aboutcode-org / aboutcode-org/scancode-toolkit

Dependencies for maven project only resolved for cyclonedx, not for spdx/json

Open
#2,854 4 comments 0 reactions 0 assignees View on GitHub
bug
Dominant language
Python
Stars
2.6k
Forks
791
Avg merge
1d 12h
Merged PRs (30d)
5

Description

### Description

Dependencies/Packages from a maven pom.xml are only detected when outputting to cyclone-dx-xml, but not when outputting to json or spdx-tv or spdx-xml.

Im not sure if this is a missing feature that is only implemented in cyclonedx or a bug?

### How To Reproduce

I created a Hello-World-Style java project with the following dependency included in pom.xml

```xml


log4j
log4j
1.2.17

```
Running scancode like so:

```bash
scancode -clpieu --spdx-tv ../../scancode-java.spdx.tv ../../Log4J-example-with-java --max-depth 0 --consolidate
```

Yields an SBOM which only includes "Files" and the main Package

```
# Package

PackageName: log4j_example_with_java
SPDXID: SPDXRef-001
PackageDownloadLocation: NOASSERTION
PackageVerificationCode: daf7c31358a7967f856b9a0eda8bee2f61abde16
PackageLicenseDeclared: NOASSERTION
PackageLicenseConcluded: NOASSERTION
PackageLicenseInfoFromFiles: NONE
PackageCopyrightText: NONE

# File
FileName: ./Log4J-example-with-java/.idea/compiler.xml
SPDXID: SPDXRef-6
FileChecksum: SHA1: 5deee417bc8e462aa80f979e9fb353f707df9b1f
LicenseConcluded: NOASSERTION
LicenseInfoInFile: NONE
FileCopyrightText: NONE

# ...
```

Same goes for the JSON output.

CycloneDX however correctly includes the log4j dependency:

```bash
scancode -clpieu --cyclonedx ../../scancode-java.json.cdx ../../Log4J-example-with-java --max-depth 0 --consolidate
```

```xml




```

### System configuration

5.13.0-27-generic #29-Ubuntu SMP Wed Jan 12 17:36:47 UTC 2022 x86_64 x86_64 x86_64 GNU/Linux

ScanCode version 30.1.0

ScanCode Output Format version 2.0.0

SPDX License list version 3.15

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.