aboutcode-org / aboutcode-org/scancode-toolkit

empty files are reported with empty hash in spdx tag/value, that makes it invalid

Open
#2,668 4 comments 0 reactions 0 assignees View on GitHub
bug
Dominant language
Python
Stars
2.6k
Forks
791
Avg merge
1d 12h
Merged PRs (30d)
5

Description

### Description

The generated spdx in tag/value format is invalid, if the scan contained an empty file, e.g. the following part is invalid since it misses the SHA1 hash:

```
131 │ # File
132 │
133 │ FileName: ./public/.keep
134 │ FileChecksum: SHA1:
135 │ LicenseConcluded: NOASSERTION
136 │ LicenseInfoInFile: NONE
137 │ FileCopyrightText: NONE
```

### How To Reproduce

* scan a directory with an empty file
* generate tag/value
* use https://tools.spdx.org/app/validate/ to validate and see the following violation:

![Bildschirmfoto_2021-08-25_21-12-38](https://user-images.githubusercontent.com/1187050/130851110-625c25dc-e869-48f3-b67b-41d03a7dfcf0.png)

### System configuration
v21.8.4

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.