Skip to content

Feature: fixes issue #20 by adding support for cargo - #48

Open
georgbramm wants to merge 24 commits into
mainfrom
feat/cargo-support
Open

georgbramm wants to merge 24 commits into
mainfrom
feat/cargo-support

Conversation

@georgbramm

Copy link
Copy Markdown
Contributor

Covers every core component of Cargo's dependency specification syntax, hopefully =)

  • Standard caret requirements (^1.2.3)
  • Zero-major and zero-minor caret expansions (^0.2.3, ^0.0.3)
  • Tilde requirements (~1.2.3)
  • Wildcards (, 1., 1.2.*)
  • Explicit comparison operators with partial version padding (>=1.2, <=2)
  • Multiple comma-separated constraints per segment (>=1.2,<1.5)
  • Pipe-delimited disjunctions (|)
  • Pre-release and metadata version tags (-alpha.1)
    Addresses Add support for cargo #20

@tziemek tziemek linked an issue Aug 7, 2026 that may be closed by this pull request
@peinjoh

peinjoh commented Aug 10, 2026

Copy link
Copy Markdown
Contributor

Thank you for you contribution, I'll get to reviewing this later 👍

@tziemek tziemek left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think we should clarify the usage of type specific comparators in vers strings before continuing the PRs for the additional types.
This would then lead to a simpler parsing of the version range, because the type specific version comparators would only be relevant for the from_native functions and not for general validation or contains checks.

Comment thread src/schemes/cargo.rs Outdated
Comment thread src/schemes/cargo.rs Outdated
Comment thread src/range/dynamic.rs Outdated
@georgbramm
georgbramm marked this pull request as draft August 14, 2026 09:57
@peinjoh peinjoh mentioned this pull request Sep 2, 2026
@georgbramm
georgbramm marked this pull request as ready for review September 14, 2026 12:40
Comment thread src/schemes/cargo.rs Outdated
fn from_native(raw: &str) -> Result<Vec<VersionConstraint<Self>>, VersError> {
if raw.bytes().any(|b| b == b'\t' || b == b'\n' || b == b'\r') {
return Err(VersError::InvalidConstraint(
"Literal whitespace not allowed".to_string(),

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We should probably have a better error message here. These are not strictly whitespaces and whitespaces should be allowed in native strings. NPM for example, needs them to represent version ranges.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

i updated the error message in 7864096 to be more precise.

@tziemek

tziemek commented Sep 15, 2026

Copy link
Copy Markdown
Contributor

Do you plan to fix the usage of parse_native for canonical parsing in a separate PR?

@georgbramm

Copy link
Copy Markdown
Contributor Author

Do you plan to fix the usage of parse_native for canonical parsing in a separate PR?

I try to fix it in this PR

@georgbramm

Copy link
Copy Markdown
Contributor Author

VersVersionRange::from_str now correctly parses standard universal vers syntax (using VersionConstraint::parse), enforcing strict rules such as prohibiting ecosystem-native shorthands or explicit leading = in canonical URIs.
Native parsing logic (from_native / parse_native) remains fully intact and isolated for ecosystem-specific inputs (like Cargo carets/tildes or Debian's << / >>). Updated Debian test suit.

@tziemek tziemek left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Priority 1, as those are needed for CSAF:

  • Fix JSON round trip
  • Fix prerelease ordering

Priority 2:

  • fix native parsing

We can also leave native parsing open for the moment, but we should then add some info to the readme that it is not working correctly, would be fine with me.

Comment thread src/range/dynamic.rs Outdated
Comment thread src/range/dynamic.rs Outdated
Comment thread src/range/dynamic.rs
Comment thread src/range/dynamic.rs Outdated
Comment thread src/schemes/cargo.rs Outdated
Comment thread src/schemes/cargo.rs
Comment thread src/schemes/cargo.rs Outdated
Comment thread src/schemes/cargo.rs Outdated
Comment thread src/range/dynamic.rs
Comment thread src/range/dynamic.rs Outdated
/// detecting the versioning scheme and constructing the appropriate typed
/// version range internally.
///
///impl<'de> serde::de::Deserialize<'de> for DynamicVersionRange {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

That's some stray text in the comment

Suggested change
///impl<'de> serde::de::Deserialize<'de> for DynamicVersionRange {
///

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

fixed in 60f9e30

Comment thread src/schemes/cargo.rs
Comment thread src/schemes/deb.rs

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Maybe we could also use https://crates.io/crates/debversion here?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

i will check it out tomorrow and continue the integration using the mentioned crates

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

using debversion now in 26be663

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add support for cargo

3 participants