versionorder

package
v0.144.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 3, 2026 License: Apache-2.0 Imports: 2 Imported by: 0

Documentation

Overview

Package versionorder orders the versions of one package by the rules of the ecosystem it comes from.

Every ecosystem orders differently. Debian's `3.0.17-1~deb12u3` is newer than `3.0.17-1~deb12u2` and `1.0~rc1` is older than `1.0`; PEP 440 puts `1.0rc1` before `1.0` and `1.0.post1` after it; Maven's `2.13.4.2` follows `2.13.4`. A comparison that reads dotted numbers alone gets each of these wrong, and a wrong order recommends an upgrade that leaves findings behind or a downgrade of a working dependency.

The rules are osv-scalibr's, which are the ones OSV's own matching uses. Where the ecosystem is not one it orders, or a version does not parse in it, Compare says so rather than guessing, and the caller keeps every version it was given.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func Compare

func Compare(ecosystem, a, b string) (order int, ok bool)

Compare returns -1, 0 or +1 as a is older than, the same as or newer than b under ecosystem's rules. ok is false when the ecosystem is not one this orders, or either version does not parse in it, and then the order is unknown rather than equal.

func Ecosystem

func Ecosystem(purl, reported string) string

Ecosystem names the rules that order a package's versions, from its package URL or, without one, from the ecosystem a scanner reported. Empty when neither names rules this package knows.

Types

This section is empty.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL