class Detector::Rust::Cli

Overview

Detects Rust command-line applications: crates depending on a CLI library (clap, structopt, argh, bpaf, pico-args, getopts) or source that derives a parser / uses std::env::args(). Gates the Rust CLI analyzer. Bare std::env::var(...) (config reads, common in web crates) does not qualify.

Defined in:

detector/detectors/rust/cli.cr

Constant Summary

BUILDER_CMD = /\bCommand::new\s*\(/
CARGO_CLI_DEP = /(?m)^\s*(?:clap|structopt|argh|bpaf|pico\-args|getopts)\b/

Single-pass alternation over CLI_CRATES — the previous per-crate interpolated literal recompiled (and rescanned) once per crate for every Cargo.toml.

CLI_CRATES = ["clap", "structopt", "argh", "bpaf", "pico-args", "getopts"]
DERIVE_ARGH = /#\[\s*derive\s*\([^)]*\bFromArgs\b/
DERIVE_PARSER = /#\[\s*derive\s*\([^)]*\b(?:Parser|Subcommand|Args)\b/
DERIVE_STRUCTOPT = /#\[\s*derive\s*\([^)]*\bStructOpt\b/
ENV_ARGS = /\b(?:std::)?env::args(?:_os)?\s*\(/
SOURCE_MARKER = Regex.union(DERIVE_PARSER, DERIVE_STRUCTOPT, DERIVE_ARGH, USE_CLI_LIB, ENV_ARGS)

Single-pass union of the standalone source markers (the clap-builder check below stays separate: it is gated on includes?("clap")). The previous chain scanned the whole file up to 5 times on non-CLI Rust sources — the common case.

USE_CLI_LIB = /\buse\s+(?:clap|structopt|argh|bpaf|pico_args|getopts)\b|\b(?:clap|structopt|argh|bpaf|pico_args|getopts)::/

Instance Method Summary

Instance methods inherited from class Detector

applicable?(filename : String) : Bool applicable?, detect(filename : String, file_contents : String) : Bool detect, gemfile_dependency?(file_contents : String, gem_name : String) : Bool gemfile_dependency?, gemspec_dependency?(file_contents : String, gem_name : String) : Bool gemspec_dependency?, idempotent? : Bool idempotent?, logger : NoirLogger logger, name : String name, path_sensitive? : Bool path_sensitive?

Constructor methods inherited from class Detector

new(options : Hash(String, YAML::Any)) new

Instance Method Detail

def applicable?(filename : String) : Bool #
Description copied from class Detector

Cheap filename-only filter the detector pass uses to skip #detect on files the detector cannot possibly match. The default true preserves prior behavior (every detector runs on every file). Override with the same predicate the body of #detect starts with — e.g., filename.ends_with?(".py") for a Python framework detector — so the detector loop avoids the #detect dispatch on files outside the detector's language.

On large codebases (saleor's 4255 .py files) this lifts ~100 virtual #detect calls per file out of the hot loop because most detectors' inner first-line is exactly this kind of cheap filename check.


[View source]
def detect(filename : String, file_contents : String) : Bool #

[View source]
def set_name #

[View source]