gomodgraph

package
v0.2.2 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 27, 2026 License: Apache-2.0 Imports: 11 Imported by: 0

Documentation

Overview

Package gomodgraph resolves the transitive dependency EDGES of a Go module by shelling out to `go mod graph` via argv and mapping its module-graph output onto the SBOM's existing golang components. go.mod alone carries only the (flattened) requirement list – not the edge graph – and the transitive graph lives in the module cache, which `go mod graph` reads; so an owned, no-exec parse cannot produce edges. This adapter fills that gap as a best-effort, post-SBOM enrichment.

SAFETY: `go mod graph` only READS go.mod files (from the workspace + module cache) – it does NOT compile the target (unlike govulncheck/taint), so it is low-risk; it still runs sandbox-confined when a runner is set (the module dir bound READ-ONLY, GOPROXY=off so it never reaches the network – cache-only, fail-fast offline; GOTOOLCHAIN=local so a hostile `toolchain` directive can never trigger a toolchain fetch+exec). It is BEST-EFFORT: a non-Go target, an un-resolvable graph (no module cache), or any tool error adds NO edges and never fails the scan. Edges are RESOLUTION-AS-FILTER: an edge is emitted only when BOTH endpoints are already golang components in the SBOM, so a `go mod graph` line for an unselected module version (the graph lists every version considered by MVS) is dropped – never a phantom edge.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

This section is empty.

Types

type Resolver

type Resolver struct {
	// contains filtered or unexported fields
}

Resolver runs `go mod graph` to add Go dependency edges to an SBOM. bin is the go executable (path/name).

func New

func New(bin string) *Resolver

New returns a resolver using the given go binary (defaults to "go" in PATH).

func (*Resolver) ResolveEdges

func (r *Resolver) ResolveEdges(ctx context.Context, dir string, doc *sbom.SBOM) (int, error)

ResolveEdges runs `go mod graph` over dir and adds the resolved Go dependency edges to doc, in place. It no-ops (0, nil) when doc has no golang components (not a Go target – nothing to resolve, and the tool would be pointless). Returns the number of edges (DependsOn entries) added. Best-effort: a tool error is returned for the caller to log+ignore; doc is left unchanged on error.

func (*Resolver) WithRunner

func (r *Resolver) WithRunner(runner ports.ToolRunner) *Resolver

WithRunner runs `go mod graph` through a ToolRunner (the SandboxRunner) instead of a bare os/exec. The module dir is bound READ-ONLY; `go mod graph` reads the module cache (HOME/go/pkg/mod in the sandbox's ephemeral env) – binding a populated cache offline is an operational follow-up shared with govulncheck, so until then a sandboxed run is best-effort (no cache ⇒ no edges, never a false graph).

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL