aboutcode-org / aboutcode-org/dejacode

BUG: SBOM import fails with "The 'for_package' cannot be the same as 'resolved_to_package'" and duplicates number of dependencies

Đang mở
#257 1 bình luận 0 reaction 0 người được giao Xem trên GitHub
bug design needed enhancement PackageSet
Ngôn ngữ chính
Python
Star
50
Fork
27
Merge trung bình
4 giờ 51 phút
Pull request đã merge (30 ngày)
11

Mô tả

**Describe the bug**
When importing a particular SBOM created with cdxgen, the `load_sbom` pipeline succeeds according to ScanCode.io, but DejaCode reports issues importing the dependencies. The error message states: `The 'for_package' cannot be the same as 'resolved_to_package'`

Repeating the SBOM import causes an additional issue. DejaCode duplicates the number of dependencies, apparently not realizing that these are the same dependencies that have been previously added.

Note: This is the same SBOM as https://github.com/aboutcode-org/scancode.io/issues/1576 where ScanCode reported issues with `create_dependecies` but the overall pipeline is considered a success.

**To Reproduce**
Not clear yet. Cannot share actual data at the moment. I will see if an MWE can be provided.
If the error provides indication what I should look out for in the SBOM, I might be able to find it quicker.

**Expected behavior**
The SBOM should be properly loaded and no duplicate dependency entries should be added

**Screenshots**
![Image](https://github.com/user-attachments/assets/ccdf620a-f410-453f-8273-d92759184d3e)

**Context (OS, Browser, Device, etc.):**
n.a.

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Đánh giá

Issue này chưa được đánh giá.

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.