aboutcode-org / aboutcode-org/scancode-toolkit

RFC: Introduce "primary package" vs. "embedded- or sub-packages"

Open
#2,418 7 comments 0 reactions 0 assignees View on GitHub
new feature package scan package-at-toplevel package-files primary-summary RFC
Dominant language
Python
Stars
2.6k
Forks
791
Avg merge
1d 12h
Merged PRs (30d)
5

Description

## Short Description
In the same way we have dependencies, we often have:
- a package within a package such as a node_modules in an npm, mono-repos, uberjars and fatjars, and similar
- multiple personalities for the same package (bower and npm)

We should have a heuristic to report one of these has primary and the other as sub/embedded packages.
This would likely be done in a post-scan step.
Data-wise this could be a list of Package URL similar to what we have for dependencies.

## Select Category
- [x] Enhancement

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.