"""build_dependency_graph must mirror sbom["dependencies"] exactly, including a leaf's empty
`dependsOn` — dropping empty entries would make a later "is this ref known to the graph at all"
check unable to tell a scanned leaf from a ref nobody ever declared dependencies for."""
from sec_sbom import build_dependency_graph


def test_build_dependency_graph_matches_the_dependencies_array(sbom):
    graph = build_dependency_graph(sbom)

    assert graph["pkg:generic/f1-service@1.0.0"] == {
        "pkg:pypi/requests@2.31.0",
        "pkg:pypi/mycorp-auth@0.4.0",
        "pkg:pypi/django-mycorp-plugin@1.1.0",
        "pkg:pypi/mycorp-telemetry@2.0.0",
        "pkg:pypi/mycorp-internal-tool@0.9.0",
    }, f"root's dependsOn set is wrong: {graph.get('pkg:generic/f1-service@1.0.0')}"

    assert graph["pkg:pypi/requests@2.31.0"] == {"pkg:pypi/mycorp-billing@3.2.0"}, (
        f"requests must depend on mycorp-billing (the transitive edge), got "
        f"{graph.get('pkg:pypi/requests@2.31.0')}"
    )

    assert graph["pkg:pypi/mycorp-auth@0.4.0"] == set(), (
        "a leaf's dependsOn:[] must still be a key mapped to an empty set, not omitted — got "
        f"{graph.get('pkg:pypi/mycorp-auth@0.4.0')!r}"
    )
