Skip to content

Commit

Permalink
Fix for when there is no dependencies (evryfs#134)
Browse files Browse the repository at this point in the history
* Fix for when there is no dependencies

When no dependencies, just rely on components. No need to check for the dependencies length.

* add a test. check in packaged js

Co-authored-by: Kjetil Oen <[email protected]>
  • Loading branch information
alangonzalez and Kjetil Oen authored Oct 21, 2022
1 parent 5c1aea8 commit f496df3
Show file tree
Hide file tree
Showing 5 changed files with 23 additions and 8 deletions.
15 changes: 15 additions & 0 deletions __tests__/main.test.ts
Original file line number Diff line number Diff line change
Expand Up @@ -65,6 +65,21 @@ describe('Map to GH dep submission', () => {
expect(manifest.directDependencies().length).toBe(903)
expect(manifest.indirectDependencies().length).toBe(0) // dropwizard example has all deps listed as direct
})

test('testBaseUbuntuSyftExample', () => {
const bomfile: string = '__tests__/data/base_ubuntu_syft_packages.json'
const bom: SBom = parseSbomFile(bomfile)
const snapshot: Snapshot = map(bom, bomfile)
expect(snapshot).not.toBeNull()

expect(Object.keys(snapshot.manifests).length).toBe(1)

const manifest: Manifest =
snapshot.manifests[Object.keys(snapshot.manifests)[0]]
expect(manifest.directDependencies().length).toBe(118)
expect(manifest.indirectDependencies().length).toBe(0)
})

})

describe('GitHub action', () => {
Expand Down
6 changes: 3 additions & 3 deletions dist/index.js

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion dist/index.js.map

Large diffs are not rendered by default.

6 changes: 3 additions & 3 deletions lib/main.js
Original file line number Diff line number Diff line change
Expand Up @@ -82,7 +82,7 @@ function process(sbomFile) {
}
exports.process = process;
function map(sbom, sbomFilename) {
var _a, _b, _c, _d, _e, _f, _g, _h, _j, _k, _l;
var _a, _b, _c, _d, _e, _f, _g, _h, _j, _k;
//const bom: SBom = sbom as SBom
const detectors = Array.from(sbom.metadata.tools.values()).map(tool => {
var _a, _b, _c, _d;
Expand All @@ -107,11 +107,11 @@ function map(sbom, sbomFilename) {
snap.addManifest(buildTarget);
const packageCache = new dependency_submission_toolkit_1.PackageCache();
const deps = dependencyForPackage((_j = (_h = sbom.metadata.component) === null || _h === void 0 ? void 0 : _h.purl) === null || _j === void 0 ? void 0 : _j.toString(), sbom.dependencies);
if (!deps.length && ((_k = sbom.dependencies) === null || _k === void 0 ? void 0 : _k.length) && sbom.components) {
if (!deps.length && sbom.components) {
// main package url has not defined explicit dependencies in SBOM, add all components
for (const c of sbom.components) {
if (c.purl)
deps.push((_l = c.purl) === null || _l === void 0 ? void 0 : _l.toString());
deps.push((_k = c.purl) === null || _k === void 0 ? void 0 : _k.toString());
}
}
for (const dep of deps) {
Expand Down
2 changes: 1 addition & 1 deletion src/main.ts
Original file line number Diff line number Diff line change
Expand Up @@ -88,7 +88,7 @@ export function map(sbom: SBom, sbomFilename?: string): Snapshot {
sbom.metadata.component?.purl?.toString(),
sbom.dependencies
)
if (!deps.length && sbom.dependencies?.length && sbom.components) {
if (!deps.length && sbom.components) {
// main package url has not defined explicit dependencies in SBOM, add all components
for (const c of sbom.components) {
if (c.purl) deps.push(c.purl?.toString())
Expand Down

0 comments on commit f496df3

Please sign in to comment.