depsource

package
v0.8.1 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 24, 2026 License: AGPL-3.0, AGPL-3.0-or-later Imports: 20 Imported by: 0

Documentation

Overview

Package depsource answers one read-only question: what are the pinned bytes of a third-party Go module this repository depends on, and do they match the checksum the committed go.sum records?

The package never downloads, never writes to the module cache, and never reads the dirty worktree for evidence. When the pin cannot be proven it abstains with an explicit reason instead of returning unverified content (AGENTS.md invariants 1, 2, 4 and 7).

Index

Constants

View Source
const (
	// DefaultLimit bounds the file listing when no --limit is given.
	DefaultLimit = 200
)

Variables

This section is empty.

Functions

func Render

func Render(ctx context.Context, options Options, stdout io.Writer) error

Render resolves one module and writes a single canonical JSON line.

Types

type Error

type Error struct{ Message string }

Error is a depsource failure. An abstention is not an Error: it is a successful answer whose Verified member is false.

func (*Error) Error

func (err *Error) Error() string

type FileEntry

type FileEntry struct {
	Path string `json:"path"`
	Size int64  `json:"size"`
	Blob string `json:"blob,omitempty"`
}

FileEntry is one bounded listing row.

type FileExcerpt

type FileExcerpt struct {
	Path      string   `json:"path"`
	SHA256    string   `json:"sha256"`
	Size      int64    `json:"size"`
	Blob      string   `json:"blob,omitempty"`
	Truncated bool     `json:"truncated"`
	Lines     []string `json:"lines"`
}

FileExcerpt is one file's pinned content, capped at 64 KiB.

type Options

type Options struct {
	Root        string
	Module      string
	Version     string // Empty means "whatever the committed go.mod pins".
	File        string
	Limit       int
	ModuleCache string
}

Options is one depsource request. ModuleCache is injectable so a test can point at a fixture cache without mutating process environment.

type Result

type Result struct {
	Module       string       `json:"module"`
	Version      string       `json:"version"`
	Revision     string       `json:"revision"`
	Resolution   string       `json:"resolution"`
	GoSumHash    string       `json:"go_sum_hash"`
	ComputedHash string       `json:"computed_hash,omitempty"`
	Verified     bool         `json:"verified"`
	Reason       string       `json:"reason,omitempty"`
	FileCount    int          `json:"file_count"`
	Truncated    bool         `json:"truncated"`
	Files        []FileEntry  `json:"files,omitempty"`
	File         *FileExcerpt `json:"file,omitempty"`
}

Result is the emitted answer. Field order is the emitted member order.

func Resolve

func Resolve(ctx context.Context, options Options) (Result, error)

Resolve produces the answer without emitting it.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL