From fb69e7fc1c8bbd99eae6534eda00adb73e66e4c1 Mon Sep 17 00:00:00 2001 From: Facundo Rodriguez Date: Mon, 21 Sep 2026 11:03:42 -0300 Subject: [PATCH] fix(eol): expose dependency summary on scan components --- README.md | 3 ++- src/types/eol-scan.test.ts | 34 ++++++++++++++++++++++++++++++++++ src/types/eol-scan.ts | 9 +++++++++ 3 files changed, 45 insertions(+), 1 deletion(-) create mode 100644 src/types/eol-scan.test.ts diff --git a/README.md b/README.md index df5a5a5..9362a7e 100644 --- a/README.md +++ b/README.md @@ -89,7 +89,8 @@ The package exports the following TypeScript types: - `UnknownComponentMetadata` - Metadata for an unknown/unresolvable component, carrying only an `unknownReason` - `ComponentMetadata` - Union of `EolScanComponentMetadata` and `UnknownComponentMetadata`; the type of `EolScanComponent.metadata` - `UnknownReason` - Reason a component is unknown (`not_identifiable`, `no_listed_versions`, `unsupported_ecosystem`, `queued`) -- `EolScanComponent` - Component data for EOL scanning with metadata, PURL, and optional NES remediation +- `DependencySummary` - Dependency graph classification for a component; individual classifications may be unknown, while a `null` summary means the SBOM graph could not be parsed +- `EolScanComponent` - Component data for EOL scanning with metadata, PURL, dependency summary, and optional remediation details - `EolReportMetadata` - Report-level metadata including component counts - `EolReport` - Complete EOL scan report with components and metadata - `EolReportQueryResponse` - GraphQL response type for EOL report queries diff --git a/src/types/eol-scan.test.ts b/src/types/eol-scan.test.ts new file mode 100644 index 0000000..6c4c375 --- /dev/null +++ b/src/types/eol-scan.test.ts @@ -0,0 +1,34 @@ +import type { DependencySummary, EolScanComponent } from './eol-scan.js'; + +type Equal = + (() => Value extends Left ? 1 : 2) extends < + Value, + >() => Value extends Right ? 1 : 2 + ? true + : false; + +type Assert = Condition; + +export type DependencySummaryMatchesApiContract = Assert< + Equal< + DependencySummary, + { + directDependency: boolean | null; + transitiveDependency: boolean | null; + prodDependency: boolean | null; + devDependency: boolean | null; + dependencies: string[]; + } + > +>; + +export type ComponentDependencySummaryMatchesApiContract = Assert< + Equal +>; + +export type ComponentDependencySummaryIsRequired = Assert< + Equal< + {} extends Pick ? true : false, + false + > +>; diff --git a/src/types/eol-scan.ts b/src/types/eol-scan.ts index e514f2f..6245baf 100644 --- a/src/types/eol-scan.ts +++ b/src/types/eol-scan.ts @@ -88,9 +88,18 @@ export interface Remediation { target?: RemediationTarget; } +export interface DependencySummary { + directDependency: boolean | null; + transitiveDependency: boolean | null; + prodDependency: boolean | null; + devDependency: boolean | null; + dependencies: string[]; +} + export interface EolScanComponent { metadata: ComponentMetadata | null; purl: string; + dependencySummary: DependencySummary | null; nesRemediation?: NesRemediation | null; remediations?: Remediation[] | null; }