Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

don't attempt to update a package if no versions could be found #8502

Merged
merged 4 commits into from
Dec 5, 2023
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
48 changes: 47 additions & 1 deletion nuget/lib/dependabot/nuget/file_parser/project_file_parser.rb
Original file line number Diff line number Diff line change
Expand Up @@ -16,6 +16,7 @@ class FileParser
class ProjectFileParser
require "dependabot/file_parsers/base/dependency_set"
require_relative "property_value_finder"
require_relative "../update_checker/repository_finder"

DEPENDENCY_SELECTOR = "ItemGroup > PackageReference, " \
"ItemGroup > GlobalPackageReference, " \
Expand All @@ -38,6 +39,10 @@ def self.dependency_set_cache
CacheManager.cache("project_file_dependency_set")
end

def self.dependency_url_search_cache
CacheManager.cache("dependency_url_search_cache")
end

def initialize(dependency_files:, credentials:)
@dependency_files = dependency_files
@credentials = credentials
Expand Down Expand Up @@ -261,12 +266,53 @@ def build_dependency(name, req, version, prop_name, project_file, dev: false)
requirement[:metadata] = { property_name: root_prop_name }
end

Dependency.new(
dependency = Dependency.new(
name: name,
version: version,
package_manager: "nuget",
requirements: [requirement]
)

# only include dependency if one of the sources has it
return unless dependency_has_search_results?(dependency)
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Consider logging the dependency and why it was skipped. It might be hard to track down why a certain dependency is missing without a log message here.


dependency
end

def dependency_has_search_results?(dependency)
nuget_configs = dependency_files.select { |f| f.name.casecmp?("nuget.config") }
dependency_urls = UpdateChecker::RepositoryFinder.new(
dependency: dependency,
credentials: credentials,
config_files: nuget_configs
).dependency_urls
if dependency_urls.empty?
dependency_urls = [UpdateChecker::RepositoryFinder.get_default_repository_details(dependency.name)]
end
dependency_urls_with_package = dependency_urls.select do |dependency_url|
response = execute_search_for_dependency_url(dependency_url)
next unless response.status == 200

body = JSON.parse(response.body)
data = body["data"]
next unless data.length.positive?

found_matching_result = data.any? { |result| result["id"].casecmp?(dependency.name) }
found_matching_result
end

dependency_urls_with_package.any?
end

def execute_search_for_dependency_url(dependency_url)
search_url = dependency_url.fetch(:search_url)
cache = ProjectFileParser.dependency_url_search_cache
cache[search_url] ||= Dependabot::RegistryClient.get(
url: search_url,
headers: dependency_url.fetch(:auth_header)
)

cache[search_url]
end

def dependency_name(dependency_node, project_file)
Expand Down
Loading