You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Tracking: scope project-mode cache crawls to what the project resolves #595
[agent] Filed by the scheduled architecture audit routine (ecosystems and formats). Register: E05.
Kind: tracking. Source: review §3 #3 and Part 6.6; register E05 (a step toward E36, one Inventory).
Problem
In local (project) mode, five crawlers return the whole machine cache as soon as the project has a marker file. Nothing narrows it to what the project resolves:
These are wrong answers from a security tool: agent mode patches, and VEX attests, packages the project never uses, and scan sends every cached coordinate on the machine to the API. Scan cost grows with the machine cache, not with the project.
Target design
In project mode, crawlers become locators. The candidate set comes from the project's own resolution data, and the cache is consulted only to find the bytes for a coordinate:
fn project_coordinates(cwd) -> Option<Vec<Coordinate>> per ecosystem, built on the existing readers: Cargo.lock (formats::cargo), go.sum/go.mod (go_mod_edit/go_sum_edit), packages.lock.json / obj/project.assets.jsonlibraries, the deno.lockjsr section, and Maven/Gradle lockfiles or the reactor's resolved POM set (vendor::jvm).
crawl_all in project mode becomes find_by_purls(cache, project_coordinates). Enumerating the whole cache stays, for --global / --global-prefix only.
When project_coordinates returns None (no lock or resolution file), keep today's enumeration but emit an explicit warning code (for example crawl_unscoped_cache), so lockless projects keep working and the result is labelled. Existing warning codes don't change.
Cargo: scope to Cargo.lock[[package]] entries with a registry source.
Go: scope to go.sum module lines (the /go.mod-only lines don't count).
Deno: scope to the deno.lockjsr entries.
Shared: the crawl_unscoped_cache warning, documented in CLI_CONTRACT.md.
Each child deletes its whole-cache path from project mode and adds a test with an unrelated package in the fake cache that must not appear in crawl_all.
Acceptance criteria
In project mode with a lock or resolution file, no crawler returns a package the project doesn't resolve.
--global output is unchanged.
The crawler oracle and equivalence suites, which encode today's whole-cache output, are updated deliberately rather than silenced.
Dependencies
Part of E36 (one Inventory). The NuGet child benefits from the shared packages.lock.json walker in #593 but doesn't need it. The FIFO fix #592 touches the same crawlers and should land first.
[agent] Filed by the scheduled architecture audit routine (ecosystems and formats). Register: E05.
Kind: tracking. Source: review §3 #3 and Part 6.6; register E05 (a step toward E36, one
Inventory).Problem
In local (project) mode, five crawlers return the whole machine cache as soon as the project has a marker file. Nothing narrows it to what the project resolves:
CargoCrawler::get_crate_source_pathsCargo.toml/Cargo.lockvendor/, else every$CARGO_HOME/registry/src/*GoCrawler::get_module_cache_pathsgo.mod/go.sumGOMODCACHEMavenCrawler::get_maven_repo_pathspom.xml,build.gradle*,settings.gradle*~/.m2/repositoryNuGetCrawler::get_nuget_package_paths.csproj/.fsproj/.vbproj/.sln/.slnx,packages.config,nuget.configpackages/,~/.nuget/packages, everypackageFolderskeyDenoCrawler::get_jsr_cache_pathsdeno.json(c)/deno.lock$DENO_DIR/npm/jsr.ioscanfeeds this crawl (crawl_every_ecosystem) to the patch API and to agent-mode apply and VEX. For Maven and NuGet the crawl is the only discovery.Symptoms
~/.m2) #265: Maven hosted scan pins, and VEX attests, artifacts the project doesn't depend on (the crawler lists all of~/.m2).~/.m2), Agent-mode NuGet apply patches ~/.nuget/packages instead of the project's configured globalPackagesFolder / RestorePackagesPath, reports success, and VEX attests not_affected #397 and Agent-mode NuGet apply ignores nuget.config repositoryPath for packages.config projects and patches ~/.nuget/packages instead, reporting success #398 (NuGetglobalPackagesFolder/repositoryPath), Agent-mode cargo apply patches only the first of several registry/src index dirs (cargo 1.84 vs 1.85+ hashes), so one cargo keeps building the unpatched crate while apply and VEX report success #339 (cargo patches only the firstregistry/srcindex dir).Impact
These are wrong answers from a security tool: agent mode patches, and VEX attests, packages the project never uses, and scan sends every cached coordinate on the machine to the API. Scan cost grows with the machine cache, not with the project.
Target design
In project mode, crawlers become locators. The candidate set comes from the project's own resolution data, and the cache is consulted only to find the bytes for a coordinate:
fn project_coordinates(cwd) -> Option<Vec<Coordinate>>per ecosystem, built on the existing readers:Cargo.lock(formats::cargo),go.sum/go.mod(go_mod_edit/go_sum_edit),packages.lock.json/obj/project.assets.jsonlibraries, thedeno.lockjsrsection, and Maven/Gradle lockfiles or the reactor's resolved POM set (vendor::jvm).crawl_allin project mode becomesfind_by_purls(cache, project_coordinates). Enumerating the whole cache stays, for--global/--global-prefixonly.project_coordinatesreturnsNone(no lock or resolution file), keep today's enumeration but emit an explicit warning code (for examplecrawl_unscoped_cache), so lockless projects keep working and the result is labelled. Existing warning codes don't change.Checklist (one PR each, in order)
obj/project.assets.jsonlibraries(fallbackpackages.lock.json). Child: Project-mode NuGet agent scan patches, and VEX attests, packages the project doesn't depend on (the crawler lists the whole ~/.nuget/packages) #427.~/.m2) #265.Cargo.lock[[package]]entries with a registry source.go.summodule lines (the/go.mod-only lines don't count).deno.lockjsrentries.crawl_unscoped_cachewarning, documented inCLI_CONTRACT.md.Each child deletes its whole-cache path from project mode and adds a test with an unrelated package in the fake cache that must not appear in
crawl_all.Acceptance criteria
--globaloutput is unchanged.Dependencies
Part of E36 (one
Inventory). The NuGet child benefits from the sharedpackages.lock.jsonwalker in #593 but doesn't need it. The FIFO fix #592 touches the same crawlers and should land first.