aboutcode-org / aboutcode-org/dejacode

BUG: Packages being created with inadequate PURL data

オープン
#275 コメント 2 件 リアクション 0 件 担当者 3 名 @DennisClark が担当を希望しています GitHub で見る
bug HighPriority integration PackageSet
主要言語
Python
スター
50
フォーク
27
平均マージ
4時間 51分
マージ済み PR(30日)
11

説明

This problem actually is associated with multiple AboutCode projects, but the impact is most apparent to the DejaCode user. A recent import of an SBOM to a product in DejaCode resulted in the creation of 3 different package definitions for `pkg:github/pypa/pip@20.3.1` each with a different download URL. A subsequent search for `pip@20.3.1` turned up 2 older package definitions for `pkg:pypi/pip@20.3.1` each with a different download URL. We don't have a problem of duplicate packages here, but the PURLs are not well defined and should contain additional details to differentiate them:

* The 2 pypi packages should have a file_name qualifier.
* The 3 github packages should have a subpath value.

Screenshot of the 5 pip@20.3.1 packages attached.

Image

コントリビューションガイド

コントリビューションガイドを開く

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。