Documentation
¶
Overview ¶
Package gomodgraph resolves the transitive dependency EDGES of a Go module by shelling out to `go mod graph` via argv and mapping its module-graph output onto the SBOM's existing golang components. go.mod alone carries only the (flattened) requirement list – not the edge graph – and the transitive graph lives in the module cache, which `go mod graph` reads; so an owned, no-exec parse cannot produce edges. This adapter fills that gap as a best-effort, post-SBOM enrichment.
SAFETY: `go mod graph` only READS go.mod files (from the workspace + module cache) – it does NOT compile the target (unlike govulncheck/taint), so it is low-risk; it still runs sandbox-confined when a runner is set (the module dir bound READ-ONLY, GOPROXY=off so it never reaches the network – cache-only, fail-fast offline; GOTOOLCHAIN=local so a hostile `toolchain` directive can never trigger a toolchain fetch+exec). It is BEST-EFFORT: a non-Go target, an un-resolvable graph (no module cache), or any tool error adds NO edges and never fails the scan. Edges are RESOLUTION-AS-FILTER: an edge is emitted only when BOTH endpoints are already golang components in the SBOM, so a `go mod graph` line for an unselected module version (the graph lists every version considered by MVS) is dropped – never a phantom edge.
Index ¶
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type Resolver ¶
type Resolver struct {
// contains filtered or unexported fields
}
Resolver runs `go mod graph` to add Go dependency edges to an SBOM. bin is the go executable (path/name).
func (*Resolver) ResolveEdges ¶
ResolveEdges runs `go mod graph` over dir and adds the resolved Go dependency edges to doc, in place. It no-ops (0, nil) when doc has no golang components (not a Go target – nothing to resolve, and the tool would be pointless). Returns the number of edges (DependsOn entries) added. Best-effort: a tool error is returned for the caller to log+ignore; doc is left unchanged on error.
func (*Resolver) WithRunner ¶
func (r *Resolver) WithRunner(runner ports.ToolRunner) *Resolver
WithRunner runs `go mod graph` through a ToolRunner (the SandboxRunner) instead of a bare os/exec. The module dir is bound READ-ONLY; `go mod graph` reads the module cache (HOME/go/pkg/mod in the sandbox's ephemeral env) – binding a populated cache offline is an operational follow-up shared with govulncheck, so until then a sandboxed run is best-effort (no cache ⇒ no edges, never a false graph).