Skip to content

Commit

Permalink
SQRP-221 Add sca_releases table splitting out part of sca_dependencies
Browse files Browse the repository at this point in the history
This will allow us to do paginated queries of releases instead of dependencies.

In this commit, the behavior of the dependencies endpoint is not changed;
this commit sets it up to be change-able, but just keeps it the same for
the time being.
  • Loading branch information
havocp authored and sonartech committed Feb 19, 2025
1 parent c5c17d4 commit d2d0cb7
Show file tree
Hide file tree
Showing 35 changed files with 1,502 additions and 250 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -19,19 +19,32 @@
*/
package org.sonar.ce.common.sca;

import java.util.Collection;
import java.util.List;
import org.sonar.db.sca.ScaDependencyDto;
import org.sonar.db.sca.ScaReleaseDto;

public interface ScaHolder {
void setDependencies(List<ScaDependencyDto> dependencies);
void setDependencies(Collection<ScaDependencyDto> dependencies);

/**
* Get the dependencies of this ScaHolder. This is an error
* to call if dependencyAnalysisPresent() returns false.
*
* @return the dependencies found by the analysis
*/
List<ScaDependencyDto> getDependencies();

void setReleases(Collection<ScaReleaseDto> releases);

/**
* Get the releases of this ScaHolder. This is an error
* to call if dependencyAnalysisPresent() returns false.
*
* @return the releases found by the analysis
*/
List<ScaReleaseDto> getReleases();

/**
* Returns true if we were able to analyze dependencies.
* If we were not able, then the other getters can't return
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -19,16 +19,18 @@
*/
package org.sonar.ce.common.sca;

import org.sonar.db.sca.ScaDependencyDto;

import java.util.Collection;
import java.util.List;
import java.util.Optional;
import org.sonar.db.sca.ScaDependencyDto;
import org.sonar.db.sca.ScaReleaseDto;

public class ScaHolderImpl implements ScaHolder {
private List<ScaDependencyDto> dependencies = null;
private List<ScaReleaseDto> releases = null;

@Override
public void setDependencies(List<ScaDependencyDto> dependencies) {
public void setDependencies(Collection<ScaDependencyDto> dependencies) {
this.dependencies = List.copyOf(dependencies);
}

Expand All @@ -37,10 +39,18 @@ public List<ScaDependencyDto> getDependencies() {
return Optional.ofNullable(this.dependencies).orElseThrow(() -> new IllegalStateException("SCA dependency analysis was not performed"));
}

@Override
public void setReleases(Collection<ScaReleaseDto> releases) {
this.releases = List.copyOf(releases);
}

@Override
public List<ScaReleaseDto> getReleases() {
return Optional.ofNullable(this.releases).orElseThrow(() -> new IllegalStateException("SCA dependency analysis was not performed"));
}

@Override
public boolean dependencyAnalysisPresent() {
// for the time being, we just go by whether dependencies were set.
// When we add more data that can be set by ScaStep, we might store this differently.
return this.dependencies != null;
return this.dependencies != null && this.releases != null;
}
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,89 @@
/*
* SonarQube
* Copyright (C) 2009-2025 SonarSource SA
* mailto:info AT sonarsource DOT com
*
* This program is free software; you can redistribute it and/or
* modify it under the terms of the GNU Lesser General Public
* License as published by the Free Software Foundation; either
* version 3 of the License, or (at your option) any later version.
*
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
* Lesser General Public License for more details.
*
* You should have received a copy of the GNU Lesser General Public License
* along with this program; if not, write to the Free Software Foundation,
* Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.
*/
package org.sonar.ce.common.sca;

import java.util.Collection;
import java.util.List;
import org.junit.jupiter.api.Test;
import org.sonar.db.sca.PackageManager;
import org.sonar.db.sca.ScaDependencyDto;
import org.sonar.db.sca.ScaReleaseDto;

import static org.assertj.core.api.Assertions.assertThat;

class ScaHolderImplTest {
@Test
void test_setAndGetDependencies() {
ScaHolderImpl scaHolderImpl = new ScaHolderImpl();
var dep = newScaDependencyDto();
Collection<ScaDependencyDto> dependencies = List.of(dep);
scaHolderImpl.setDependencies(dependencies);
List<ScaDependencyDto> result = scaHolderImpl.getDependencies();
assertThat(result).containsExactly(dep);
}

@Test
void test_setAndGetReleases() {
ScaHolderImpl scaHolderImpl = new ScaHolderImpl();
var release = newScaReleaseDto();
Collection<ScaReleaseDto> releases = List.of(release);
scaHolderImpl.setReleases(releases);
List<ScaReleaseDto> result = scaHolderImpl.getReleases();
assertThat(result).containsExactly(release);
}

@Test
void test_dependencyAnalysisPresent() {
ScaHolderImpl scaHolderImpl = new ScaHolderImpl();
assertThat(scaHolderImpl.dependencyAnalysisPresent()).isFalse();
var dep = newScaDependencyDto();
var release = newScaReleaseDto();
Collection<ScaDependencyDto> dependencies = List.of(dep);
Collection<ScaReleaseDto> releases = List.of(release);
scaHolderImpl.setDependencies(dependencies);
assertThat(scaHolderImpl.dependencyAnalysisPresent()).isFalse();
scaHolderImpl.setReleases(releases);
assertThat(scaHolderImpl.dependencyAnalysisPresent()).isTrue();
}

private static ScaDependencyDto newScaDependencyDto() {
return new ScaDependencyDto("scaDependencyUuid",
"scaReleaseUuid",
true,
"compile",
"some/path",
"another/path",
1L,
2L);
}

private static ScaReleaseDto newScaReleaseDto() {
return new ScaReleaseDto("scaReleaseUuid",
"componentUuid",
"packageUrl",
PackageManager.MAVEN,
"foo:bar",
"1.0.0",
"MIT",
true,
1L,
2L);
}
}
Original file line number Diff line number Diff line change
Expand Up @@ -108,6 +108,7 @@ public final class SqTables {
"rules_profiles",
"rule_repositories",
"sca_dependencies",
"sca_releases",
"scanner_analysis_cache",
"schema_migrations",
"scim_groups",
Expand Down
Loading

0 comments on commit d2d0cb7

Please sign in to comment.