aboutcode-org / aboutcode-org/scancode-toolkit

Support npm dependencies with "weird" versions

Open
#2,509 0 comments 0 reactions 0 assignees View on GitHub
bug dependencies package scan package-formats
Dominant language
Python
Stars
2.6k
Forks
791
Avg merge
1d 12h
Merged PRs (30d)
5

Description

Per https://docs.npmjs.com/cli/v7/configuring-npm/package-json#dependencies the version of a dependency can be various things:

- URLs as Dependencies: "http://asdf.com/asdf.tar.gz",
- Git URLs as Dependencies: See https://docs.npmjs.com/cli/v7/configuring-npm/package-json#git-urls-as-dependencies ... this is using a VCS_URL-os-SPDX and pip-like syntax
- GitHub URLs: user/repo#feature\/branch
- Local Paths: "bar": "file:../foo/bar" ....

These versions end up in the package-lock.json too and they are not really versions.
We should instead treat them as requirements and not as concrete versions.

This is also impacting ScanCode.io BTW

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.