aboutcode-org / aboutcode-org/dejacode

BUG: Packages being created with inadequate PURL data

Open
#275 2 comments 0 reactions 3 assignees Claimed by @DennisClark View on GitHub
bug HighPriority integration PackageSet
Dominant language
Python
Stars
50
Forks
27
Avg merge
4h 51m
Merged PRs (30d)
11

Description

This problem actually is associated with multiple AboutCode projects, but the impact is most apparent to the DejaCode user. A recent import of an SBOM to a product in DejaCode resulted in the creation of 3 different package definitions for `pkg:github/pypa/pip@20.3.1` each with a different download URL. A subsequent search for `pip@20.3.1` turned up 2 older package definitions for `pkg:pypi/pip@20.3.1` each with a different download URL. We don't have a problem of duplicate packages here, but the PURLs are not well defined and should contain additional details to differentiate them:

* The 2 pypi packages should have a file_name qualifier.
* The 3 github packages should have a subpath value.

Screenshot of the 5 pip@20.3.1 packages attached.

Image

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.