Skip to content

refactor: adopt bomly-sdk v0.13.0's package split - #476

Merged
bomly-guy merged 6 commits into
mainfrom
claude/sdk-v013-migration
Sep 17, 2026
Merged

bomly-guy merged 6 commits into
mainfrom
claude/sdk-v013-migration

Conversation

@bomly-guy

@bomly-guy bomly-guy commented Sep 16, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

bomly-sdk v0.13.0 dissolves the SDK root package into four, split by the question each answers. Every identifier keeps its name; only the package that owns it moves:

Before (sdk.) After
graph, node, package, registry, vulnerability, vocabulary, scope, origin, digest, contact, normalization, merge, policy types model.
Detector/Matcher/Auditor/Analyzer, Base*, *Descriptor, *Request/*Result, Module, HostContext, ConfigSchemaFor, PluginKind*, ExecutionTarget, Subproject, Consolidated* plugin.
ServeModule, Serve*, Client, HandshakeConfig, ClientPluginMap, EnvPluginID, DecodePluginConfigFromEnv runtime.
HTTPClientProvider, HTTPClientConfig, NewHTTPClientProvider*, EnvHTTP* httpkit.ClientProvider, httpkit.ClientConfig, httpkit.NewClientProvider*, httpkit.EnvHTTP*

324 files were requalified with the SDK's migration tooling, which type-checks each package against the old single-package layout to learn what every sdk.X reference actually is, then rewrites it to the package that owns it now. Inside internal/plugin, whose own package is named plugin, the SDK contract is imported as sdkplugin. Embedded plugin fixture sources (raw strings a test compiles) were rewritten by the same name table.

The changes that are not moves

The guard analyzers. internal/tools/guardcheck/analyzers matched both the graph and the detection result against a single SDK import path. Those types are now in two packages, so sdkPath becomes modelPath (Graph) and pluginPath (DetectionResult), and the fake-SDK tree under testdata/src splits the same way.

The plugin authoring guides. The four docs/plugins/how-to-implement-*.md guides, docs/PLUGINS.md, docs/REACHABILITY.md, and docs/SCAN_TARGETS.md are the documented starting point for plugin authors, and every example imported the root package v0.13.0 removes. Each symbol now names its owning package, and each example imports only what it uses. The detector guide additionally taught sdk.NewDependency(sdk.Dependency{}) and node.ID, an API that predates v0.13.0 and exists in no package; both sites now use model.NewDependencyNode, handle its error, and join edges on NodeID().

Plugin releases

Every embedded plugin has released a build against the split packages, and the pins move with the SDK bump. Their exported types changed identity rather than shape, so each is a minor bump:

Module Before After
depsdev-license-matcher v0.2.2 v0.3.0
govulncheck-analyzer v0.3.2 v0.4.0
grype-matcher v0.5.0 v0.6.0
jsreach-analyzer v0.3.2 v0.4.0
jvmreach-analyzer v0.3.2 v0.4.0
osv-matcher v0.2.2 v0.3.0
pyreach-analyzer v0.3.2 v0.4.0
scorecard-matcher v0.2.2 v0.3.0
syft-detector v0.5.0 v0.6.0

That is the release order the SDK's AGENTS.md prescribes: the SDK tags, plugin repositories adopt the tag, then this repository updates its pins.

Verification

Standalone, with no workspace override and everything resolved from the module proxy:

  • go build ./... and go vet ./..., plus go vet under each of smoke, bomly_external_syft, and bomly_external_grype.
  • go test ./... passes, guardcheck's analyzer suite included, and gofmt reports nothing.
  • The main example in the auditor, detector, and matcher guides was extracted and compiled against the released v0.13.0; the analyzer example does the same but for one helper it leaves to the reader.

🤖 Generated with Claude Code

v0.13.0 dissolves the SDK root package into model (the domain types),
plugin (the component contract), runtime (the managed-plugin transport),
and httpkit (outbound HTTP policy). Every identifier keeps its name; only
the package that owns it changes. The SDK contract is imported as
sdkplugin inside internal/plugin, whose own package is named plugin.

