aboutcode-org / aboutcode-org/dejacode

DJC: Design an enhanced DejaCode Package model to identify source code relationships

Open
#41 1 comment 0 reactions 3 assignees Claimed by @DennisClark View on GitHub
design needed enhancement integration PackageSet
Dominant language
Python
Stars
50
Forks
27
Avg merge
4h 51m
Merged PRs (30d)
11

Description

The working idea here is to come up with the best way to identify cross-package relationships, especially to be able to get to
(1) the source code
and
(2) more complete copyright+license data, which usually comes from the source code.

We could start by displaying the values for `contains_source_code`, `source_packages`, `code_view_url`, and `vcs_url` in the "Detected Package" section of the Scan tab (when a value is available). The ScanCode package model has this support for source code relationships (which are also in PurlDB):

- the `contains_source_code` boolean flags tells if the package itself contains source code: https://github.com/nexB/scancode-toolkit/blob/0465269543eb338086c10bdeb1e81d3013522b4d/src/packagedcode/models.py#L452
- the `source_packages` field is a list of Package URLs that may exist for this package https://github.com/nexB/scancode-toolkit/blob/0465269543eb338086c10bdeb1e81d3013522b4d/src/packagedcode/models.py#L457
- the `code_view_url` and `vcs_url` provide reference URLs to view or fetch actual source code https://github.com/nexB/scancode-toolkit/blob/0465269543eb338086c10bdeb1e81d3013522b4d/src/packagedcode/models.py#L414

Now that we have standardized on PURL as the package identifier, we should be able to pursue this DejaCode improvement using **package-set** values via integration with the PurlDB.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.