aboutcode-org / aboutcode-org/scancode-toolkit

Support npm dependencies with "weird" versions

オープン
#2,509 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る
bug dependencies package scan package-formats
主要言語
Python
スター
2.6k
フォーク
791
平均マージ
1日 12時間
マージ済み PR(30日)
5

説明

Per https://docs.npmjs.com/cli/v7/configuring-npm/package-json#dependencies the version of a dependency can be various things:

- URLs as Dependencies: "http://asdf.com/asdf.tar.gz",
- Git URLs as Dependencies: See https://docs.npmjs.com/cli/v7/configuring-npm/package-json#git-urls-as-dependencies ... this is using a VCS_URL-os-SPDX and pip-like syntax
- GitHub URLs: user/repo#feature\/branch
- Local Paths: "bar": "file:../foo/bar" ....

These versions end up in the package-lock.json too and they are not really versions.
We should instead treat them as requirements and not as concrete versions.

This is also impacting ScanCode.io BTW

コントリビューションガイド

コントリビューションガイドを開く

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。