feat(graph): resolve full dependency graph directly from .zpkg.toml - #530
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What changed
Adds
zed graph localas a read-only prospective resolver for a local.zpkg.toml, aimed at AI/tooling that needs the whole selected dependency graph before install or lockfile mutation.Fast path
view=declaredgraph metadata instead of downloading/extracting every package artifact just to inspect its manifestanalysis_digest--runtime-onlyprojects runtime edges[overrides.path]Hardening
zpkg/dependency-graph/v1JSON plus semantic digest and validates a present digest response header--allow-artifact-fallback) and visible in output statsContract/output
The prospective output intentionally uses
zpkg/local-dependency-graph/v1rather than pretending to be an authoritative resolved graph. Pre-lock analysis does not yet have the registry-snapshot + lock provenance required by the canonical resolvedzpkg/dependency-graph/v1contract.Tests/docs
Adds solver tests for diamond deduplication, backtracking, cycles, and the operational-error/backtracking boundary; extends the flags2env contract tests for the new command; adds
docs/dependency-graph-cli.mdwith AI/tooling usage and safety semantics.Audit finding behind the change
Existing
zed tree --jsonis lock/materialization-oriented, while install resolution discovers transitive dependencies through package artifacts. The registry/interface layer already exposes immutable declared graph metadata specifically suited to a local resolver, so this PR adds that missing analysis path without changingzed graph packagebyte-preserving behavior.CI status
Exact-head policy/contract checks including agents policy, formal review procedure, flags2env forward compatibility, and the package-graph contract validation reach their expected validation stages. Rust build/test jobs are currently blocked before rustc by the repository's committed
Cargo.lockbeing out of sync withCargo.toml:cargo check --locked --all-targetsexits withcannot update the lock file ... because --locked was passed. This is present at the base revision as well; this PR does not weaken--lockedor modify the lockfile blindly. A temporary branch-only diagnostic workflow was removed and is not part of the final diff.