Found during review of #97 (feat/85-swift-package-resolved). Disclosed there but not repaired, because the fix is a behaviour change to pin classification that belongs with registry support rather than inside a review repair.
What happens
crates/dependable-core/src/lockfiles/swift_package_resolved.rs, pin_item (~line 311).
A Package.resolved pin of "kind": "registry" — the SE-0292 package-registry kind — carries no location: a registry package is addressed by its scoped identity (mona.LinkedList), not by a repository URL.
pin_item treats only fileSystem and localSourceControl (or a location that looks like a local path) as local. A registry pin is therefore neither local nor location-bearing, so the name falls through to:
pin.location
.as_deref()
.map(swift_package_name)
.filter(|name| !name.is_empty())
.or_else(|| pin.identity.clone())?
which yields the bare registry identity, e.g. mona.linkedlist. It has a version, so it becomes PackageSource::Inherited — a checkable dependency.
That name is then queried against OSV's SwiftURL ecosystem, which is keyed by repository URL with no scheme and no .git (github.com/apple/swift-nio). A registry identity is not a repository URL and can never match that key.
Why it matters
The query cannot match, so the row reports clean, and nothing anywhere says the query was meaningless. This is the exact failure mode the Swift work exists to prevent: an answer that looks like "no advisories" when it is really "we asked a question that cannot be answered".
It is narrower than the general Swift caveat. Undetermined already says currency was never established, but the OSV verdict is the one verdict a Swift run does claim to give — and for a registry pin that claim is unfounded rather than merely absent.
Why it is Low today
Reachability, not correctness. No public SE-0292 registry has meaningful adoption, so "kind": "registry" is vanishingly rare in a real Package.resolved. That is a statement about likelihood, and it will stop being true if a registry lands.
Direction
Either:
- skip a
kind == "registry" pin outright, or
- give it a non-checkable source, so it is visible in the listing but never queried against
SwiftURL with an identifier that is not a URL.
Either way the row must not report clean off the back of a query that could not match.
Close this alongside whatever ships real registry support — at which point the pin gets a source that can actually be checked.
Reproduction
A Package.resolved containing:
{
"pins" : [
{
"identity" : "mona.linkedlist",
"kind" : "registry",
"state" : { "version" : "0.1.2" }
}
],
"version" : 2
}
The pin is read as a checkable dependency named mona.linkedlist and scanned as if it were a repository path.
Found during review of #97 (
feat/85-swift-package-resolved). Disclosed there but not repaired, because the fix is a behaviour change to pin classification that belongs with registry support rather than inside a review repair.What happens
crates/dependable-core/src/lockfiles/swift_package_resolved.rs,pin_item(~line 311).A
Package.resolvedpin of"kind": "registry"— the SE-0292 package-registry kind — carries nolocation: a registry package is addressed by its scoped identity (mona.LinkedList), not by a repository URL.pin_itemtreats onlyfileSystemandlocalSourceControl(or alocationthat looks like a local path) as local. Aregistrypin is therefore neither local nor location-bearing, so the name falls through to:which yields the bare registry identity, e.g.
mona.linkedlist. It has aversion, so it becomesPackageSource::Inherited— a checkable dependency.That name is then queried against OSV's
SwiftURLecosystem, which is keyed by repository URL with no scheme and no.git(github.com/apple/swift-nio). A registry identity is not a repository URL and can never match that key.Why it matters
The query cannot match, so the row reports clean, and nothing anywhere says the query was meaningless. This is the exact failure mode the Swift work exists to prevent: an answer that looks like "no advisories" when it is really "we asked a question that cannot be answered".
It is narrower than the general Swift caveat.
Undeterminedalready says currency was never established, but the OSV verdict is the one verdict a Swift run does claim to give — and for a registry pin that claim is unfounded rather than merely absent.Why it is Low today
Reachability, not correctness. No public SE-0292 registry has meaningful adoption, so
"kind": "registry"is vanishingly rare in a realPackage.resolved. That is a statement about likelihood, and it will stop being true if a registry lands.Direction
Either:
kind == "registry"pin outright, orSwiftURLwith an identifier that is not a URL.Either way the row must not report clean off the back of a query that could not match.
Close this alongside whatever ships real registry support — at which point the pin gets a source that can actually be checked.
Reproduction
A
Package.resolvedcontaining:{ "pins" : [ { "identity" : "mona.linkedlist", "kind" : "registry", "state" : { "version" : "0.1.2" } } ], "version" : 2 }The pin is read as a checkable dependency named
mona.linkedlistand scanned as if it were a repository path.