Skip to content

Scope the project-mode Deno crawl to the JSR packages deno.lock records #1216

Description

[agent] Filed by the scheduled architecture refactor routine (Deno child of #595). Register: discussion #560 register.

Kind: refactor. Source: review §3 #3, Part 6.6; register E05 (tracking #595, checklist item "Deno: scope to the deno.lock jsr entries").

Problem (main @ b76d7ab)

In project mode, DenoCrawler::crawl_all walks the whole $DENO_DIR/npm/jsr.io cache as soon as cwd has a deno.json, deno.jsonc or deno.lock (get_jsr_cache_paths).`` The project's deno.lock is never consulted, so `scan` reports (and sends to the API, and agent apply and VEX see) every JSR package version any project on the machine cached. The walk lists every scope, name and version directory, so its cost grows with the machine cache.

Separately, the version-dependent layout of deno.lock (top-level sections in v4/v5, packages.<section> in v3, <section>.packages in v2) is known only to vex::discover::deno::deno_npm_keys; a second reader would copy it.

Verified on main by a unit test: a locked project (jsr: {"@std/path@0.220.0"}) whose cache also holds @std/fs@1.0.0 and @other/x@2.0.0 crawls all three; an npm-only lock crawls all three too.

Impact

Wrong answers (JSR packages the project never resolves) and a crawl whose cost grows with the machine cache, not the project.

Proposed change

  • In project mode with a readable <cwd>/deno.lock that parses and carries a version, look up each jsr key (@<scope>/<name>@<version>) as <cache>/<scope>/<name>/<version>/ instead of walking. A lock without a jsr section records no JSR package.
  • The lookup is the one find_by_purls already does (purl grammar, traversal guard, is_dir): one shared locate for both.
  • One lock_section(lock, "npm" | "jsr") reader for the lock layout, used by the crawl and by VEX discovery's deno_npm_keys.
  • Keep the walk for --global / --global-prefix and a project without a usable deno.lock.

Size and scope

crawlers/deno_crawler.rs and vex/discover/deno.rs; ~+60 production lines. Out of scope: the shared crawl_unscoped_cache warning (#595's last item); moving lock_section to a formats::deno model once formats/mod.rs is free.

Acceptance criteria

  • A project with a deno.lock crawls only the JSR packages it records (red on main).
  • Lockless, unparseable-lock and global crawls are unchanged.
  • Traversal-shaped lock keys and uncached locked packages are not reported.
  • crawler_deno_e2e, the VEX Deno suites and deno_npm_keys stay green.

Dependencies

Child of #595. Follows the cargo (#1204) and Go (#1207) children.

Activity

  1. added
    arch-auditFiled by a scheduled architecture audit routine (see the architecture review discussion)
    on Oct 9, 2026
  2. added
    refactorStructural change: duplicated code or logic, missing abstraction, layering, dead code
    on Oct 9, 2026
  3. mikolalysenko commented on Oct 9, 2026

    @mikolalysenko
    CollaboratorAuthor

    [agent] Claiming this issue for the architecture refactor routine (highest leverage: the next free #595 child, a measurable crawl speed-up plus one shared deno.lock layout reader). Branch: arch-refactor/1216-deno-lock-scope. Claim-ID: 20261009T030615Z-3e3fbb


    Generated by Claude Code

  4. added a commit that references this issue on Oct 9, 2026
    a3e5f30
  5. mikolalysenko commented on Oct 9, 2026

    @mikolalysenko
    CollaboratorAuthor

    [agent] Draft PR: #1217.


    Generated by Claude Code

  6. mikolalysenko commented on Oct 9, 2026

    @mikolalysenko
    CollaboratorAuthor

    [agent] Triage: priority:p3 (Deno). Open PR #1217 addresses this; leaving it to that PR.


    Generated by Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    agent:triagedarch-auditFiled by a scheduled architecture audit routine (see the architecture review discussion)priority:p3refactorStructural change: duplicated code or logic, missing abstraction, layering, dead code

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions