Skip to content

fix(engine): keep unpinned Go requires visible in build and scan - #335

Closed
vibgrate-team wants to merge 2 commits into
mainfrom
cursor/go-unpinned-requires-cbed
Closed

vibgrate-team wants to merge 2 commits into
mainfrom
cursor/go-unpinned-requires-cbed

Conversation

@vibgrate-team

@vibgrate-team vibgrate-team commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Summary

vg build and vg scan dropped a direct Go module when its go.mod require had no v-prefixed version. ingestGoMod only kept lines matching \S+\s+v\S+, and the Go scanner required a second token, so an omitted pin never became an edge or a dependency row.

This change keeps that module path for Go only:

  • The code graph records an import edge to the external module. Graph nodes still have no version field, so nothing is invented.
  • The scan row keeps the dependency with currentSpec and resolvedVersion set to null (and majorsBehind null). A real pin, including 0.0.0 or a version that does not start with v, is unchanged.
  • That row is excluded from the drift mean, so a missing version is not scored as current (absent stays distinct from zero).
  • SBOM export still emits the component. Its version stays the existing unknown sentinel, the purl has no @version, and the declared spec is omitted rather than written as "" or a guessed pin.

replace, exclude, and comments stay ignored. Indirect requires stay out of the scan's direct list, matching the scanner's existing filter, and still appear on the code graph.

Related issues

Fixes #215

Checklist

  • pnpm test passes
  • pnpm lint is clean
  • pnpm typecheck is clean
  • Docs updated (README / DOCS / ARCHITECTURE) where behavior changed
  • Determinism preserved — identical input still produces identical graph.json / report output (content-hashed IDs, stable sorts; no time, randomness, or filesystem-order dependence)
  • No proprietary or internal references — public, Apache-2.0 content only
  • Commits use Conventional Commits and are signed off (git commit -s, DCO)

Notes for reviewers

Verify with the Go fixture in src/engine/manifests.test.ts and src/core-open/scanners/go-scanner.test.ts: a bare require module is present, example.com/excluded and replace targets are not, and the unpinned row's version fields are null.

pnpm test (4901 passed), pnpm lint, and pnpm typecheck are green on this branch.

Open in Web Open in Cursor 

cursoragent and others added 2 commits October 3, 2026 22:01
A go.mod require without a v-prefixed version never became an edge, so
direct dependencies disappeared from vg build and vg scan. Record the
module path and leave the version null instead of inventing a pin.

Fixes #215

Signed-off-by: Cursor Agent <cursoragent@cursor.com>

Co-authored-by: support <support@bugben.ai>
isConcreteVersion now predicates string so an omitted require pin stays
on the unknown sentinel without a type error.

Signed-off-by: Cursor Agent <cursoragent@cursor.com>

Co-authored-by: support <support@bugben.ai>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Enhancement: keep direct dependencies without explicit version pins visible in vg scan graphs

2 participants