Skip to content

fix(dependency): generate schemas for transitive package dependencies - #270

Open
haarchri wants to merge 1 commit into
crossplane:mainfrom
haarchri:fix/transitive-dependency-schemas
Open

fix(dependency): generate schemas for transitive package dependencies#270
haarchri wants to merge 1 commit into
crossplane:mainfrom
haarchri:fix/transitive-dependency-schemas

Conversation

@haarchri

@haarchri haarchri commented Aug 13, 2026

Copy link
Copy Markdown
Member

Description of your changes

When generating schemas for xpkg dependencies, the CLI only processed the directly declared package and never read the fetched package's own spec.dependsOn metadata. As a result, transitive dependencies were skipped, for example, adding provider-aws-s3 did not generate schemas for provider-family-aws, which holds the ProviderConfig CRDs.

This change makes addPackage recursively process the dependencies declared in a package's metadata after generating its schemas:

  • After schemas.Add succeeds, the new addTransitiveDeps iterates pkg.GetDependencies() and recursively adds each entry. This covers all xpkg schema paths: dependency add, project build/run, dependency update-cache, and direct AddPackage calls.
  • A mutex-guarded visited set on Manager (keyed by unresolved ref, claimed before fetching) deduplicates shared transitive dependencies across the concurrent AddAll goroutines — a family provider shared by several providers is fetched exactly once — and breaks dependency cycles.
  • Transitive dependencies get schemas only; they are not persisted to crossplane-project.yaml. The refresh flag propagates so update-cache re-pulls transitive packages too. Transitive failures fail hard with an error naming both the transitive ref and its parent, matching the validate flow.
  • Refactor: extracted the digest-vs-tag ref formatting into a shared xpkgRef helper and added dependencyRepo to read the image from new-style package: and deprecated provider:/configuration:/function: dependency fields.

How has this code been tested

have an open draft PR modelplaneai/modelplane#397 remove the family providers and get all family provider schemas by default

Fixes #

I have:

Need help with this checklist? See the cheat sheet.

Signed-off-by: Christopher Haar <christopher.haar@upbound.io>
@haarchri
haarchri requested review from a team, jcogilvie and tampakrap as code owners August 13, 2026 09:35
@haarchri
haarchri requested review from negz and removed request for a team August 13, 2026 09:35
@coderabbitai

coderabbitai Bot commented Aug 13, 2026

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

@haarchri, you've reached your PR review limit, so we couldn't start this review.

Next review available in: 13 minutes

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: 09eb106e-97c7-466d-8197-5e38410c40b8

📥 Commits

Reviewing files that changed from the base of the PR and between 3c8f298 and 60578cf.

📒 Files selected for processing (2)
  • internal/dependency/manager.go
  • internal/dependency/manager_test.go

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant