aboutcode-org / aboutcode-org/fetchcode

Add FetchCode support for docker

未關閉
#172 0 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
主要語言
HTML
星號
13
分支
24
PR 合併指標
30 天內沒有已合併 PR

描述

A pkg:docker/... PURL identifies a container image by name and digest or tag, but Docker images aren’t distributed as single downloadable files. They are composed of multiple layers, each stored as a separate blob in a Docker registry and retrieved via the Docker Registry HTTP API v2.

Key reasons:

No canonical file: A Docker image isn’t a .tar.gz or .zip; it’s a manifest + config + N layers.

Layered, digest-addressed architecture: Each part of the image must be downloaded individually by digest (e.g., sha256:abc...) via authenticated API requests.

Authentication required: Docker Hub and others enforce token-based authentication, even for public images.

Toolchain needed: Tools like docker pull, skopeo, or crane orchestrate these multi-step fetches - no single URL works on its own.

Hence, a Docker PURL does not map to a static downloadable URL, and trying to force one goes against the registry design.

貢獻指南

這個儲存庫沒有索引到貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。