aboutcode-org / aboutcode-org/scancode-toolkit
Support npm dependencies with "weird" versions
オープン
bug
dependencies
package scan
package-formats
- 主要言語
- Python
- スター
- 2.6k
- フォーク
- 791
- 平均マージ
- 1日 12時間
- マージ済み PR(30日)
- 5
説明
Per https://docs.npmjs.com/cli/v7/configuring-npm/package-json#dependencies the version of a dependency can be various things:
- URLs as Dependencies: "http://asdf.com/asdf.tar.gz",
- Git URLs as Dependencies: See https://docs.npmjs.com/cli/v7/configuring-npm/package-json#git-urls-as-dependencies ... this is using a VCS_URL-os-SPDX and pip-like syntax
- GitHub URLs: user/repo#feature\/branch
- Local Paths: "bar": "file:../foo/bar" ....
These versions end up in the package-lock.json too and they are not really versions.
We should instead treat them as requirements and not as concrete versions.
This is also impacting ScanCode.io BTW
コントリビューションガイド
評価
この issue はまだ評価されていません。