Skip to content

Fix: Workspace License Issues - #3

Merged
JosephMaynard merged 2 commits into
masterfrom
fix/workspace-licence-issues
Feb 1, 2026
Merged

JosephMaynard merged 2 commits into
masterfrom
fix/workspace-licence-issues

Conversation

@JosephMaynard

@JosephMaynard JosephMaynard commented Feb 1, 2026 •

Copy link
Copy Markdown
Owner

Summary by CodeRabbit

Release Notes

  • New Features
    • Added automatic detection for pnpm lock files during audit operations
    • Enhanced package resolution to support multiple resolve paths
    • Improved license file discovery and identification

✏️ Tip: You can customize this high-level summary in your review settings.

@coderabbitai

coderabbitai Bot commented Feb 1, 2026 •

Copy link
Copy Markdown
Contributor
📝 Walkthrough

Walkthrough

The pull request updates dependency resolution strategy by introducing a multi-path resolution mechanism for locating package.json files, adds license file detection to package metadata retrieval, and refactors npm audit execution to automatically detect and use pnpm or npm based on lock file presence.

Changes

Cohort / File(s) Summary
Metadata Updates
dependency-radar.json, report-ui/sample-data.json
Updated timestamp and branch reference; removed description field from sample data entry for vite@5.4.21.
Package Resolution Strategy
src/utils.ts, src/aggregator.ts
Introduced resolvePackageJsonPath() for multi-path resolution, updated readLicenseFromPackageJson() signature to accept resolvePaths array and return license file info alongside license field; aggregator now uses new resolver for license and metadata discovery.
NPM Audit Tool Detection
src/runners/npmAudit.ts
Added lock file detection logic (findLockDir()) to traverse directory tree and identify pnpm-lock.yaml, package-lock.json, or npm-shrinkwrap.json; selects appropriate tool (pnpm or npm) and sets working directory accordingly.

Sequence Diagrams

sequenceDiagram
    participant Aggregator as Aggregator
    participant Utils as Utils<br/>(resolvePackageJsonPath)
    participant FS as Filesystem
    participant LicenseHelper as License Helper<br/>(findLicenseFile)
    
    Aggregator->>Utils: resolvePackageJsonPath(pkgName, resolvePaths)
    Utils->>FS: Check multiple resolve paths
    FS-->>Utils: Return found path or undefined
    alt Path found
        Aggregator->>Utils: readLicenseFromPackageJson(pkgName, resolvePaths)
        Utils->>FS: Read package.json
        FS-->>Utils: Package metadata
        Utils->>LicenseHelper: findLicenseFile(directory)
        LicenseHelper->>FS: Search for license files
        FS-->>LicenseHelper: License file name or undefined
        LicenseHelper-->>Utils: Return license file
        Utils-->>Aggregator: {license, licenseFile}
    else Path not found
        Utils-->>Aggregator: undefined
    end
Loading
sequenceDiagram
    participant Runner as npmAudit Runner
    participant Detector as Lock File<br/>Detector
    participant FS as Filesystem
    participant Tool as Execution<br/>Tool
    
    Runner->>Detector: findLockDir(projectPath)
    Detector->>FS: Check for pnpm-lock.yaml
    FS-->>Detector: Found or not found
    alt pnpm lock found
        Detector->>FS: Confirm pnpm-lock.yaml exists
        FS-->>Detector: true
        Detector-->>Runner: lockDir, use pnpm
    else pnpm not found
        Detector->>FS: Check for npm locks
        FS-->>Detector: npm-lock or shrinkwrap found
        Detector-->>Runner: lockDir, use npm
    else no locks found
        Detector-->>Runner: undefined, use npm (fallback)
    end
    
    Runner->>Tool: Execute audit (selected tool, cwd)
    Tool-->>Runner: Parse JSON or capture output
Loading

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~22 minutes

Possibly related PRs

Poem

🐰 With whiskers twitching, quick and keen,
We bound through paths we've never seen,
Lock files leap and licenses shine,
pnpm and npm work in line!
Resolution paths now multiply so wide,
Our dependencies have nowhere to hide! ✨

🚥 Pre-merge checks | ✅ 2 | ❌ 1
❌ Failed checks (1 warning)
Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (2 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title 'Fix: Workspace License Issues' directly addresses the main objectives of the PR. The changes demonstrate fixes to license resolution in workspace environments by improving path resolution mechanisms and license detection across multiple files.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing touches
  • 📝 Generate docstrings
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch fix/workspace-licence-issues

Comment @coderabbitai help to get the list of available commands and usage tips.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant