aboutcode-org / aboutcode-org/scancode.io

JVM d2d: match dependencies from pom.xml

Offen
#1,907 7 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
Vorherrschende Sprache
Python
Sterne
215
Forks
203
Ø Merge
4 T. 8 Std.
Gemergte PRs (30 T.)
6

Beschreibung

- Ref: https://github.com/aboutcode-org/scancode.io/issues/1473

A significant number of non-matching files appear to originate from dependencies included during the build process.
For instance:
`poi-tl-v1.12.0`
Devel: https://github.com/Sayi/poi-tl/archive/refs/tags/v1.12.0.zip#from
Deploy: https://github.com/Sayi/poi-tl/releases/download/v1.12.0/poi-tl-cli.jar#to
Some of the non-matching files found in the deployment:
```
to/com/beust/jcommander/validators/NoValidator.class
to/com/beust/jcommander/validators/NoValueValidator.class
to/com/beust/jcommander/validators/PositiveInteger.class
to/com/beust/jcommander/WrappedParameter.class
to/com/codewaves/codehighlight/core/Highlighter$HighlightResult.class
to/com/codewaves/codehighlight/core/Highlighter.class
to/com/codewaves/codehighlight/core/HighlightParser$1.class
to/com/codewaves/codehighlight/core/HighlightParser$ParentWrapper.class
to/com/codewaves/codehighlight/core/HighlightParser.class
```

However, these "missing" code packages exist in the pom.xml
`./poi-tl-cli/pom.xml`
```

com.beust
jcommander
1.72

```
`./poi-tl-plugin-highlight/pom.xml`
```

com.deepoove
codehighlight
1.0.3

```

It would be great if we could parse/extract/index the dependency packages listed in the pom.xml, and then correlate them with the "missing" source files to improve the D2D process.

Beitragsleitfaden

Beitragsleitfaden öffnen

Bewertung

Dieses Issue wurde noch nicht bewertet.

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.