The one change that is not a move: guardcheck's analyzers matched the
graph and the detection result against a single SDK import path, and
those types now live in two packages, so the rules name modelPath and
pluginPath respectively. Its fake-SDK testdata splits to match.

The embedded plugin modules still pin releases built against the old
layout, so their requires must be bumped once those repositories tag.

Co-Authored-By: Claude Opus 5 <[email protected]>
@coderabbitai

coderabbitai Bot commented Sep 16, 2026 •

Copy link
Copy Markdown
Contributor

Important

Review skipped

Too many files!

This PR contains 335 files, which is 235 over the limit of 100.

To get a review, reduce the PR to 100 files or fewer by splitting it into smaller PRs or changing its base branch.

Upgrade to a paid plan to raise the limit.

Usage-priced reviews support at most 300 files.

⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: 318124fc-9df4-474d-af15-084c740e60dc

📥 Commits

Reviewing files that changed from the base of the PR and between f91eacc and 05c6d33.

⛔ Files ignored due to path filters (8)
  • go.sum is excluded by !**/*.sum
  • internal/tools/guardcheck/analyzers/testdata/src/github.com/bomly-dev/bomly-cli/internal/attributed/a.go is excluded by !**/testdata/**
  • internal/tools/guardcheck/analyzers/testdata/src/github.com/bomly-dev/bomly-cli/internal/detectors/attribution.go is excluded by !**/testdata/**
  • internal/tools/guardcheck/analyzers/testdata/src/github.com/bomly-dev/bomly-cli/internal/nodeinsert/a.go is excluded by !**/testdata/**
  • internal/tools/guardcheck/analyzers/testdata/src/github.com/bomly-dev/bomly-cli/internal/nodeinsert/b_test.go is excluded by !**/testdata/**
  • internal/tools/guardcheck/analyzers/testdata/src/github.com/bomly-dev/bomly-sdk/detectorkit/nodes.go is excluded by !**/testdata/**
  • internal/tools/guardcheck/analyzers/testdata/src/github.com/bomly-dev/bomly-sdk/model/model.go is excluded by !**/testdata/**
  • internal/tools/guardcheck/analyzers/testdata/src/github.com/bomly-dev/bomly-sdk/plugin/plugin.go is excluded by !**/testdata/**
📒 Files selected for processing (335)
  • .golangci.yml
  • docs/PLUGINS.md
  • docs/REACHABILITY.md
  • docs/SCAN_TARGETS.md
  • docs/plugins/how-to-implement-analyzer.md
  • docs/plugins/how-to-implement-auditor.md
  • docs/plugins/how-to-implement-detector.md
  • docs/plugins/how-to-implement-matcher.md
  • go.mod
  • internal/auditors/license/auditor.go
  • internal/auditors/license/auditor_test.go
  • internal/auditors/license/spdx_policy_matrix_test.go
  • internal/auditors/package/auditor.go
  • internal/auditors/package/auditor_test.go
  • internal/auditors/vulnerability/auditor.go
  • internal/auditors/vulnerability/auditor_test.go
  • internal/auditors/vulnerability/policy_matrix_test.go
  • internal/baseline/baseline.go
  • internal/baseline/baseline_test.go
  • internal/baseline/identity_round_trip_test.go
  • internal/benchmark/run.go
  • internal/benchmark/run_test.go
  • internal/benchmark/summary.go
  • internal/benchmark/summary_test.go
  • internal/benchmark/targets.go
  • internal/benchmark/targets_test.go
  • internal/cli/baseline_cmd.go
  • internal/cli/baseline_cmd_test.go
  • internal/cli/benchmark_run.go
  • internal/cli/benchmark_run_test.go
  • internal/cli/cmd_progress.go
  • internal/cli/cmd_progress_test.go
  • internal/cli/diff_cmd.go
  • internal/cli/diff_cmd_test.go
  • internal/cli/diff_resolve.go
  • internal/cli/explain_cmd.go
  • internal/cli/mcp_cmd.go
  • internal/cli/mcp_cmd_test.go
  • internal/cli/opts/filters.go
  • internal/cli/opts/filters_test.go
  • internal/cli/opts/options.go
  • internal/cli/opts/options_test.go
  • internal/cli/opts/planning.go
  • internal/cli/opts/planning_diagnostics.go
  • internal/cli/opts/planning_diagnostics_test.go
  • internal/cli/opts/planning_recursive.go
  • internal/cli/opts/planning_recursive_test.go
  • internal/cli/opts/planning_test.go
  • internal/cli/opts/registry.go
  • internal/cli/plugin_cmd.go
  • internal/cli/plugin_cmd_health_test.go
