summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorCan Eldem <celdem@gitlab.com>2020-02-24 14:15:16 +0000
committerCan Eldem <celdem@gitlab.com>2020-02-24 14:15:16 +0000
commit1bd03175f997d381eaac4b2d3756b5d179e697e5 (patch)
tree560b309ede2161c19af1c6989a7e2032333c8eb6
parent36e9f083880cfe4e886277c7242295f2506fad91 (diff)
parent7352e16643fed6ed96d5f63476efd4b4bce71c5f (diff)
Merge branch '199078-update-license-finder' into 'master'v2.5.0
Update license_finder gem to 6.0.0 See merge request gitlab-org/security-products/license-management!112
-rw-r--r--CHANGELOG.md4
-rw-r--r--Gemfile.lock8
-rw-r--r--lib/license/management.rb22
-rw-r--r--lib/license/management/python/pipenv.rb64
-rw-r--r--lib/license/management/python/pypi.rb44
-rw-r--r--lib/license/management/version.rb2
-rw-r--r--license-management.gemspec3
7 files changed, 9 insertions, 138 deletions
diff --git a/CHANGELOG.md b/CHANGELOG.md
index b2b8f7a..a17c714 100644
--- a/CHANGELOG.md
+++ b/CHANGELOG.md
@@ -1,5 +1,9 @@
# GitLab License management changelog
+## v2.5.0
+
+- Upgrade [LicenseFinder](https://github.com/pivotal/LicenseFinder/releases/tag/v6.0.0) to version `6.0.0` (!112)
+
## v2.4.3
- Add support for `gradlew` (!109)
diff --git a/Gemfile.lock b/Gemfile.lock
index 02a54aa..39c1142 100644
--- a/Gemfile.lock
+++ b/Gemfile.lock
@@ -1,9 +1,8 @@
PATH
remote: .
specs:
- license-management (2.4.3)
- license_finder (~> 5.11)
- net-hippie (~> 0.3)
+ license-management (2.5.0)
+ license_finder (~> 6.0)
GEM
remote: https://rubygems.org/
@@ -13,14 +12,13 @@ GEM
diff-lcs (1.3)
json-schema (2.8.1)
addressable (>= 2.4)
- license_finder (5.11.1)
+ license_finder (6.0.0)
bundler
rubyzip (>= 1, < 3)
thor
toml (= 0.2.0)
with_env (= 1.1.0)
xml-simple
- net-hippie (0.3.2)
parslet (1.8.2)
public_suffix (4.0.3)
rspec (3.9.0)
diff --git a/lib/license/management.rb b/lib/license/management.rb
index ebab5e2..37fe1a0 100644
--- a/lib/license/management.rb
+++ b/lib/license/management.rb
@@ -6,8 +6,6 @@ require 'json'
require 'license_finder'
require 'license/management/loggable'
require 'license/management/verifiable'
-require 'license/management/python/pipenv'
-require 'license/management/python/pypi'
require 'license/management/repository'
require 'license/management/report'
require 'license/management/version'
@@ -15,26 +13,6 @@ require 'license/management/version'
# This applies a monkey patch to the JsonReport found in the `license_finder` gem.
LicenseFinder::JsonReport.prepend(License::Management::Report)
-# This monkey patch can be removed once https://github.com/pivotal/LicenseFinder/pull/659 is released
-LicenseFinder::Scanner.const_set(
- :PACKAGE_MANAGERS,
- LicenseFinder::Scanner::PACKAGE_MANAGERS + [License::Management::Pipenv]
-)
-
-# This monkey patch can be removed once we upgrade to license_finder 5.9.2. Details [here](https://gitlab.com/gitlab-org/gitlab/issues/13748#note_235810786).
