"""Shared fixtures — provided, not part of the exercise.

`sbom` is the CycloneDX document for a small fictional service, `f1-service`: it depends
directly on `requests`, three internal-looking packages, and (through `requests`) transitively
on a fourth. `public_index` is a stand-in for "what the public PyPI/npm registry already has a
project named" — a real checker would query the registry API; this fixture is what your
`find_confusion` is graded against instead.
"""
import json
from pathlib import Path

import pytest

FIXTURE = Path(__file__).resolve().parent.parent / "fixtures" / "f1-service.cdx.json"


@pytest.fixture
def sbom() -> dict:
    return json.loads(FIXTURE.read_text())


@pytest.fixture
def internal_prefixes() -> list[str]:
    return ["mycorp"]


@pytest.fixture
def public_index() -> dict[str, list[str]]:
    return {
        "requests": ["2.31.0", "2.32.0"],
        "mycorp-auth": ["0.1.0"],
        "django-mycorp-plugin": ["1.1.0"],
        "mycorp-telemetry": ["0.9.3"],
        "mycorp-billing": ["1.0.0"],
        # "mycorp-internal-tool" is deliberately absent: nobody has published that name yet.
    }
