aboutcode-org / aboutcode-org/scancode-toolkit

Scancode for licenses scans the same package from different sources

Offen
#4,144 6 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
bug
Vorherrschende Sprache
Python
Sterne
2.6k
Forks
791
Ø Merge
1 T. 12 Std.
Gemergte PRs (30 T.)
5

Beschreibung

### Description

I am only looking to use scancode to check licenses in my project, and it runs extremely slowly, even when limited to only looking through the package.json files in my repo. I believe scancode doesn't optimize for when multiple installed packages have the same dependency, and it will scan that dependency many times. This causes it to take ~30 minutes to run, whereas this [license compliance package](https://www.npmjs.com/package/license-compliance) runs in under 10 seconds. I would prefer using scancode over this package, however I can't justify a 30 minute run.

### How To Reproduce

> Tell us how to reproduce the issue.

Install multiple npm packages that share the same peer dependency and run `scancode --licenses`

### System configuration

> For bug reports, it really helps us to know:

* What OS are you running on? (Windows/MacOS/Linux)
* What version of scancode-toolkit was used to generate the scan file?
* What installation method was used to install/run scancode? (pip/source download/other)

Beitragsleitfaden

Beitragsleitfaden öffnen

Bewertung

Dieses Issue wurde noch nicht bewertet.

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.