aboutcode-org / aboutcode-org/scancode-toolkit

Authenticated Git dependency in package.json parsed as package "git" instead of declared dependency name

Đang mở
#4,753 0 bình luận 0 reaction 0 người được giao Xem trên GitHub
bug
Ngôn ngữ chính
Python
Star
2.6k
Fork
791
Merge trung bình
1 ngày 12 giờ
Pull request đã merge (30 ngày)
5

Mô tả

**Description**
ScanCode reports an incorrect dependency name when a package.json dependency uses an authenticated Git URL.

The dependency key defined in package.json is lost and replaced with "git".

**Steps to reproduce**
1. Create package.json:

{
"name": "example",
"version": "1.0.0",
"dependencies": {
"private-lib": "git+ssh://git@github.com:org/repo.git#v1.0.0"
}
}

2. Run:
./scancode -clip --json result.json .

3. Inspect dependency output

**Observed result**
Dependency is reported as:
pkg:npm/git

The declared dependency name "private-lib" is not preserved.

**Expected result**
Dependency name should remain "private-lib"
and the Git URL should be treated as the requirement for that dependency.

**Why this matters**
Authenticated Git dependencies are commonly used for private repositories.
Incorrect dependency names break dependency tracking and SBOM generation.

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Đánh giá

Issue này chưa được đánh giá.

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.