aboutcode-org / aboutcode-org/scancode-toolkit

empty files are reported with empty hash in spdx tag/value, that makes it invalid

未關閉
#2,668 4 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
bug
主要語言
Python
星號
2.6k
分支
791
平均合併
1 天 12 小時
30 天內合併 PR
5

描述

### Description

The generated spdx in tag/value format is invalid, if the scan contained an empty file, e.g. the following part is invalid since it misses the SHA1 hash:

```
131 │ # File
132 │
133 │ FileName: ./public/.keep
134 │ FileChecksum: SHA1:
135 │ LicenseConcluded: NOASSERTION
136 │ LicenseInfoInFile: NONE
137 │ FileCopyrightText: NONE
```

### How To Reproduce

* scan a directory with an empty file
* generate tag/value
* use https://tools.spdx.org/app/validate/ to validate and see the following violation:

![Bildschirmfoto_2021-08-25_21-12-38](https://user-images.githubusercontent.com/1187050/130851110-625c25dc-e869-48f3-b67b-41d03a7dfcf0.png)

### System configuration
v21.8.4

貢獻指南

開啟貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。