aboutcode-org / aboutcode-org/dejacode

Problems creating a package from a SourceForge download URL

未关闭
#26 13 条评论 0 个 reaction 已指派 2 人 已被 @pombredanne 认领 在 GitHub 查看
help wanted integration question
主要语言
Python
星标
50
派生
27
平均合并
4 小时 51 分钟
30 天内合并 PR
11

描述

Perhaps this is a user "pilot" error, but when I create a Package in DejaCode from a SourceForge download URL, I get strange results. A recent Add Package using
https://sourceforge.net/projects/scribus/files/scribus/1.6.0/scribus-1.6.0.tar.gz/download
resulted in a Package with a filename of `download` rather than `scribus-1.6.0.tar.gz`.
It also resulted in the rather verbose PURL value of
`pkg:generic/download?download_url=https://sourceforge.net/projects/scribus/files/scribus/1.6.0/scribus-1.6.0.tar.gz/download`

I scanned the package, using the same download URL, directly in SCIO v32.0.8, and it returned a PURL value of
`pkg:autotools/scribus-1.6.0`
in the key_files_packages section

So it appears that the rather eccentric download conventions of SourceForge are messing things up a bit.
* Can we improve DejaCode to interpret the results of such a scan differently?
* Does such an improvement rather belong in SCIO?
* or should we prompt the DejaCode user with instructions how to provide a different, better, less eccentric download URL when processing a SourceForge package?

贡献指南

打开贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。