  • internal/cli/plugin_cmd_test.go
  • internal/cli/plugin_config_warnings.go
  • internal/cli/render/diff.go
  • internal/cli/render/diff_markdown.go
  • internal/cli/render/diff_markdown_test.go
  • internal/cli/render/diff_posture.go
  • internal/cli/render/explain_markdown.go
  • internal/cli/render/reachability_test.go
  • internal/cli/render/remediation.go
  • internal/cli/render/remediation_projection_test.go
  • internal/cli/render/scan.go
  • internal/cli/render/scan_findings_test.go
  • internal/cli/render/scan_warnings_test.go
  • internal/cli/render/scorecard_fields.go
  • internal/cli/render/scorecard_render_test.go
  • internal/cli/render/vulnerability_fields.go
  • internal/cli/scan_cmd.go
  • internal/cli/scan_cmd_test.go
  • internal/cli/scan_output.go
  • internal/cli/scan_output_test.go
  • internal/composition/composition.go
  • internal/composition/composition_full.go
  • internal/composition/composition_lite.go
  • internal/composition/composition_test.go
  • internal/detectors/attribution.go
  • internal/detectors/attribution_detectors_test.go
  • internal/detectors/attribution_test.go
  • internal/detectors/cargo/detector.go
  • internal/detectors/cargo/detector_test.go
  • internal/detectors/cargo/identity_test.go
  • internal/detectors/cargo/lock_index.go
  • internal/detectors/cargo/origin.go
  • internal/detectors/cargo/origin_test.go
  • internal/detectors/cargo/parser_fuzz_test.go
  • internal/detectors/cargo/positions.go
  • internal/detectors/cargo/remediation.go
  • internal/detectors/cargo/workspace.go
  • internal/detectors/cargo/workspace_test.go
  • internal/detectors/cocoapods/detector.go
  • internal/detectors/cocoapods/detector_test.go
  • internal/detectors/cocoapods/positions.go
  • internal/detectors/composer/detector.go
  • internal/detectors/composer/detector_test.go
  • internal/detectors/composer/positions.go
  • internal/detectors/composer/remediation.go
  • internal/detectors/conan/detector.go
  • internal/detectors/conan/detector_test.go
  • internal/detectors/conan/positions.go
  • internal/detectors/githubactions/detector.go
  • internal/detectors/githubactions/detector_test.go
  • internal/detectors/githubactions/positions.go
  • internal/detectors/gomod/attribution_test.go
  • internal/detectors/gomod/detector.go
  • internal/detectors/gomod/detector_test.go
  • internal/detectors/gomod/fixture_test.go
  • internal/detectors/gomod/parser_fuzz_test.go
  • internal/detectors/gomod/remediation.go
  • internal/detectors/gradle/detector.go
  • internal/detectors/gradle/detector_test.go
  • internal/detectors/gradle/fixture_test.go
  • internal/detectors/gradle/positions.go
  • internal/detectors/gradle/remediation.go
  • internal/detectors/maven/attribution_test.go
  • internal/detectors/maven/detector.go
  • internal/detectors/maven/detector_test.go
  • internal/detectors/maven/fixture_test.go
  • internal/detectors/maven/modules.go
  • internal/detectors/maven/modules_test.go
  • internal/detectors/maven/positions.go
  • internal/detectors/maven/remediation.go
  • internal/detectors/mix/detector.go
  • internal/detectors/mix/detector_test.go
  • internal/detectors/mix/positions.go
  • internal/detectors/node/bun/bun_lockfile.go
  • internal/detectors/node/bun/bun_lockfile_parser.go
  • internal/detectors/node/bun/bun_lockfile_parser_test.go
  • internal/detectors/node/bun/bun_lockfile_test.go
  • internal/detectors/node/bun/bun_native.go
  • internal/detectors/node/bun/bun_native_parser.go
  • internal/detectors/node/bun/bun_native_test.go
  • internal/detectors/node/bun/remediation.go
  • internal/detectors/node/common.go
  • internal/detectors/node/common_test.go
  • internal/detectors/node/graph_relationships.go
  • internal/detectors/node/graph_relationships_test.go
  • internal/detectors/node/lockfile_common.go
  • internal/detectors/node/lockfile_integration_test.go
  • internal/detectors/node/logging_test.go
  • internal/detectors/node/nodetest/fuzz.go
  • internal/detectors/node/npm/npm.go
  • internal/detectors/node/npm/npm_lockfile.go
