aboutcode-org / aboutcode-org/scancode-toolkit

NuGet packages.lock.json parser fails on Project and CentralTransitive dependency types

未关闭
#5,106 2 条评论 1 个 reaction 已指派 0 人 在 GitHub 查看
bug
主要语言
Python
星标
2.6k
派生
791
平均合并
1 天 12 小时
30 天内合并 PR
5

描述

## Summary

The NuGet `packages.lock.json` parser fails when a lockfile contains dependency entries with the `Project` or `CentralTransitive` type.

NuGet lockfiles can contain these dependency types in addition to `Direct` and `Transitive`. Currently, the parser only handles `Direct` and `Transitive`. Any other type raises an exception, which causes parsing to abort.

As a result, valid NuGet lockfiles generated by projects using project references or Central Package Management may produce no package results.

## Affected file type

`packages.lock.json`

## Observed behavior

When parsing a NuGet lockfile containing entries like this:

```json
{
"version": 2,
"dependencies": {
"net8.0": {
"Example.Direct": {
"type": "Direct",
"requested": "[1.0.0, )",
"resolved": "1.0.0",
"contentHash": "..."
},
"Example.Transitive": {
"type": "Transitive",
"resolved": "2.0.0",
"contentHash": "..."
},
"Example.CentralTransitive": {
"type": "CentralTransitive",
"requested": "[3.0.0, )",
"resolved": "3.0.0",
"contentHash": "..."
},
"example.project.reference": {
"type": "Project",
"dependencies": {
"Example.Direct": "[1.0.0, )"
}
}
}
}
}
```

the parser raises an exception similar to:

```text
Unknown package type: Project
```

or:

```text
Unknown package type: CentralTransitive
```

## Expected behavior

The parser should handle all dependency types that NuGet can write to `packages.lock.json`.

Suggested behavior:

`Direct` entries should be reported as direct NuGet dependencies.

`Transitive` entries should be reported as transitive NuGet dependencies.

`CentralTransitive` entries should be reported as transitive NuGet dependencies, because they are package dependencies resolved through Central Package Management.

`Project` entries should be skipped, because they are project references and not NuGet package dependencies.

## Why this matters

Projects using Central Package Management or project references can generate valid NuGet lockfiles that include `CentralTransitive` and `Project` entries.

If parsing aborts on these entries, ScanCode Toolkit cannot reliably extract the package inventory from such lockfiles.

贡献指南

打开贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。