renovate/lib/manager/pub
2019-11-23 21:44:55 +01:00
..
extract.ts chore(manager): add more type annotations (#4344) 2019-08-22 17:42:35 +02:00
index.ts feat(manager): convert to typescript (#4148) 2019-07-25 08:17:19 +02:00
readme.md docs: update docs and app references 2019-08-27 13:11:25 +02:00
update.ts refactor(eslint): fix eslint warnings in manager (#4865) 2019-11-23 21:44:55 +01:00

Overview

Name of package manager

pub


Implementation status

Beta


What language does this support?

Dart / Flutter SDK


Does that language have other (competing?) package managers?

No.

Package File Detection

What type of package files and names does it use?

pubspec.yaml


What fileMatch pattern(s) should be used?

(^|\/)pubspec\.yaml$


Is it likely that many users would need to extend this pattern for custom file names?

No


Is the fileMatch pattern likely to get many "false hits" for files that have nothing to do with package management?

No

Parsing and Extraction

Yes

Is there reason why package files need to be parsed together (in serial) instead of independently?

No


What format/syntax is the package file in? e.g. JSON, TOML, custom?

YAML


How do you suggest parsing the file? Using an off-the-shelf parser, using regex, or can it be custom-parsed line by line?

Use YAML parser like JS-YAML


Does the package file structure distinguish between different "types" of dependencies? e.g. production dependencies, dev dependencies, etc?

Yes, dependencies and dev-dependencies.

More details in: https://www.dartlang.org/tools/pub/dependencies

Example from https://github.com/brianegan/flutter_architecture_samples/blob/master/example/firestore_redux/pubspec.yaml:

environment:
  sdk: '>=2.0.0 <3.0.0'

dependencies:
  meta: '>=1.1.0 <2.0.0'
  redux: ^3.0.0
  flutter_redux: ^0.5.0
  flutter:
    sdk: flutter
  flutter_architecture_samples:
    path: ../../
  firebase_flutter_repository:
    path: ../firebase_flutter_repository

dev_dependencies:
  test: ^1.3.0
  mockito: ^3.0.0
  flutter_driver:
    sdk: flutter
  flutter_test:
    sdk: flutter
  integration_tests:
    path: ../integration_tests
  todos_repository_flutter:
    path: ../todos_repository_flutter

List all the sources/syntaxes of dependencies that can be extracted:

  • SDK

    dependencies:
      flutter_driver:
        sdk: flutter
        version: ^0.0.1
    
  • Version constraints

    dependencies:
      meta: '>=1.1.0 <2.0.0'
      flutter_redux: 0.5.0
    
  • Caret syntax

    dependencies:
      redux: ^3.0.0
    
  • Git packages

    dependencies:
      kittens:
        git: git://github.com/munificent/kittens.git
    
    dependencies:
      kittens:
        git: git@github.com:munificent/kittens.git
    
    dependencies:
      kittens:
        git:
          url: git://github.com/munificent/kittens.git
          ref: some-branch
    
    dependencies:
      kittens:
        git:
          url: git://github.com/munificent/cats.git
          path: path/to/kittens
    
  • Path packages

    dependencies:
      transmogrify:
        path: /Users/me/transmogrify
    
  • Hosted packages

    dependencies:
      transmogrify:
        hosted:
          name: transmogrify
          url: http://your-package-server.com
        version: ^1.4.0
    

Describe which types of dependencies above are supported and which will be implemented in future:

All

Versioning

What versioning scheme do the package files use?

https://www.dartlang.org/tools/pub/dependencies


Does this versioning scheme support range constraints, e.g. ^1.0.0 or 1.x?

Yes


Is this package manager used for applications, libraries, or both? If both, is there a way to tell which is which?

Both. No.


If ranges are supported, are there any cases when Renovate should pin ranges to exact versions if rangeStrategy=auto?

Dev dependencies can always be pinned.

Lookup

Is a new datasource required? Provide details

We'll need to support the pub API as a new datasource. Example URL: pub.dartlang.org/api/packages/url_launcher


Will users need the capability to specify a custom host/registry to look up? Can it be found within the package files, or within other files inside the repository, or would it require Renovate configuration?

Yes

A registry can be specified in pubspec.yaml with:

dependencies:
  transmogrify:
    hosted:
      name: transmogrify
      url: http://your-package-server.com
    version: ^1.4.0

Do the package files contain any "constraints" on the parent language (e.g. supports only v3.x of Python) or platform (Linux, Windows, etc) that should be used in the lookup procedure?

Yes, SDK version can be defined using:

environment:
  sdk: '>=2.0.0 <3.0.0'

Will users need the ability to configure language or other constraints using Renovate config?

No

Artifacts

Are lock files or checksum files used? Mandatory?

Yes and yes, in pubspec.lock.


If so, what tool and exact commands should be used if updating 1 or more package versions in a dependency file?

Update all dependencies:

flutter packages upgrade

Update 1 dependency is not supported by a command. The package needs to be changed with the version number in pubspec.yaml and then run flutter packages upgrade.


If applicable, describe how the tool maintains a cache and if it can be controlled via CLI or env? Do you recommend the cache be kept or disabled/ignored?


If applicable, what command should be used to generate a lock file from scratch if you already have a package file? This will be used for "lock file maintenance".

flutter packages get

Other

Is there anything else to know about this package manager?

The information here refers to the Flutter SDK package manager, which is built on top of Dart's pub package manager but differs in some ways.

More info: