aboutcode-org / aboutcode-org/scancode.io

JVM d2d: match dependencies from pom.xml

オープン
#1,907 コメント 7 件 リアクション 0 件 担当者 0 名 GitHub で見る
主要言語
Python
スター
215
フォーク
203
平均マージ
4日 8時間
マージ済み PR(30日)
6

説明

- Ref: https://github.com/aboutcode-org/scancode.io/issues/1473

A significant number of non-matching files appear to originate from dependencies included during the build process.
For instance:
`poi-tl-v1.12.0`
Devel: https://github.com/Sayi/poi-tl/archive/refs/tags/v1.12.0.zip#from
Deploy: https://github.com/Sayi/poi-tl/releases/download/v1.12.0/poi-tl-cli.jar#to
Some of the non-matching files found in the deployment:
```
to/com/beust/jcommander/validators/NoValidator.class
to/com/beust/jcommander/validators/NoValueValidator.class
to/com/beust/jcommander/validators/PositiveInteger.class
to/com/beust/jcommander/WrappedParameter.class
to/com/codewaves/codehighlight/core/Highlighter$HighlightResult.class
to/com/codewaves/codehighlight/core/Highlighter.class
to/com/codewaves/codehighlight/core/HighlightParser$1.class
to/com/codewaves/codehighlight/core/HighlightParser$ParentWrapper.class
to/com/codewaves/codehighlight/core/HighlightParser.class
```

However, these "missing" code packages exist in the pom.xml
`./poi-tl-cli/pom.xml`
```

com.beust
jcommander
1.72

```
`./poi-tl-plugin-highlight/pom.xml`
```

com.deepoove
codehighlight
1.0.3

```

It would be great if we could parse/extract/index the dependency packages listed in the pom.xml, and then correlate them with the "missing" source files to improve the D2D process.

コントリビューションガイド

コントリビューションガイドを開く

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。