Skip to content

Fix Yarn lockfile matching for ranges containing spaces - #16367

Open
jtlopezdev wants to merge 4 commits into
dependabot:mainfrom
jtlopezdev:codex/yarn-descriptor-lookup
Open

jtlopezdev wants to merge 4 commits into
dependabot:mainfrom
jtlopezdev:codex/yarn-descriptor-lookup

Conversation

@jtlopezdev

@jtlopezdev jtlopezdev commented Sep 22, 2026 •

Copy link
Copy Markdown
Contributor

What are you trying to accomplish?

Fix Yarn lockfile lookup when a package has multiple entries and the requested range contains spaces. The existing yarn_berry/no_lockfile_change fixture contains separate aproba entries for ^1.0.3 and ^1.0.3 || ^2.0.0; looking up the latter currently returns no match instead of the locked version 2.0.0.

Compare complete descriptors instead of extracting a range only up to its first whitespace character. This also fixes comparator ranges such as >= 1.5.0 < 2 in composite lockfile keys and prevents a short requirement from falsely matching the prefix of a longer range.

Related context: #4701. This fixes Yarn descriptor lookup when several lockfile entries exist; it does not resolve the broader multi-version aggregation/update behavior discussed there.

Anything you want to highlight for special attention from reviewers?

The change is limited to Yarn lockfile lookup and parser specs. It preserves the single-entry fallback and supports both bare and npm: descriptors. Four examples use unchanged repository lockfile fixtures to cover OR ranges, comparator ranges, scoped names, and lookup of the second descriptor in a composite key. Two small helper-result examples cover rejection of incomplete descriptor prefixes and bare descriptors containing spaces. The fixture comments explain why multiple candidate entries must remain present.

How will you know you've accomplished your goal?

Verified in an isolated Linux Docker checkout with networking disabled and seed 16367:

  • With the pre-fix implementation: 85 parser examples, with exactly four expected failures (the OR range, comparator range, false prefix, and bare OR range); the other 81 pass.
  • With this change: 85 parser examples, zero failures, including native Yarn helper execution.
  • 631 parser, fetcher, package-manifest updater/preparer, and requirement-updater examples, with zero failures and one existing git-lfs pending example.
  • All three changed files pass RuboCop.
  • Repository production Sorbet checking passes using the lockfile-pinned sorbet-static 0.6.13449 binary, sorbet/config, and the checked-in RBIs. This checks production types; it does not run the workflow's RBI regeneration/coverage steps.

The full repository/ecosystem suite is outside this verification scope. Upstream workflows have started for the current head; full CI verification remains in progress. The earlier reviewed commit reported action_required.

Checklist

  • I have run the complete test suite to ensure all tests and linters pass.
  • I have thoroughly tested my code changes to ensure they work as expected, including adding additional tests for new functionality.
  • I have written clear and descriptive commit messages.
  • I have provided a detailed description of the changes in the pull request, including the problem it addresses, how it fixes the problem, and any relevant details about the implementation.
  • I have ensured that the code is well-documented and easy to understand.

When multiple lockfile entries exist for a package, the range scan stops
at whitespace and cannot find OR or comparator requirements. Compare
complete descriptors while preserving the single-entry fallback.

Exercise the public lockfile lookup with existing fixtures and cover
scoped names, unmatched ranges, and composite descriptor separators.
@jtlopezdev
jtlopezdev marked this pull request as ready for review September 22, 2026 13:11
@jtlopezdev
jtlopezdev requested a review from a team as a code owner September 22, 2026 13:11
@v-abhishekbhaskar v-abhishekbhaskar moved this to Scoping in Dependabot Sep 23, 2026
Cover incomplete range prefixes and bare descriptors with spaces through the public lookup API. Document complete-descriptor matching and the fixture dependency on multiple candidates, and restore the ignored parser spec's original type sigil.

Validate 631 focused examples with no failures and one existing pending example. Confirm both new regressions fail with the pre-fix matcher; run RuboCop and production Sorbet checking against checked-in RBIs.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

Status: Scoping

Development

Successfully merging this pull request may close these issues.

2 participants