aboutcode-org / aboutcode-org/scancode.io

Maven package not identified in dependencies

Ouverte
#1,576 3 commentaires 0 réactions 0 personnes assignées Voir sur GitHub
bug
Langage dominant
Python
Étoiles
215
Forks
203
Merge moyen
4 j 8 h
PR mergées (30 j)
6

Description

**Describe the bug**
When running a `load_sbom` errors are reported for Maven dependencies during the `create_dependencies` operation. 110 package are affected. Example:
`Could not find resolved_to package entry: pkg:maven/org.apache.logging.log4j/log4j-core@2.24.1?type=jar`

**System configuration**
- Which version of ScanCode.io are you running?
- d9f50b1b30b59916ed484460d9f60feebd14750b
- Are you running the app using Docker?
- No, Helm chart for Kubernetes
- On which OS?
- Linux
- What inputs are you using?
- SBOM generated with cdxgen (see excerpt below)
- Which pipeline are you running?
- load_sbom

Relevant part from SBOM:
```
{
"type": "framework",
"bom-ref": "pkg:maven/org.apache.logging.log4j/log4j-core@2.24.1?type=jar",
"group": "org.apache.logging.log4j",
"name": "log4j-core",
"version": "2.24.1",
"description": "A versatile, industrial-grade, and reference implementation of the Log4j API.\n It bundles a rich set of components to assist various use cases:\n Appenders targeting files, network sockets, databases, SMTP servers;\n Layouts that can render CSV, HTML, JSON, Syslog, etc. formatted outputs;\n Filters that can be configured using log event rates, regular expressions, scripts, time, etc.\n It contains several extension points to introduce custom components, if needed.",
"licenses": [
{
"license": {
"id": "Apache-2.0",
"url": "https://opensource.org/licenses/Apache-2.0"
}
}
],
"purl": "pkg:maven/org.apache.logging.log4j/log4j-core@2.24.1?type=jar",
"properties": [
{
"name": "GradleProfileName",
"value": "compileClasspath"
}
]
},
```

**To Reproduce**

1. Create a product in DejaCode
2. Use Action > Load Packages from SBOMs

[mwe-scancode-io-1576-v6.json](https://github.com/user-attachments/files/18748871/mwe-scancode-io-1576-v6.json)

Note: This file has been crafted by hand based on the original file which I cannot share. It should result in the aformentioned error for the package `log4j-api@2.24.1`.

**Expected behavior**
ScanCode.io should be able to resolve package

**Screenshots**
n.a.

Guide de contribution

Ouvrir le guide de contribution

Évaluation

Cette issue n'a pas encore été évaluée.

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.