aboutcode-org / aboutcode-org/scancode-toolkit

Incorrect purls reported for bundled code in package scan

Open
#4,399 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Python
Stars
2.6k
Forks
791
Avg merge
1d 12h
Merged PRs (30d)
5

Description

Package scan for `next-14.2.26` is correctly reported as `pkg:npm/next@14.2.26` . However, all the sub-packages (bundled code) are also reported as `pkg:npm/next@14.2.26` which may not be correct.

input: https://www.npmjs.com/package/next/v/14.2.26?activeTab=code

For instance,

```
{
"path": "code/next-14.2.26.tgz-extract/package/dist/compiled/@edge-runtime/primitives/fetch.js.text.js",
"type": "file",
"package_data": [],
"for_packages": [
"pkg:npm/next@14.2.26?uuid=44b2abd3-413c-432f-88e5-dc1cd843855b"
],
"scan_errors": []
},
```
The `for_packages` should be: `pkg:npm/@edge-runtime/primitives`

```
{
"path": "code/next-14.2.26.tgz-extract/package/dist/compiled/@ampproject/toolbox-optimizer/index.js",
"type": "file",
"package_data": [],
"for_packages": [
"pkg:npm/next@14.2.26?uuid=44b2abd3-413c-432f-88e5-dc1cd843855b"
],
"scan_errors": []
},
```
The `for_packages` should be: `pkg:npm/@ampproject/toolbox-optimizer`

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.