml, [source.*] with replace-with
- Bundler
mirror.* settings in .bundle/config
Each entry needs the registry URL, the scope or package pattern it applies to when there is one, whether it replaces the default or supplements it, and the file it came from.
These files carry credentials: .npmrc holds _authToken and _auth, and pip and Cargo index URLs can embed a username and password. Parsing must not return them. Token keys should be skipped, and userinfo stripped from any URL before it reaches a caller, so a result is safe to log or store alongside the rest of a scan.
A new Kind looks right here, since these are neither manifests nor lockfiles and should not produce Dependencies. Public Parse tests should cover each file with fixtures, including a credentialed URL and an _authToken line, asserting neither appears in the result.
On v0.12.2 and current main, configuration that redirects a package manager to a different registry is not parseable. Using Go 1.27.1:
Sourcescovers source declarations written inside a manifest, so a Bundlersourceblock or a Cargo registry named inCargo.tomlis retained. Redirection that lives beside the manifest is invisible, which means two repositories with identical manifests can resolve every dependency from different hosts and parse identically. The files are already partly in reach:DiscoverVendorsglobs.cargo/configand.cargo/config.tomlto find directory sources.Formats worth covering:
.npmrcand.yarnrc.yml, including scoped registry keyspip.confandpip.ini,index-urlandextra-index-url.cargo/config.toml,[source.*]withreplace-withmirror.*settings in.bundle/configEach entry needs the registry URL, the scope or package pattern it applies to when there is one, whether it replaces the default or supplements it, and the file it came from.
These files carry credentials:
.npmrcholds_authTokenand_auth, and pip and Cargo index URLs can embed a username and password. Parsing must not return them. Token keys should be skipped, and userinfo stripped from any URL before it reaches a caller, so a result is safe to log or store alongside the rest of a scan.A new
Kindlooks right here, since these are neither manifests nor lockfiles and should not produceDependencies. PublicParsetests should cover each file with fixtures, including a credentialed URL and an_authTokenline, asserting neither appears in the result.