aboutcode-org / aboutcode-org/scancode-toolkit

NuGet packages.lock.json parser fails on Project and CentralTransitive dependency types

Ouverte
#5,106 2 commentaires 1 réaction 0 personnes assignées Voir sur GitHub
bug
Langage dominant
Python
Étoiles
2.6k
Forks
791
Merge moyen
1 j 12 h
PR mergées (30 j)
5

Description

## Summary

The NuGet `packages.lock.json` parser fails when a lockfile contains dependency entries with the `Project` or `CentralTransitive` type.

NuGet lockfiles can contain these dependency types in addition to `Direct` and `Transitive`. Currently, the parser only handles `Direct` and `Transitive`. Any other type raises an exception, which causes parsing to abort.

As a result, valid NuGet lockfiles generated by projects using project references or Central Package Management may produce no package results.

## Affected file type

`packages.lock.json`

## Observed behavior

When parsing a NuGet lockfile containing entries like this:

```json
{
"version": 2,
"dependencies": {
"net8.0": {
"Example.Direct": {
"type": "Direct",
"requested": "[1.0.0, )",
"resolved": "1.0.0",
"contentHash": "..."
},
"Example.Transitive": {
"type": "Transitive",
"resolved": "2.0.0",
"contentHash": "..."
},
"Example.CentralTransitive": {
"type": "CentralTransitive",
"requested": "[3.0.0, )",
"resolved": "3.0.0",
"contentHash": "..."
},
"example.project.reference": {
"type": "Project",
"dependencies": {
"Example.Direct": "[1.0.0, )"
}
}
}
}
}
```

the parser raises an exception similar to:

```text
Unknown package type: Project
```

or:

```text
Unknown package type: CentralTransitive
```

## Expected behavior

The parser should handle all dependency types that NuGet can write to `packages.lock.json`.

Suggested behavior:

`Direct` entries should be reported as direct NuGet dependencies.

`Transitive` entries should be reported as transitive NuGet dependencies.

`CentralTransitive` entries should be reported as transitive NuGet dependencies, because they are package dependencies resolved through Central Package Management.

`Project` entries should be skipped, because they are project references and not NuGet package dependencies.

## Why this matters

Projects using Central Package Management or project references can generate valid NuGet lockfiles that include `CentralTransitive` and `Project` entries.

If parsing aborts on these entries, ScanCode Toolkit cannot reliably extract the package inventory from such lockfiles.

Guide de contribution

Ouvrir le guide de contribution

Évaluation

Cette issue n'a pas encore été évaluée.

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.