Files
mesh-catalog/modules/gitea/cmd/npm-registry/refs_test.go
T
jochen a378abc758 gitea: say what keeps each npm version and delete only what nothing names (hq ADR 0251)
Every publish added a version and nothing removed one. A Go bundle beside the
TypeScript one keeps what a lockfile or a range on the forge names, what a
dist-tag names and the newest five; a dry run unless asked with a why, and
nothing deleted while any repository is unread.
2026-10-08 12:00:48 +02:00

93 lines
3.4 KiB
Go

package main
import (
"sort"
"strings"
"testing"
)
var knownHere = map[string]bool{"@novox/mesh-sdk": true, "@novox/ui": true, "sdk": true}
func pins(ps []Pinned) string {
var out []string
for _, p := range ps {
out = append(out, p.Package+"@"+p.Version)
}
sort.Strings(out)
return strings.Join(out, " ")
}
func TestAManifestNamesItsRegistryRangesAndNothingElse(t *testing.T) {
got, err := ReadManifest([]byte(`{
"dependencies": {"@novox/mesh-sdk": "^0.1.0", "left-pad": "^1.0.0", "@novox/ui": "file:../ui"},
"devDependencies": {"sdk": "npm:@novox/ui@~2.0.0"},
"peerDependencies": {"@novox/ui": "workspace:*"},
"optionalDependencies": {"@novox/ui": "1.x"}
}`), "r:package.json", knownHere)
if err != nil {
t.Fatal(err)
}
var said []string
for _, w := range got {
said = append(said, w.Package+" "+w.Range)
}
sort.Strings(said)
if strings.Join(said, ",") != "@novox/mesh-sdk ^0.1.0,@novox/ui 1.x,@novox/ui ~2.0.0" {
t.Fatalf("read %v", said)
}
}
func TestAnNpmLockfileOfEveryVersionNamesWhatItPins(t *testing.T) {
v3 := `{"lockfileVersion":3,"packages":{"":{"name":"x"},
"node_modules/@novox/mesh-sdk":{"version":"0.1.3"},
"node_modules/a/node_modules/@novox/mesh-sdk":{"version":"0.1.1"},
"node_modules/sdk":{"name":"@novox/ui","version":"2.0.4"},
"node_modules/left-pad":{"version":"1.3.0"}}}`
got, err := ReadLock("package-lock.json", []byte(v3), "r:package-lock.json", knownHere)
if err != nil {
t.Fatal(err)
}
if pins(got) != "@novox/mesh-sdk@0.1.1 @novox/mesh-sdk@0.1.3 @novox/ui@2.0.4" {
t.Fatalf("v3: %s", pins(got))
}
v1 := `{"lockfileVersion":1,"dependencies":{"@novox/mesh-sdk":{"version":"0.1.2","dependencies":{"@novox/ui":{"version":"1.0.0"}}},
"sdk":{"version":"npm:@novox/ui@2.0.1"}}}`
got, err = ReadLock("npm-shrinkwrap.json", []byte(v1), "r", knownHere)
if err != nil {
t.Fatal(err)
}
if pins(got) != "@novox/mesh-sdk@0.1.2 @novox/ui@1.0.0 @novox/ui@2.0.1" {
t.Fatalf("v1: %s", pins(got))
}
if _, err := ReadLock("package-lock.json", []byte("{not json"), "r", knownHere); err == nil {
t.Fatal("a broken lockfile read as empty")
}
}
func TestAYarnLockOfEitherFormatNamesWhatItPins(t *testing.T) {
classic := "# yarn lockfile v1\n\n\"@novox/mesh-sdk@^0.1.0\", \"@novox/mesh-sdk@^0.1.2\":\n version \"0.1.4\"\n resolved \"x\"\n dependencies:\n left-pad \"^1\"\n\nleft-pad@^1:\n version \"1.3.0\"\n"
if got := pins(readYarnLock([]byte(classic), "r", knownHere)); got != "@novox/mesh-sdk@0.1.4" {
t.Fatalf("classic: %s", got)
}
berry := "__metadata:\n version: 6\n\n\"@novox/ui@npm:^2.0.0\":\n version: 2.0.7\n resolution: \"@novox/ui@npm:2.0.7\"\n"
if got := pins(readYarnLock([]byte(berry), "r", knownHere)); got != "@novox/ui@2.0.7" {
t.Fatalf("berry: %s", got)
}
}
func TestAPnpmLockNamesWhatItPinsInEachFormat(t *testing.T) {
lock := "lockfileVersion: '9.0'\npackages:\n '@novox/mesh-sdk@0.1.5':\n resolution: {}\n /@novox/ui/2.0.2:\n resolution: {}\n /@other/novox/ui@9.9.9:\n /x-sdk@1.0.0:\n"
if got := pins(readTextLock([]byte(lock), "r", knownHere)); got != "@novox/mesh-sdk@0.1.5 @novox/ui@2.0.2" {
t.Fatalf("pnpm: %s", got)
}
}
func TestOnlyTheRepositorysOwnManifestsAreRead(t *testing.T) {
for p, want := range map[string]bool{"package.json": true, "modules/x/package-lock.json": true, "yarn.lock": true,
"pnpm-lock.yaml": true, "node_modules/a/package.json": false, "README.md": false, "a/package.json.bak": false} {
if interesting(p) != want {
t.Errorf("%s: %v", p, !want)
}
}
}