  • internal/detectors/node/npm/npm_lockfile_attribution_test.go
  • internal/detectors/node/npm/npm_lockfile_parser.go
  • internal/detectors/node/npm/npm_lockfile_parser_test.go
  • internal/detectors/node/npm/npm_lockfile_workspaces_test.go
  • internal/detectors/node/npm/npm_native.go
  • internal/detectors/node/npm/npm_native_test.go
  • internal/detectors/node/npm/origin_test.go
  • internal/detectors/node/npm/positions.go
  • internal/detectors/node/npm/remediation.go
  • internal/detectors/node/origin_integration_test.go
  • internal/detectors/node/package_manager_warnings.go
  • internal/detectors/node/package_manager_warnings_fuzz_test.go
  • internal/detectors/node/package_manager_warnings_test.go
  • internal/detectors/node/pnpm/pnpm.go
  • internal/detectors/node/pnpm/pnpm_lockfile.go
  • internal/detectors/node/pnpm/pnpm_lockfile_parser.go
  • internal/detectors/node/pnpm/pnpm_lockfile_parser_test.go
  • internal/detectors/node/pnpm/pnpm_lockfile_workspaces_test.go
  • internal/detectors/node/pnpm/pnpm_native.go
  • internal/detectors/node/pnpm/pnpm_native_test.go
  • internal/detectors/node/pnpm/positions.go
  • internal/detectors/node/pnpm/remediation.go
  • internal/detectors/node/strategy.go
  • internal/detectors/node/yarn/positions.go
  • internal/detectors/node/yarn/remediation.go
  • internal/detectors/node/yarn/yarn.go
  • internal/detectors/node/yarn/yarn_lockfile.go
  • internal/detectors/node/yarn/yarn_lockfile_parser.go
  • internal/detectors/node/yarn/yarn_lockfile_parser_test.go
  • internal/detectors/node/yarn/yarn_native.go
  • internal/detectors/nuget/detector.go
  • internal/detectors/nuget/detector_test.go
  • internal/detectors/nuget/positions.go
  • internal/detectors/positions_extractors_test.go
  • internal/detectors/pub/detector.go
  • internal/detectors/pub/detector_test.go
  • internal/detectors/pub/origin_test.go
  • internal/detectors/pub/positions.go
  • internal/detectors/pub/pub_native.go
  • internal/detectors/python/common.go
  • internal/detectors/python/detector_test.go
  • internal/detectors/python/lockfile_integration_test.go
  • internal/detectors/python/origin.go
  • internal/detectors/python/origin_test.go
  • internal/detectors/python/pip.go
  • internal/detectors/python/pip_resolution_test.go
  • internal/detectors/python/pipenv.go
  • internal/detectors/python/piplock.go
  • internal/detectors/python/piplock_test.go
  • internal/detectors/python/poetry.go
  • internal/detectors/python/poetrylock.go
  • internal/detectors/python/positions_loose.go
  • internal/detectors/python/remediation.go
  • internal/detectors/python/resolution.go
  • internal/detectors/python/roots_test.go
  • internal/detectors/python/source_test.go
  • internal/detectors/python/uv.go
  • internal/detectors/python/uvlock.go
  • internal/detectors/python/venv.go
  • internal/detectors/ruby/detector.go
  • internal/detectors/ruby/detector_test.go
  • internal/detectors/ruby/origin_test.go
  • internal/detectors/ruby/parser_fuzz_test.go
  • internal/detectors/ruby/positions.go
  • internal/detectors/ruby/remediation.go
  • internal/detectors/sbom/detector.go
  • internal/detectors/sbom/detector_test.go
  • internal/detectors/sbt/detector.go
  • internal/detectors/sbt/detector_test.go
  • internal/detectors/sbt/positions.go
  • internal/detectors/sbt/sbt_native.go
  • internal/detectors/swiftpm/detector.go
  • internal/detectors/swiftpm/detector_test.go
  • internal/detectors/swiftpm/origin_test.go
  • internal/detectors/swiftpm/positions.go
  • internal/detectors/swiftpm/swiftpm_native.go
  • internal/engine/analyzer_test.go
  • internal/engine/consolidation/consolidation.go
  • internal/engine/consolidation/consolidation_fallback_test.go
  • internal/engine/consolidation/consolidation_test.go
  • internal/engine/consolidation/enrichment.go
  • internal/engine/consolidation/enrichment_test.go
  • internal/engine/consolidation/location_fold_test.go
  • internal/engine/consolidation/locations.go
  • internal/engine/consolidation/locations_test.go
  • internal/engine/consolidation/manifest.go
