aboutcode-org / aboutcode-org/scancode-toolkit

NuGet packages.lock.json parser fails on Project and CentralTransitive dependency types

Offen
#5,106 2 Kommentare 1 Reaktion 0 zugewiesene Personen Auf GitHub ansehen
bug
Vorherrschende Sprache
Python
Sterne
2.6k
Forks
791
Ø Merge
1 T. 12 Std.
Gemergte PRs (30 T.)
5

Beschreibung

## Summary

The NuGet `packages.lock.json` parser fails when a lockfile contains dependency entries with the `Project` or `CentralTransitive` type.

NuGet lockfiles can contain these dependency types in addition to `Direct` and `Transitive`. Currently, the parser only handles `Direct` and `Transitive`. Any other type raises an exception, which causes parsing to abort.

As a result, valid NuGet lockfiles generated by projects using project references or Central Package Management may produce no package results.

## Affected file type

`packages.lock.json`

## Observed behavior

When parsing a NuGet lockfile containing entries like this:

```json
{
"version": 2,
"dependencies": {
"net8.0": {
"Example.Direct": {
"type": "Direct",
"requested": "[1.0.0, )",
"resolved": "1.0.0",
"contentHash": "..."
},
"Example.Transitive": {
"type": "Transitive",
"resolved": "2.0.0",
"contentHash": "..."
},
"Example.CentralTransitive": {
"type": "CentralTransitive",
"requested": "[3.0.0, )",
"resolved": "3.0.0",
"contentHash": "..."
},
"example.project.reference": {
"type": "Project",
"dependencies": {
"Example.Direct": "[1.0.0, )"
}
}
}
}
}
```

the parser raises an exception similar to:

```text
Unknown package type: Project
```

or:

```text
Unknown package type: CentralTransitive
```

## Expected behavior

The parser should handle all dependency types that NuGet can write to `packages.lock.json`.

Suggested behavior:

`Direct` entries should be reported as direct NuGet dependencies.

`Transitive` entries should be reported as transitive NuGet dependencies.

`CentralTransitive` entries should be reported as transitive NuGet dependencies, because they are package dependencies resolved through Central Package Management.

`Project` entries should be skipped, because they are project references and not NuGet package dependencies.

## Why this matters

Projects using Central Package Management or project references can generate valid NuGet lockfiles that include `CentralTransitive` and `Project` entries.

If parsing aborts on these entries, ScanCode Toolkit cannot reliably extract the package inventory from such lockfiles.

Beitragsleitfaden

Beitragsleitfaden öffnen

Bewertung

Dieses Issue wurde noch nicht bewertet.

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.