Commit 421b4f1
fix(go): handle replace directives in go list -m all parsing (#468)
## Summary
- Fix `go list -m all` parsing in
`GoModulesProvider.getFinalPackagesVersionsForModule()` to handle Go
replace directives (5-part format: `name v1 => replacement v2`)
- Extract `parseModuleVersions()` method mirroring JS client PR #505
- Add replace directive test fixture to `go_mod_light_no_ignore` and
update expected SBOM
Implements [TC-4359](https://redhat.atlassian.net/browse/TC-4359)
## Test plan
- [x] All 18 Go module tests pass (all 6 parameterized folders, both
stack and component analysis)
- [x] `go_mod_no_path` fixture with no-op replace still passes
- [x] MVS-related tests pass (`Test_Golang_MvS_Logic_Disabled`,
`Test_Golang_MvS_Enabled_Preserves_All_Transitive_Dependencies`)
- [x] `mvn spotless:apply` passes (code formatted)
- [x] `mvn verify` passes (only pre-existing Python env failures)
🤖 Generated with [Claude Code](https://claude.com/claude-code)
[TC-4359]:
https://redhat.atlassian.net/browse/TC-4359?atlOrigin=eyJpIjoiNWRkNTljNzYxNjVmNDY3MDlhMDU5Y2ZhYzA5YTRkZjUiLCJwIjoiZ2l0aHViLWNvbS1KU1cifQ
## Summary by Sourcery
Handle Go module replace directives when resolving final package
versions from `go list -m all` output.
Bug Fixes:
- Correct resolution of final Go module versions by supporting replace
directive lines in `go list -m all` output.
Enhancements:
- Extract shared `parseModuleVersions` helper to parse `go list -m all`
output into a module-to-version map.
Tests:
- Extend Go module test fixtures with a replace directive example and
update the expected SBOM for stack analysis to cover the new behavior.
---------
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>1 parent bbeb043 commit 421b4f1
4 files changed
Lines changed: 112 additions & 10 deletions
File tree
- src
- main/java/io/github/guacsec/trustifyda/providers
- test
- java/io/github/guacsec/trustifyda/providers
- resources/tst_manifests/golang/go_mod_light_no_ignore
Lines changed: 20 additions & 6 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
347 | 347 | | |
348 | 348 | | |
349 | 349 | | |
350 | | - | |
351 | | - | |
352 | | - | |
353 | | - | |
354 | | - | |
355 | | - | |
| 350 | + | |
356 | 351 | | |
357 | 352 | | |
358 | 353 | | |
| |||
387 | 382 | | |
388 | 383 | | |
389 | 384 | | |
| 385 | + | |
| 386 | + | |
| 387 | + | |
| 388 | + | |
| 389 | + | |
| 390 | + | |
| 391 | + | |
| 392 | + | |
| 393 | + | |
| 394 | + | |
| 395 | + | |
| 396 | + | |
| 397 | + | |
| 398 | + | |
| 399 | + | |
| 400 | + | |
| 401 | + | |
| 402 | + | |
| 403 | + | |
390 | 404 | | |
391 | 405 | | |
392 | 406 | | |
| |||
Lines changed: 86 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
Lines changed: 4 additions & 4 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
263 | 263 | | |
264 | 264 | | |
265 | 265 | | |
266 | | - | |
| 266 | + | |
267 | 267 | | |
268 | 268 | | |
269 | | - | |
270 | | - | |
| 269 | + | |
| 270 | + | |
271 | 271 | | |
272 | 272 | | |
273 | 273 | | |
| |||
497 | 497 | | |
498 | 498 | | |
499 | 499 | | |
500 | | - | |
| 500 | + | |
501 | 501 | | |
502 | 502 | | |
503 | 503 | | |
| |||
Lines changed: 2 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
6 | 6 | | |
7 | 7 | | |
8 | 8 | | |
| 9 | + | |
| 10 | + | |
0 commit comments