  • internal/engine/consolidation/modules.go
  • internal/engine/consolidation/modules_test.go
  • internal/engine/consolidation/origin_test.go
  • internal/engine/diff/diff.go
  • internal/engine/diff/diff_test.go
  • internal/engine/engine.go
  • internal/engine/engine_test.go
  • internal/engine/explain/why.go
  • internal/engine/explain/why_test.go
  • internal/engine/finding_policy.go
  • internal/engine/finding_policy_test.go
  • internal/engine/findings.go
  • internal/engine/findings_test.go
  • internal/engine/graph_accounting_invariants_test.go
  • internal/engine/graph_container.go
  • internal/engine/license_checker_test.go
  • internal/engine/match_eligibility.go
  • internal/engine/match_eligibility_test.go
  • internal/engine/package_updates_test.go
  • internal/engine/pipeline.go
  • internal/engine/pipeline_explain.go
  • internal/engine/pipeline_fallback_test.go
  • internal/engine/pipeline_logger_test.go
  • internal/engine/pipeline_network_intent_test.go
  • internal/engine/pipeline_resolve.go
  • internal/engine/pipeline_test.go
  • internal/engine/registry.go
  • internal/engine/test_compat_test.go
  • internal/engine/types.go
  • internal/engine/vulnerability_consolidation.go
  • internal/engine/vulnerability_consolidation_test.go
  • internal/mcp/classify.go
  • internal/mcp/compact_diff.go
  • internal/mcp/compact_diff_test.go
  • internal/mcp/compact_explain.go
  • internal/mcp/compact_limits_test.go
  • internal/mcp/compact_scan.go
  • internal/mcp/mcp_test.go
  • internal/mcp/remediation.go
  • internal/mcp/remediation_test.go
  • internal/mcp/server.go
  • internal/mcp/types_compact.go
  • internal/output/cross_surface_contract_test.go
  • internal/output/dependencies_graph_test.go
  • internal/output/findings_test.go
  • internal/output/hierarchy_test.go
  • internal/output/output_test.go
  • internal/output/policy_status_test.go
  • internal/output/registry_lookup.go
  • internal/output/registry_lookup_test.go
  • internal/output/remediation_projection_test.go
  • internal/output/sarif.go
  • internal/output/sarif_reachability_test.go
  • internal/output/sarif_test.go
  • internal/output/types.go
  • internal/output/types_test.go
  • internal/output/view.go
  • internal/output/view_fallback_test.go
  • internal/output/view_projection_test.go
  • internal/output/view_test.go
  • internal/plugin/analyzer_plugin_test.go
  • internal/plugin/env_test.go
  • internal/plugin/github_release_test.go
  • internal/plugin/http_test.go
  • internal/plugin/install.go
  • internal/plugin/plugin_test.go
  • internal/plugin/pool.go
  • internal/plugin/pool_test.go
  • internal/plugin/registry.go
  • internal/plugin/runtime/hashicorp/runtime.go
  • internal/plugin/test.go
  • internal/plugin/test_doctor_test.go
  • internal/plugin/types.go
  • internal/plugin/types_clone_test.go
  • internal/registry/builder.go
  • internal/registry/builder_test.go
  • internal/registry/discovery.go
  • internal/registry/discovery_test.go
  • internal/registry/module.go
  • internal/registry/module_test.go
  • internal/registry/remediation_ownership_test.go
  • internal/registry/support.go
  • internal/registry/support_test.go
  • internal/remediation/derive.go
  • internal/remediation/derive_test.go
  • internal/support/component_docs.go
  • internal/support/composition_docs_test.go
  • internal/support/support_matrix.go
  • internal/testnodes/testnodes.go
  • internal/tools/guardcheck/analyzers/analyzers.go
  • internal/tools/guardcheck/analyzers/attributed.go
  • internal/tools/guardcheck/analyzers/nodeinsert.go
  • internal/tools/guardcheck/analyzers/purlstring.go
  • internal/tui/diff.go
  • internal/tui/diff_aggregations_test.go
  • internal/tui/focus_test.go
  • internal/tui/posture.go
  • internal/tui/posture_diff.go
  • internal/tui/posture_test.go
  • internal/tui/remediation_details_test.go
  • internal/tui/scan.go
  • internal/tui/scan_test.go
  • internal/tui/tui.go
  • internal/tui/tui_test.go
  • internal/tui/utils.go
  • test/smoke/audit_test.go
  • test/smoke/fixture_compile_test.go

