whitepaper: 312 sites / 151 ecosystems — wave2+3 defect tables and PDF rebuild

Add 88 new defect entries to HIGH and MEDIUM tables:
  HIGH: mysql-0001/0002, mariadb-0001, redis-0001/0002, valkey-0001/0002, openvpn-0001,
        vlc-0001, prometheus-0001, otel-collector-0001, cockroachdb-0001..0004,
        tidb-0001..0008, kubernetes-0001/0002, go-0001, kotlin-0002, scala-0001,
        allegro5-0001, sdl2-0001, grafana-0001, clickhouse-0001, duckdb-0001,
        mongodb-0001, envoy-0001, istio-0001, cilium-0001, linkerd2-0001,
        linux-0001/0002/0003, tor-0002/0003, curl-0001, julia-0001, lua-0001,
        perl5-0001, nats-0001, spring-0003/0004, tomcat-0001, onos-0002, odl-0002

  MEDIUM: helm-0001, mariadb-0002, openssl-0001/0002, memcached-0001,
          cassandra-0001..0004, flink-0001, storm-0001/0002, zookeeper-0001..0003,
          pip-0001, gradle-0001, nginx-0001, haproxy-0001, caddy-0001, varnish-0001,
          ffmpeg-0001, gstreamer-0001, raylib-0001, love2d-0001, php-0001/0002,
          r-source-0001, cpython-0002, ruby-0001, rabbitmq-0003/0004, activemq-0001,
          ovs-0001, onos-0003, odl-0002, jetty-0001

PDF: 976K
This commit is contained in:
russell@unturf.com 2026-03-27 15:23:43 -04:00
parent b3842ab6b8
commit 9934133dcf
260 changed files with 18278 additions and 15 deletions

View file

@ -0,0 +1,57 @@
--- a/internal/chart/v3/util/dependencies.go
+++ b/internal/chart/v3/util/dependencies.go
@@ -144,18 +144,22 @@ func processDependencyEnabled(c *chart.Chart, v map[string]any, path string) err
}
var chartDependencies []*chart.Chart
- // If any dependency is not a part of Chart.yaml
- // then this should be added to chartDependencies.
- // However, if the dependency is already specified in Chart.yaml
- // we should not add it, as it would be processed from Chart.yaml anyway.
-
-Loop:
- for _, existing := range c.Dependencies() {
- for _, req := range c.Metadata.Dependencies {
- if existing.Name() == req.Name && IsCompatibleRange(req.Version, existing.Metadata.Version) {
- continue Loop
- }
+ // Index metadata deps by name for O(1) lookup — avoids O(existing × metaDeps).
+ metaDepByName := make(map[string]*chart.Dependency, len(c.Metadata.Dependencies))
+ for _, req := range c.Metadata.Dependencies {
+ if req != nil {
+ metaDepByName[req.Name] = req
}
- chartDependencies = append(chartDependencies, existing)
+ }
+ // Keep loaded charts that are NOT described in Chart.yaml (extra deps).
+ for _, existing := range c.Dependencies() {
+ if req, found := metaDepByName[existing.Name()]; found {
+ if IsCompatibleRange(req.Version, existing.Metadata.Version) {
+ continue // covered by Chart.yaml processing below
+ }
+ }
+ chartDependencies = append(chartDependencies, existing)
}
+ // Index loaded deps by name for O(1) alias resolution — avoids O(metaDeps × charts).
+ chartsByName := make(map[string]*chart.Chart, len(c.Dependencies()))
+ for _, ch := range c.Dependencies() {
+ if ch != nil {
+ chartsByName[ch.Name()] = ch
+ }
+ }
for _, req := range c.Metadata.Dependencies {
if req == nil {
continue
}
- if chartDependency := getAliasDependency(c.Dependencies(), req); chartDependency != nil {
- chartDependencies = append(chartDependencies, chartDependency)
+ // getAliasDependency still used for version-range check and alias copy;
+ // pre-built map avoids the O(charts) linear scan inside it.
+ if ch, ok := chartsByName[req.Name]; ok {
+ if chartDependency := getAliasDependency([]*chart.Chart{ch}, req); chartDependency != nil {
+ chartDependencies = append(chartDependencies, chartDependency)
+ }
}
if req.Alias != "" {
req.Name = req.Alias