aboutcode-org / aboutcode-org/scancode-toolkit

NuGet: add support for extra manifests

未關閉
#1,584 1 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
new feature package scan package-formats
主要語言
Python
星號
2.6k
分支
791
平均合併
1 天 12 小時
30 天內合併 PR
5

描述

### Description
Beyond the base `.nuspec` manifest file there are several other files we should detect and report:

- `packages-config`: See https://docs.microsoft.com/en-us/nuget/reference/packages-config

This is an XML file and it mostly lists the dependencies of a project. This is a "legacy" format
It is somewhat related to the packages.lock.json too.
```xml


```

- `project.json` and `project.lock.json` See https://docs.microsoft.com/en-us/nuget/archive/project-json

This is a JSON file and mostly list dependencies though it can store some extra attributes . This is a "legacy" NuGet 3.x+ format. The lock file is also JSON.

```json
"dependencies": {
"Microsoft.NETCore": "5.0.0",
"System.Runtime.Serialization.Primitives": "4.0.10"
}
```

- `PackageReference` See https://docs.microsoft.com/en-us/nuget/consume-packages/package-references-in-project-files (therefore is XML)

It stores NuGet dependencies in the VS projects files directly under a PackageReference node.

```xml



```

Notes: Projects that use PackageReference do not use packages.config.

See also #648

貢獻指南

開啟貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。