aboutcode-org / aboutcode-org/scancode-toolkit

Vendor some key libraries

オープン
#3,192 コメント 1 件 リアクション 0 件 担当者 0 名 GitHub で見る
bug
主要言語
Python
スター
2.6k
フォーク
791
平均マージ
1日 12時間
マージ済み PR(30日)
5

説明

As a fix for https://github.com/nexB/scancode-toolkit/issues/3179 a solution is to vendor the libraries with objects that participate in the license index pickle such that we are not dependent on their uncontrolled updates. These include:

- attrs
- intbitset and pyahocorasick: these are native libraries and are low priority since we are maintaining them and are able to control their release cycle
- license_expression and boolean.py though we maintain these, so low priority (used for the Rule.license_expression_object)

See also these related issues:
- https://github.com/nexB/scancode-toolkit/issues/3190
- https://github.com/nexB/scancode-toolkit/issues/3191
- https://github.com/nexB/scancode-toolkit/issues/3179

Note: we are doing vendoring in https://github.com/nexB/typecode/blob/main/README.rst with vendy for pygments and also FetchCode (inherit from pip) and tracecode-toolkit-strace (using vendorize for altgraph and docopt). python-vendorize seems mostly current and upda to date.

コントリビューションガイド

コントリビューションガイドを開く

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。