aboutcode-org / aboutcode-org/scancode.io

Restructure `inspect_packages` pipeline

Open
#1,419 0 comments 0 reactions 1 assignee Claimed by @AyanSinhaMahapatra View on GitHub
high priority
Dominant language
Python
Stars
215
Forks
203
Avg merge
4d 8h
Merged PRs (30d)
6

Description

There are two conflicting use cases that needs to be addressed:

1. Running a fast package scan to only get package information from manifests and lockfiles
2. Running a more detailed package scan with package assembly and resolving dependencies (but still faster as this is a package-only scan without license/copyrights)

2 was needed for https://github.com/aboutcode-org/scancode.io/pull/1244 and is what we have now with package assembly and resolving dependencies through the `StaticResolver` group, but note that we have the same functionality with the `ResolveDependencies` pipeline, so it be better perhaps to:

* Have the `inspect_packages` pipeline only do 1.
* Have the `resolve_dependencies` pipeline do 2.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.