aboutcode-org / aboutcode-org/scancode-toolkit

NuGet packages.lock.json parser fails on Project and CentralTransitive dependency types

オープン
#5,106 コメント 2 件 リアクション 1 件 担当者 0 名 GitHub で見る
bug
主要言語
Python
スター
2.6k
フォーク
791
平均マージ
1日 12時間
マージ済み PR(30日)
5

説明

## Summary

The NuGet `packages.lock.json` parser fails when a lockfile contains dependency entries with the `Project` or `CentralTransitive` type.

NuGet lockfiles can contain these dependency types in addition to `Direct` and `Transitive`. Currently, the parser only handles `Direct` and `Transitive`. Any other type raises an exception, which causes parsing to abort.

As a result, valid NuGet lockfiles generated by projects using project references or Central Package Management may produce no package results.

## Affected file type

`packages.lock.json`

## Observed behavior

When parsing a NuGet lockfile containing entries like this:

```json
{
"version": 2,
"dependencies": {
"net8.0": {
"Example.Direct": {
"type": "Direct",
"requested": "[1.0.0, )",
"resolved": "1.0.0",
"contentHash": "..."
},
"Example.Transitive": {
"type": "Transitive",
"resolved": "2.0.0",
"contentHash": "..."
},
"Example.CentralTransitive": {
"type": "CentralTransitive",
"requested": "[3.0.0, )",
"resolved": "3.0.0",
"contentHash": "..."
},
"example.project.reference": {
"type": "Project",
"dependencies": {
"Example.Direct": "[1.0.0, )"
}
}
}
}
}
```

the parser raises an exception similar to:

```text
Unknown package type: Project
```

or:

```text
Unknown package type: CentralTransitive
```

## Expected behavior

The parser should handle all dependency types that NuGet can write to `packages.lock.json`.

Suggested behavior:

`Direct` entries should be reported as direct NuGet dependencies.

`Transitive` entries should be reported as transitive NuGet dependencies.

`CentralTransitive` entries should be reported as transitive NuGet dependencies, because they are package dependencies resolved through Central Package Management.

`Project` entries should be skipped, because they are project references and not NuGet package dependencies.

## Why this matters

Projects using Central Package Management or project references can generate valid NuGet lockfiles that include `CentralTransitive` and `Project` entries.

If parsing aborts on these entries, ScanCode Toolkit cannot reliably extract the package inventory from such lockfiles.

コントリビューションガイド

コントリビューションガイドを開く

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。