-module LicenseFinder
- class Bundler < PackageManager
- def definition
- @definition ||=
- begin
- Dir.chdir(project_path.to_s) do
- ::Bundler::Definition.build(detected_package_path, lockfile_path, nil)
- end
- end
- end
- end
-end
-
module License
module Management
def self.root
diff --git a/lib/license/management/python/pipenv.rb b/lib/license/management/python/pipenv.rb
deleted file mode 100644
index 482fd25..0000000
--- a/lib/license/management/python/pipenv.rb
+++ /dev/null
@@ -1,64 +0,0 @@
-# frozen_string_literal: true
-
-module License
- module Management
- class Pipenv < LicenseFinder::PackageManager
- include Loggable
-
- def initialize(options = {})
- super
- @lockfile = Pathname('Pipfile.lock')
- end
-
- def current_packages
- @current_packages ||=
- begin
- packages = {}
- each_dependency(groups: allowed_groups) do |name, data, group|
- version = canonicalize(data['version'])
- package = packages.fetch(key_for(name, version)) do |key|
- packages[key] = build_package_for(name, version)
- end
- package.groups << group
- end
- packages.values
- end
- end
-
- def possible_package_paths
- project_path ? [project_path.join(@lockfile)] : [@lockfile]
- end
-
- private
-
- def each_dependency(groups: [])
- dependencies = JSON.parse(IO.read(detected_package_path))
- groups.each do |group|
- dependencies[group].each do |name, data|
- yield name, data, group
- end
- end
- end
-
- def canonicalize(version)
- version.sub(/^==/, '')
- end
-
- def build_package_for(name, version)
- LicenseFinder::PipPackage.new(name, version, PyPI.definition(name, version))
- end
-
- def key_for(name, version)
- "#{name}-#{version}"
- end
-
- def allowed_groups
- %w[default develop] - ignored_groups
- end
-
- def ignored_groups
- @ignored_groups.to_a || []
- end
- end
- end
-end
diff --git a/lib/license/management/python/pypi.rb b/lib/license/management/python/pypi.rb
deleted file mode 100644
index 0397532..0000000
--- a/lib/license/management/python/pypi.rb
+++ /dev/null
@@ -1,44 +0,0 @@
-# frozen_string_literal: true
-
-require 'net/hippie'
-
-module License
- module Management
- class PyPI
- include Loggable
-
- def initialize(http)
- @http = http
- end
-
- def definition_for(name, version)
- uri = "https://pypi.org/pypi/#{name}/#{version}/json"
- process(@http.with_retry { |client| client.get(uri) }).tap do |definition|
- log_info([name, version, definition["license"]].inspect)
- end
- rescue *Net::Hippie::CONNECTION_ERRORS
- {}
- end
-
- class << self
- def definition(name, version)
- @pypi ||= new(License::Management.http)
- @pypi.definition_for(name, version)
- end
- end
-
- private
-
- def process(response)
- return JSON.parse(response.body).fetch('info', {}) if ok?(response)
-
- log_error([response.class, response.code, response.body].inspect)
- {}
- end
-
- def ok?(response)
- response.is_a?(Net::HTTPSuccess)
- end
- end
- end
-end
diff --git a/lib/license/management/version.rb b/lib/license/management/version.rb
index 7c4b598..69fb69d 100644
--- a/lib/license/management/version.rb
+++ b/lib/license/management/version.rb
@@ -2,6 +2,6 @@
module License
module Management
- VERSION = '2.4.3'
+ VERSION = '2.5.0'
end
end
diff --git a/license-management.gemspec b/license-management.gemspec
index 60ab5e1..9acbcaf 100644
--- a/license-management.gemspec
+++ b/license-management.gemspec
@@ -27,8 +27,7 @@ Gem::Specification.new do |spec|
spec.executables = spec.files.grep(%r{^exe/}) { |f| File.basename(f) }
spec.require_paths = ['lib']
- spec.add_dependency 'license_finder', '~> 5.11'
- spec.add_dependency 'net-hippie', '~> 0.3'
+ spec.add_dependency 'license_finder', '~> 6.0'
spec.add_development_dependency 'json-schema', '~> 2.8'
spec.add_development_dependency 'rspec', '~> 3.9'
end