aboutcode-org / aboutcode-org/scancode.io

Should a dependency tree be scoped to a single project ?

オープン
#888 コメント 1 件 リアクション 1 件 担当者 0 名 GitHub で見る
主要言語
Python
スター
215
フォーク
203
平均マージ
4日 8時間
マージ済み PR(30日)
6

説明

As being discussed in https://github.com/nexB/scancode.io/issues/885, we need to improve the Package and Dependency relationships to support transitive dependencies.

During this, should a dependency tree be specific to a single project being scanned or shared across all the projects.
Say, for example:
```
purl A
+------purl B
+------purl C
+------purl D
```
here, whenever and wherever we find `purl A`, we know - for sure - that the above dependency tree will be present. Same applies for `purl C` (purl D will always be a dependency) regardless of the project being scanned.

Would it make more sense to have a central dependency relationship mapping as the source of truth for entire SCIO that will be ever-evolving with every scan performed ?

There is one caveat to this approach, let's say `purl C` changes its dependency from `purl D` to `purl E` at some point of time after the scan was run. This breaks the entire hypothesis of having a central dependency mapping source of truth.
Ideally, purls should not change dependencies at points of time but we live in a weird world.

コントリビューションガイド

コントリビューションガイドを開く

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。