aboutcode-org / aboutcode-org/scancode.io

Restructure `inspect_packages` pipeline

Aberta
#1,419 0 comentários 0 reações 1 responsável Reivindicada por @AyanSinhaMahapatra Ver no GitHub
high priority
Linguagem predominante
Python
Estrelas
215
Forks
203
Merge médio
4d 8h
PRs com merge (30d)
6

Descrição

There are two conflicting use cases that needs to be addressed:

1. Running a fast package scan to only get package information from manifests and lockfiles
2. Running a more detailed package scan with package assembly and resolving dependencies (but still faster as this is a package-only scan without license/copyrights)

2 was needed for https://github.com/aboutcode-org/scancode.io/pull/1244 and is what we have now with package assembly and resolving dependencies through the `StaticResolver` group, but note that we have the same functionality with the `ResolveDependencies` pipeline, so it be better perhaps to:

* Have the `inspect_packages` pipeline only do 1.
* Have the `resolve_dependencies` pipeline do 2.

Guia de contribuição

Abrir o guia de contribuição

Avaliação

Esta issue ainda não foi avaliada.

Receba novas issues na sua caixa de entrada

Um resumo curto de issues do GitHub para quem está começando.