Repository navigation
refactor: adopt bomly-sdk v0.13.0's package split - #476
Conversation
v0.13.0 dissolves the SDK root package into model (the domain types), plugin (the component contract), runtime (the managed-plugin transport), and httpkit (outbound HTTP policy). Every identifier keeps its name; only the package that owns it changes. The SDK contract is imported as sdkplugin inside internal/plugin, whose own package is named plugin. The one change that is not a move: guardcheck's analyzers matched the graph and the detection result against a single SDK import path, and those types now live in two packages, so the rules name modelPath and pluginPath respectively. Its fake-SDK testdata splits to match. The embedded plugin modules still pin releases built against the old layout, so their requires must be bumped once those repositories tag. Co-Authored-By: Claude Opus 5 <[email protected]>
|
Important Review skippedToo many files! This PR contains 335 files, which is 235 over the limit of 100. To get a review, reduce the PR to 100 files or fewer by splitting it into smaller PRs or changing its base branch. Upgrade to a paid plan to raise the limit. Usage-priced reviews support at most 300 files. ⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Advanced Run ID: ⛔ Files ignored due to path filters (8)
📒 Files selected for processing (335)
You can disable this status message by setting the Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Bomly Diff SummaryCompared Overview
Dependency ChangesSummary: 0 added, 10 version changed, 0 detail changes, 0 removed. Changed Dependencies
Vulnerabilities✅ No vulnerability changes. License Changes✅ No license changes. Project Posture✅ No project posture changes ( Policy Findings✅ No policy differences were identified. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 66d6ac21bf
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
The four how-to guides, PLUGINS.md, REACHABILITY.md, and SCAN_TARGETS.md
are the documented starting point for plugin authors, and every example
imported the SDK root package that v0.13.0 removes. Each symbol now names
the package that owns it, and each example imports only the packages it
uses.
The detector guide additionally taught sdk.NewDependency(sdk.Dependency{})
and node.ID, an API that predates v0.13.0 and no longer exists in any
package. Both sites now use model.NewDependencyNode, which is the only
mint for a node's identity, handle its error, and join edges on NodeID().
The main example in the auditor, detector, and matcher guides was compiled
against the released v0.13.0 to check this; the analyzer example does the
same bar one helper it leaves to the reader.
Co-Authored-By: Claude Opus 5 <[email protected]>
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 7e1a3fc3b9
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Each embedded plugin has released a version compiled against the split packages, so the pins move together with the SDK bump this branch already carries. Their exported types changed identity rather than shape, which is why every bump is a minor. depsdev-license-matcher v0.2.2 -> v0.3.0 govulncheck-analyzer v0.3.2 -> v0.4.0 grype-matcher v0.5.0 -> v0.6.0 jsreach-analyzer v0.3.2 -> v0.4.0 jvmreach-analyzer v0.3.2 -> v0.4.0 osv-matcher v0.2.2 -> v0.3.0 pyreach-analyzer v0.3.2 -> v0.4.0 scorecard-matcher v0.2.2 -> v0.3.0 syft-detector v0.5.0 -> v0.6.0 The branch now builds, vets under every build tag, and tests green without a workspace override. Co-Authored-By: Claude Opus 5 <[email protected]>
…symbols The guide text named plugin, model, and runtime while every href still targeted the dissolved root package, so a reader following the link landed where none of the listed symbols are documented. Each reference now links the packages it actually names. Co-Authored-By: Claude Opus 5 <[email protected]>
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 1b7d622fdf
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
…the split API in guard remedies Two fragments of the detector guide are pasted into its `package plugin` example, which imports the SDK contract as sdkplugin to avoid colliding with the plugin's own package; both still selected plugin.*, so a reader following them could not compile. (`plugin.Module()` in the main blocks is the plugin's own package and is left alone.) The purlstring guard told developers to build a package URL with sdk.BuildPackageURLFor, a function v0.13.0's split leaves in no package, so following the diagnostic produced another compile error; it now names model.BuildPackageURLFor. Two analyzer doc comments citing sdk.Graph and sdk.DetectionResult are corrected the same way. Co-Authored-By: Claude Opus 5 <[email protected]>
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 54abafb68a
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Both guards matched `sdk.*` selectors resolved against the removed root package, so after the v0.13.0 bump they matched nothing: a direct PackageRegistry.Get in a presentation surface and a direct NewModuleNode in the Python detectors would both have been accepted in silence. That is the worst failure mode for a house rule, since nothing goes red. Verified by stripping the //nolint markers from the two permitted call sites: with these patterns both rules report, and with the previous root-targeted patterns neither does. The purl-type remedies named sdk.BuildPackageURLFor, which the split leaves in no package, so they name model.BuildPackageURLFor now, as does the depguard note that explains why detectors may not hold purlkit directly. Co-Authored-By: Claude Opus 5 <[email protected]>
Summary
bomly-sdk v0.13.0 dissolves the SDK root package into four, split by the question each answers. Every identifier keeps its name; only the package that owns it moves:
sdk.)model.Detector/Matcher/Auditor/Analyzer,Base*,*Descriptor,*Request/*Result,Module,HostContext,ConfigSchemaFor,PluginKind*,ExecutionTarget,Subproject,Consolidated*plugin.ServeModule,Serve*,Client,HandshakeConfig,ClientPluginMap,EnvPluginID,DecodePluginConfigFromEnvruntime.HTTPClientProvider,HTTPClientConfig,NewHTTPClientProvider*,EnvHTTP*httpkit.ClientProvider,httpkit.ClientConfig,httpkit.NewClientProvider*,httpkit.EnvHTTP*324 files were requalified with the SDK's migration tooling, which type-checks each package against the old single-package layout to learn what every
sdk.Xreference actually is, then rewrites it to the package that owns it now. Insideinternal/plugin, whose own package is namedplugin, the SDK contract is imported assdkplugin. Embedded plugin fixture sources (raw strings a test compiles) were rewritten by the same name table.The changes that are not moves
The guard analyzers.
internal/tools/guardcheck/analyzersmatched both the graph and the detection result against a single SDK import path. Those types are now in two packages, sosdkPathbecomesmodelPath(Graph) andpluginPath(DetectionResult), and the fake-SDK tree undertestdata/srcsplits the same way.The plugin authoring guides. The four
docs/plugins/how-to-implement-*.mdguides,docs/PLUGINS.md,docs/REACHABILITY.md, anddocs/SCAN_TARGETS.mdare the documented starting point for plugin authors, and every example imported the root package v0.13.0 removes. Each symbol now names its owning package, and each example imports only what it uses. The detector guide additionally taughtsdk.NewDependency(sdk.Dependency{})andnode.ID, an API that predates v0.13.0 and exists in no package; both sites now usemodel.NewDependencyNode, handle its error, and join edges onNodeID().Plugin releases
Every embedded plugin has released a build against the split packages, and the pins move with the SDK bump. Their exported types changed identity rather than shape, so each is a minor bump:
That is the release order the SDK's AGENTS.md prescribes: the SDK tags, plugin repositories adopt the tag, then this repository updates its pins.
Verification
Standalone, with no workspace override and everything resolved from the module proxy:
go build ./...andgo vet ./..., plusgo vetunder each ofsmoke,bomly_external_syft, andbomly_external_grype.go test ./...passes, guardcheck's analyzer suite included, andgofmtreports nothing.🤖 Generated with Claude Code