Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

feat(go): support dependency graph and show only direct dependencies in the tree #3691

Merged
merged 11 commits into from
Feb 28, 2023

Conversation

knqyf263
Copy link
Collaborator

@knqyf263 knqyf263 commented Feb 25, 2023

Description

image

Related PRs

Checklist

  • I've read the guidelines for contributing to this repository.
  • I've followed the conventions in the PR title.
  • I've added tests that prove my fix is effective or that my feature works.
  • I've updated the documentation with the relevant information (if needed).
  • I've added usage information (if the PR introduces new options)
  • I've included a "before" and "after" example to the description (if the PR is a user interface change).

@knqyf263 knqyf263 self-assigned this Feb 25, 2023
@knqyf263 knqyf263 requested a review from masahiro331 February 26, 2023 09:18
modPath := filepath.Join(modDir, "go.mod")
f, err := os.Open(modPath)
if errors.Is(err, fs.ErrNotExist) {
log.Logger.Debugf("go.mod not found: %s", pkgID)
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This log message can be confusing. Users may not be aware that we are scanning $GOPATH/pkg/mod directory.
Maybe write something like this:

%s doesn't use Go modules

Copy link
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done 0c3c006

Comment on lines 210 to 212
if depth < 1 {
branch := topItem.AddBranch(parent.ID)
addParents(branch, parent, parentMap, ancestors, seen, depth+1)
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

looks like it is not possible or am i missing something?

Copy link
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

You're right. I wanted to support --dependency-depth so the depth can be configured. But I eventually changed my mind because it could be too much at the moment. I'll remove it.

Copy link
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done 02ba0cb

@knqyf263 knqyf263 marked this pull request as ready for review February 28, 2023 09:30
@knqyf263 knqyf263 changed the title feat(go): support dependency graph feat(go): support dependency graph and show direct deps only in the tree Feb 28, 2023
@knqyf263 knqyf263 changed the title feat(go): support dependency graph and show direct deps only in the tree feat(go): support dependency graph and show only direct dependencies in the tree Feb 28, 2023
@knqyf263 knqyf263 merged commit 00daebc into aquasecurity:main Feb 28, 2023
@knqyf263 knqyf263 deleted the go_dep_graph branch February 28, 2023 11:24
atombrella pushed a commit to atombrella/trivy that referenced this pull request Mar 25, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants