aboutcode-org / aboutcode-org/dejacode

BUG: SBOM import fails with "The 'for_package' cannot be the same as 'resolved_to_package'" and duplicates number of dependencies

未关闭
#257 1 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
bug design needed enhancement PackageSet
主要语言
Python
星标
50
派生
27
平均合并
4 小时 51 分钟
30 天内合并 PR
11

描述

**Describe the bug**
When importing a particular SBOM created with cdxgen, the `load_sbom` pipeline succeeds according to ScanCode.io, but DejaCode reports issues importing the dependencies. The error message states: `The 'for_package' cannot be the same as 'resolved_to_package'`

Repeating the SBOM import causes an additional issue. DejaCode duplicates the number of dependencies, apparently not realizing that these are the same dependencies that have been previously added.

Note: This is the same SBOM as https://github.com/aboutcode-org/scancode.io/issues/1576 where ScanCode reported issues with `create_dependecies` but the overall pipeline is considered a success.

**To Reproduce**
Not clear yet. Cannot share actual data at the moment. I will see if an MWE can be provided.
If the error provides indication what I should look out for in the SBOM, I might be able to find it quicker.

**Expected behavior**
The SBOM should be properly loaded and no duplicate dependency entries should be added

**Screenshots**
![Image](https://github.com/user-attachments/assets/ccdf620a-f410-453f-8273-d92759184d3e)

**Context (OS, Browser, Device, etc.):**
n.a.

贡献指南

打开贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。