objectionary / objectionary/lints

`addDependencyRelationships` function crashes on missing transitive Maven dependency in SPDX report generation

Open
#869 0 comments 0 reactions 1 assignee View on GitHub

@volodya-lombrozo is already working on this.

Since May 25, 2026.

bug good-title
Dominant language
Java
Stars
14
Forks
39
Avg merge
22h 54m
Merged PRs (30d)
90

Description

I'm getting this in CI when ORT generates the SPDX report:

Exception in thread "main" java.util.NoSuchElementException: Key (Identifier(type=Maven, namespace=com.jcabi, name=jcabi-xml, version=0.35.0), Identifier(type=Maven, namespace=com.jcabi, name=jcabi-log, version=0.24.3)) is missing in the map.
	at org.ossreviewtoolkit.plugins.reporters.spdx.SpdxDocumentModelMapper.map$addDependencyRelationships(SpdxDocumentModelMapper.kt:74)
	at org.ossreviewtoolkit.plugins.reporters.spdx.SpdxDocumentModelMapper.map(SpdxDocumentModelMapper.kt:125)
	at org.ossreviewtoolkit.plugins.reporters.spdx.SpdxDocumentReporter.generateReport(SpdxDocumentReporter.kt:124)

ORT's addDependencyRelationships looks up the jcabi-xml → jcabi-log edge in its packages map, but the transitive dependency is missing from it and the whole report generation fails.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.