Before merging an AI-generated build change, check its dependencies against the team's list of approved packages.
Input:
APPROVED
<lines: group:artifact version1,version2,...>
REQUESTED
<lines: group:artifact:version>
For each requested dependency, in order, print one line:
OK group:artifact:versionif the package is approved and the version is one of its approved versions;VERSION? group:artifact:version (approved: v1, v2)if the package is approved but not that version;TYPOSQUAT? group:artifact:version (did you mean G:A?)if it is not approved but itsgroup:artifactstring is within Levenshtein distance 1 or 2 of an approved one (choose the closest; first in the approved list on a tie);UNKNOWN group:artifact:version (possible hallucination)otherwise.
Finally print Approved: a, Needs review: r (r = all lines that are not OK) and Verdict: BLOCK MERGE if any line is TYPOSQUAT? or UNKNOWN, otherwise Verdict: REVIEW VERSIONS if any VERSION?, otherwise Verdict: OK.
Input:
APPROVED
com.google.code.gson:gson 2.8.9,2.10.1
org.junit.jupiter:junit-jupiter 5.9.3
REQUESTED
com.google.code.gson:gson:2.10.1
com.google.code.gsom:gson:2.10.1
org.junit.jupiter:junit-jupiter:5.10.0
io.fastjson.utils:json-quickparse:1.0.2
Output:
OK com.google.code.gson:gson:2.10.1
TYPOSQUAT? com.google.code.gsom:gson:2.10.1 (did you mean com.google.code.gson:gson?)
VERSION? org.junit.jupiter:junit-jupiter:5.10.0 (approved: 5.9.3)
UNKNOWN io.fastjson.utils:json-quickparse:1.0.2 (possible hallucination)
Approved: 1, Needs review: 3
Verdict: BLOCK MERGE