aboutcode-org / aboutcode-org/scancode-toolkit

empty files are reported with empty hash in spdx tag/value, that makes it invalid

オープン
#2,668 コメント 4 件 リアクション 0 件 担当者 0 名 GitHub で見る
bug
主要言語
Python
スター
2.6k
フォーク
791
平均マージ
1日 12時間
マージ済み PR(30日)
5

説明

### Description

The generated spdx in tag/value format is invalid, if the scan contained an empty file, e.g. the following part is invalid since it misses the SHA1 hash:

```
131 │ # File
132 │
133 │ FileName: ./public/.keep
134 │ FileChecksum: SHA1:
135 │ LicenseConcluded: NOASSERTION
136 │ LicenseInfoInFile: NONE
137 │ FileCopyrightText: NONE
```

### How To Reproduce

* scan a directory with an empty file
* generate tag/value
* use https://tools.spdx.org/app/validate/ to validate and see the following violation:

![Bildschirmfoto_2021-08-25_21-12-38](https://user-images.githubusercontent.com/1187050/130851110-625c25dc-e869-48f3-b67b-41d03a7dfcf0.png)

### System configuration
v21.8.4

コントリビューションガイド

コントリビューションガイドを開く

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。