anchore / anchore/syft

SPDX fileTypes: classify shebang scripts as SOURCE (optionally +TEXT)

Open
#4,640 1 comment 0 reactions 1 assignee Claimed by @spiffcs View on GitHub
enhancement
Dominant language
Go
Stars
9.6k
Forks
954
Avg merge
23h 27m
Merged PRs (30d)
48

Description

**What would you like to be added**:
Improve SPDX 2.3 `fileTypes` classification so that files identified as scripts (e.g., files with a valid shebang `#!` header) are emitted with `SOURCE` in addition to or instead of only `TEXT`.

Today, Syft appears to classify shebang scripts (e.g., `/usr/sbin/dpkg-preconfigure`) as:
```
"fileTypes": ["TEXT"]
```

Since SPDX 2.3 does not define a `SCRIPT` type, the closest semantic match for executable scripts is `SOURCE`.

Proposed behavior:

If file starts with a valid shebang (`#!`), emit:
```
"fileTypes": ["SOURCE", "TEXT"]
```

**Why is this needed**:
SPDX 2.3 defines `SOURCE` as “human readable source code” and `TEXT` as generic text. Scripts (shell, Python, Perl, etc.) are executable source code, not arbitrary text.

Emitting only `TEXT` loses semantic information and makes it difficult for downstream consumers to distinguish between executable scripts and arbitrary text artifacts.

Tools performing policy enforcement, integrity validation, or runtime classification rely on SPDX metadata to differentiate executable artifacts from non-executable text files.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.