aboutcode-org / aboutcode-org/scancode-toolkit

NuGet packages.lock.json parser fails on Project and CentralTransitive dependency types

未關閉
#5,106 2 則留言 1 個 reaction 已指派 0 人 在 GitHub 檢視
bug
主要語言
Python
星號
2.6k
分支
791
平均合併
1 天 12 小時
30 天內合併 PR
5

描述

## Summary

The NuGet `packages.lock.json` parser fails when a lockfile contains dependency entries with the `Project` or `CentralTransitive` type.

NuGet lockfiles can contain these dependency types in addition to `Direct` and `Transitive`. Currently, the parser only handles `Direct` and `Transitive`. Any other type raises an exception, which causes parsing to abort.

As a result, valid NuGet lockfiles generated by projects using project references or Central Package Management may produce no package results.

## Affected file type

`packages.lock.json`

## Observed behavior

When parsing a NuGet lockfile containing entries like this:

```json
{
"version": 2,
"dependencies": {
"net8.0": {
"Example.Direct": {
"type": "Direct",
"requested": "[1.0.0, )",
"resolved": "1.0.0",
"contentHash": "..."
},
"Example.Transitive": {
"type": "Transitive",
"resolved": "2.0.0",
"contentHash": "..."
},
"Example.CentralTransitive": {
"type": "CentralTransitive",
"requested": "[3.0.0, )",
"resolved": "3.0.0",
"contentHash": "..."
},
"example.project.reference": {
"type": "Project",
"dependencies": {
"Example.Direct": "[1.0.0, )"
}
}
}
}
}
```

the parser raises an exception similar to:

```text
Unknown package type: Project
```

or:

```text
Unknown package type: CentralTransitive
```

## Expected behavior

The parser should handle all dependency types that NuGet can write to `packages.lock.json`.

Suggested behavior:

`Direct` entries should be reported as direct NuGet dependencies.

`Transitive` entries should be reported as transitive NuGet dependencies.

`CentralTransitive` entries should be reported as transitive NuGet dependencies, because they are package dependencies resolved through Central Package Management.

`Project` entries should be skipped, because they are project references and not NuGet package dependencies.

## Why this matters

Projects using Central Package Management or project references can generate valid NuGet lockfiles that include `CentralTransitive` and `Project` entries.

If parsing aborts on these entries, ScanCode Toolkit cannot reliably extract the package inventory from such lockfiles.

貢獻指南

開啟貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。