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Comment thread go.mod Fixed
@github-actions

github-actions Bot commented Sep 16, 2026 •

Copy link
Copy Markdown
Contributor

Bomly Diff Summary

Compared f91eacc8ea88a6b68637eabf6739b78fb02ecfa7 to 05c6d334310cacd69b64bf5434f9b1bf498edd4d.

Overview

Status Manifests Dependencies Findings Duration
✅ Pass +0 / ~1 / -0 0 added / 10 version changed / 0 detail changes / 0 removed 0 introduced / 0 persisted / 0 resolved 1m 18s

Dependency Changes

Summary: 0 added, 10 version changed, 0 detail changes, 0 removed.

Changed Dependencies

Change Package Version Direct? Scope Licenses
changed github.com/bomly-dev/bomly-plugin-depsdev-license-matcher v0.2.2 → v0.3.0 Yes runtime Apache-2.0
changed github.com/bomly-dev/bomly-plugin-govulncheck-analyzer v0.3.2 → v0.4.0 Yes runtime Apache-2.0
changed github.com/bomly-dev/bomly-plugin-grype-matcher v0.5.0 → v0.6.0 Yes runtime Apache-2.0
changed github.com/bomly-dev/bomly-plugin-jsreach-analyzer v0.3.2 → v0.4.0 Yes runtime Apache-2.0
changed github.com/bomly-dev/bomly-plugin-jvmreach-analyzer v0.3.2 → v0.4.0 Yes runtime Apache-2.0
changed github.com/bomly-dev/bomly-plugin-osv-matcher v0.2.2 → v0.3.0 Yes runtime Apache-2.0
changed github.com/bomly-dev/bomly-plugin-pyreach-analyzer v0.3.2 → v0.4.0 Yes runtime Apache-2.0
changed github.com/bomly-dev/bomly-plugin-scorecard-matcher v0.2.2 → v0.3.0 Yes runtime Apache-2.0
changed github.com/bomly-dev/bomly-plugin-syft-detector v0.5.0 → v0.6.0 Yes runtime Apache-2.0
changed github.com/bomly-dev/bomly-sdk v0.12.0 → v0.13.0 Yes runtime Apache-2.0

Vulnerabilities

✅ No vulnerability changes.

License Changes

✅ No license changes.

