aboutcode-org / aboutcode-org/scancode.io

Don't rescan already scanned resources (container layers? packages?)

未关闭
#325 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
主要语言
Python
星标
215
派生
203
平均合并
4 天 8 小时
30 天内合并 PR
6

描述

This is related to #323 but could be extended to other resources

It would be good to reuse scans of stuff that has been already scanned.
This needs some discussion starting from granularity:
in case of containers it could be e.g. layers
for rootfs it could be on package level (hash from purl, scancode-toolkit version, and other metadata that might be needed) but this might be an issue when there would be a lot of packages to lookup from) general files would not be subject to such mechanism due to amount of them
I'm sure there is a lot more to think about regarding this but this is not a feature that we need quickly and I just wanted to open discussion regarding this and so it could be kept in mind during other changes

贡献指南

打开贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。