anchore / anchore/syft

Use `mvn dependency:tree` to resolve dependency information for Maven source

Open
#2,019 2 comments 0 reactions 0 assignees View on GitHub
Dominant language
Go
Stars
9.6k
Forks
962
Avg merge
23h 27m
Merged PRs (30d)
48

Description

This issue has no description.

Contributor guide

Open the contributing guide

Research direction

The issue names no files, tests, or entry points, so first locate the Maven source handling and its current dependency-resolution path in the Syft repository. Compare that behavior with the dependency information produced by `mvn dependency:tree`; done means Maven source dependencies are resolved through that command and the relevant behavior is covered by tests.

Written by the indexing model from the issue text.

Assessment

Domain
tooling
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.