Commit 9d721ef
authored
feat(scan): scan selected uv workspace members with dependency graphs (#1565)
* feat(scan): scan selected uv packages with dependency graphs
* docs(scan): remove stale and repeated upload comments
* fix(scan): preserve development scopes in uv package scans
* test(scan): give uv CLI tests the 30s CLI spawn timeout
These cases spawn the built CLI like the cmdit tests do, but ran with vitest's 5s default and timed out under parallel load.
* feat(scan): select uv workspace members by target directory
Replace --uv-package <project.name> with a boolean --uv-members flag. Each
TARGET is a member directory, and uv resolves it from the uv.lock in that
directory or its workspace root, so one scan can cover members of several
workspaces.
Each member's CycloneDX SBOM is written beside its pyproject.toml and removed
after the scan. That keeps the existing upload roots and reachability target
unchanged, so the scan handler takes a generic generateScanFiles hook and no
longer has uv-specific branches. With --reach, analysis runs on the member
directory only.
The e2e assertions now accept uv 0.12, which omits dependsOn on leaf nodes and
adds workspace-root dependency groups to members without their own.
* feat(scan): add the uv member target code, tests and docs
Completes the previous commit, which only picked up the renames and the reachability revert.
* fix(scan): remove uv member SBOMs when a scan is interrupted
The launcher SIGKILLs a signalled scan after a short grace period, and a
signal or process.exit() skips finally blocks, so Ctrl-C or a CI cancel left
socket-uv-cdx.json in the member directory. A later regular scan would then
pick it up as a pre-generated SBOM. Written SBOMs are now also removed
synchronously on exit, SIGHUP, SIGINT and SIGTERM.
The real-uv e2e tests get a 30s timeout, since each one runs uv twice per
member and the handler test sometimes passed 5s.1 parent 4400e0e commit 9d721ef
14 files changed
Lines changed: 1158 additions & 30 deletions
File tree
- src/commands/scan
- test/fixtures/commands/scan/uv-workspace
- packages
- api
- other
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
4 | 4 | | |
5 | 5 | | |
6 | 6 | | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
7 | 13 | | |
8 | 14 | | |
9 | 15 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
63 | 63 | | |
64 | 64 | | |
65 | 65 | | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
| 95 | + | |
| 96 | + | |
| 97 | + | |
| 98 | + | |
66 | 99 | | |
67 | 100 | | |
68 | 101 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
4 | 4 | | |
5 | 5 | | |
6 | 6 | | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
7 | 11 | | |
8 | 12 | | |
9 | 13 | | |
| |||
172 | 176 | | |
173 | 177 | | |
174 | 178 | | |
| 179 | + | |
| 180 | + | |
| 181 | + | |
| 182 | + | |
| 183 | + | |
| 184 | + | |
175 | 185 | | |
176 | 186 | | |
177 | 187 | | |
| |||
241 | 251 | | |
242 | 252 | | |
243 | 253 | | |
| 254 | + | |
244 | 255 | | |
245 | 256 | | |
246 | 257 | | |
| |||
332 | 343 | | |
333 | 344 | | |
334 | 345 | | |
| 346 | + | |
335 | 347 | | |
336 | 348 | | |
337 | 349 | | |
| |||
472 | 484 | | |
473 | 485 | | |
474 | 486 | | |
| 487 | + | |
475 | 488 | | |
476 | 489 | | |
477 | 490 | | |
| |||
567 | 580 | | |
568 | 581 | | |
569 | 582 | | |
| 583 | + | |
| 584 | + | |
| 585 | + | |
| 586 | + | |
| 587 | + | |
| 588 | + | |
| 589 | + | |
570 | 590 | | |
571 | 591 | | |
572 | 592 | | |
| |||
629 | 649 | | |
630 | 650 | | |
631 | 651 | | |
| 652 | + | |
| 653 | + | |
632 | 654 | | |
633 | 655 | | |
634 | 656 | | |
| |||
642 | 664 | | |
643 | 665 | | |
644 | 666 | | |
| 667 | + | |
| 668 | + | |
| 669 | + | |
645 | 670 | | |
646 | 671 | | |
647 | 672 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | 2 | | |
3 | | - | |
| 3 | + | |
4 | 4 | | |
5 | 5 | | |
6 | 6 | | |
| |||
17 | 17 | | |
18 | 18 | | |
19 | 19 | | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
20 | 84 | | |
21 | 85 | | |
22 | 86 | | |
| |||
54 | 118 | | |
55 | 119 | | |
56 | 120 | | |
| 121 | + | |
57 | 122 | | |
58 | 123 | | |
59 | 124 | | |
| |||
109 | 174 | | |
110 | 175 | | |
111 | 176 | | |
112 | | - | |
| 177 | + | |
| 178 | + | |
113 | 179 | | |
114 | 180 | | |
115 | 181 | | |
| |||
0 commit comments