Project Posture

✅ No project posture changes (--matchers +scorecard was not selected).

Policy Findings

✅ No policy differences were identified.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 66d6ac21bf

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread go.mod
Comment thread go.mod
The four how-to guides, PLUGINS.md, REACHABILITY.md, and SCAN_TARGETS.md
are the documented starting point for plugin authors, and every example
imported the SDK root package that v0.13.0 removes. Each symbol now names
the package that owns it, and each example imports only the packages it
uses.

The detector guide additionally taught sdk.NewDependency(sdk.Dependency{})
and node.ID, an API that predates v0.13.0 and no longer exists in any
package. Both sites now use model.NewDependencyNode, which is the only
mint for a node's identity, handle its error, and join edges on NodeID().

The main example in the auditor, detector, and matcher guides was compiled
against the released v0.13.0 to check this; the analyzer example does the
same bar one helper it leaves to the reader.

Co-Authored-By: Claude Opus 5 <[email protected]>

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 7e1a3fc3b9

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread docs/plugins/how-to-implement-analyzer.md Outdated
bomly-guy and others added 2 commits September 16, 2026 19:34
Each embedded plugin has released a version compiled against the split
packages, so the pins move together with the SDK bump this branch already
carries. Their exported types changed identity rather than shape, which is
why every bump is a minor.

  depsdev-license-matcher  v0.2.2 -> v0.3.0
  govulncheck-analyzer     v0.3.2 -> v0.4.0
  grype-matcher            v0.5.0 -> v0.6.0
  jsreach-analyzer         v0.3.2 -> v0.4.0
  jvmreach-analyzer        v0.3.2 -> v0.4.0
  osv-matcher              v0.2.2 -> v0.3.0
  pyreach-analyzer         v0.3.2 -> v0.4.0
  scorecard-matcher        v0.2.2 -> v0.3.0
  syft-detector            v0.5.0 -> v0.6.0

The branch now builds, vets under every build tag, and tests green without
a workspace override.

Co-Authored-By: Claude Opus 5 <[email protected]>
…symbols

The guide text named plugin, model, and runtime while every href still
targeted the dissolved root package, so a reader following the link landed
where none of the listed symbols are documented. Each reference now links
the packages it actually names.

Co-Authored-By: Claude Opus 5 <[email protected]>

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 1b7d622fdf

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread docs/plugins/how-to-implement-detector.md Outdated
Comment thread go.mod
…the split API in guard remedies

Two fragments of the detector guide are pasted into its `package plugin`
example, which imports the SDK contract as sdkplugin to avoid colliding
with the plugin's own package; both still selected plugin.*, so a reader
following them could not compile. (`plugin.Module()` in the main blocks is
the plugin's own package and is left alone.)

The purlstring guard told developers to build a package URL with
sdk.BuildPackageURLFor, a function v0.13.0's split leaves in no package, so
following the diagnostic produced another compile error; it now names
model.BuildPackageURLFor. Two analyzer doc comments citing sdk.Graph and
sdk.DetectionResult are corrected the same way.

Co-Authored-By: Claude Opus 5 <[email protected]>

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 54abafb68a

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread go.mod
Both guards matched `sdk.*` selectors resolved against the removed root
package, so after the v0.13.0 bump they matched nothing: a direct
PackageRegistry.Get in a presentation surface and a direct NewModuleNode in
the Python detectors would both have been accepted in silence. That is the
worst failure mode for a house rule, since nothing goes red.

Verified by stripping the //nolint markers from the two permitted call
sites: with these patterns both rules report, and with the previous
root-targeted patterns neither does.

The purl-type remedies named sdk.BuildPackageURLFor, which the split leaves
in no package, so they name model.BuildPackageURLFor now, as does the
depguard note that explains why detectors may not hold purlkit directly.

Co-Authored-By: Claude Opus 5 <[email protected]>
@bomly-guy
bomly-guy merged commit ecf1c48 into main Sep 17, 2026
16 checks passed
@bomly-guy
bomly-guy deleted the claude/sdk-v013-migration branch September 17, 2026 06:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants