|
10 | 10 | require "dependabot/service" |
11 | 11 | require "dependabot/updater/error_handler" |
12 | 12 | require "dependabot/updater/operations/create_group_update_pull_request" |
| 13 | +require "dependabot/updater/group_dependency_selector" |
13 | 14 | require "dependabot/dependency_change_builder" |
14 | 15 | require "dependabot/notices" |
15 | 16 |
|
|
173 | 174 | create_group_update_pull_request.perform |
174 | 175 | end |
175 | 176 | end |
| 177 | + |
| 178 | + context "when GroupDependencySelector filtering is enabled" do |
| 179 | + let(:dependency_b) do |
| 180 | + Dependabot::Dependency.new( |
| 181 | + name: "dummy-pkg-b", |
| 182 | + version: "1.0.0", |
| 183 | + requirements: [{ |
| 184 | + file: "Gemfile", |
| 185 | + requirement: "~> 1.0.0", |
| 186 | + groups: ["default"], |
| 187 | + source: nil |
| 188 | + }], |
| 189 | + package_manager: "bundler", |
| 190 | + metadata: { all_versions: ["1.0.0"] } |
| 191 | + ) |
| 192 | + end |
| 193 | + |
| 194 | + let(:dependency_group) do |
| 195 | + Dependabot::DependencyGroup.new( |
| 196 | + name: "dummy-group", |
| 197 | + rules: { "patterns" => ["dummy-pkg-a"] } |
| 198 | + ) |
| 199 | + end |
| 200 | + |
| 201 | + let(:stub_dependency_change_with_multiple_deps) do |
| 202 | + Dependabot::DependencyChange.new( |
| 203 | + job: job, |
| 204 | + updated_dependencies: [dependency, dependency_b], |
| 205 | + updated_dependency_files: [] |
| 206 | + ) |
| 207 | + end |
| 208 | + |
| 209 | + before do |
| 210 | + Dependabot::Experiments.register(:group_membership_enforcement, true) |
| 211 | + # Mock the job to allow all updates for simplicity |
| 212 | + allow(job).to receive(:allowed_update?).and_return(true) |
| 213 | + end |
| 214 | + |
| 215 | + it "filters out dependencies not in the group" do |
| 216 | + # Override the dependency change builder to return our test change |
| 217 | + allow(create_group_update_pull_request).to receive(:compile_all_dependency_changes_for) |
| 218 | + .with(dependency_group) |
| 219 | + .and_return(stub_dependency_change_with_multiple_deps) |
| 220 | + |
| 221 | + result = create_group_update_pull_request.send(:dependency_change) |
| 222 | + |
| 223 | + # Only dummy-pkg-a should remain after filtering (dummy-pkg-b should be filtered out) |
| 224 | + expect(result.updated_dependencies.map(&:name)).to eq(["dummy-pkg-a"]) |
| 225 | + end |
| 226 | + |
| 227 | + it "does not filter when group_membership_enforcement is disabled" do |
| 228 | + Dependabot::Experiments.register(:group_membership_enforcement, false) |
| 229 | + |
| 230 | + # Override the dependency change builder to return our test change |
| 231 | + allow(create_group_update_pull_request).to receive(:compile_all_dependency_changes_for) |
| 232 | + .with(dependency_group) |
| 233 | + .and_return(stub_dependency_change_with_multiple_deps) |
| 234 | + |
| 235 | + result = create_group_update_pull_request.send(:dependency_change) |
| 236 | + |
| 237 | + # Both dependencies should remain when filtering is disabled |
| 238 | + expect(result.updated_dependencies.map(&:name)).to contain_exactly("dummy-pkg-a", "dummy-pkg-b") |
| 239 | + end |
| 240 | + |
| 241 | + it "handles empty dependency changes gracefully" do |
| 242 | + empty_change = Dependabot::DependencyChange.new( |
| 243 | + job: job, |
| 244 | + updated_dependencies: [], |
| 245 | + updated_dependency_files: [] |
| 246 | + ) |
| 247 | + |
| 248 | + allow(create_group_update_pull_request).to receive(:compile_all_dependency_changes_for) |
| 249 | + .with(dependency_group) |
| 250 | + .and_return(empty_change) |
| 251 | + |
| 252 | + result = create_group_update_pull_request.send(:dependency_change) |
| 253 | + |
| 254 | + expect(result.updated_dependencies).to be_empty |
| 255 | + end |
| 256 | + |
| 257 | + it "preserves dependency files during filtering" do |
| 258 | + dependency_file = instance_double( |
| 259 | + Dependabot::DependencyFile, |
| 260 | + name: "Gemfile.lock", |
| 261 | + directory: "." |
| 262 | + ) |
| 263 | + change_with_files = Dependabot::DependencyChange.new( |
| 264 | + job: job, |
| 265 | + updated_dependencies: [dependency, dependency_b], |
| 266 | + updated_dependency_files: [dependency_file] |
| 267 | + ) |
| 268 | + |
| 269 | + allow(create_group_update_pull_request).to receive(:compile_all_dependency_changes_for) |
| 270 | + .with(dependency_group) |
| 271 | + .and_return(change_with_files) |
| 272 | + |
| 273 | + result = create_group_update_pull_request.send(:dependency_change) |
| 274 | + |
| 275 | + # Files should be preserved even after dependency filtering |
| 276 | + expect(result.updated_dependency_files).to eq([dependency_file]) |
| 277 | + end |
| 278 | + end |
176 | 279 | end |
177 | 280 | end |
178 | 281 | end |
0 commit comments