Skip to content

BUG: pypi dependencies are not consistently identified #1598

Open
@DennisClark

Description

@DennisClark

I used the scan_single_package pipeline to scan the package (source code) available at
https://github.com/aboutcode-org/scancode.io/archive/refs/tags/v34.9.5.tar.gz
and SCIO v34.9.5 found 52 dependencies but many of them are very incomplete, and have what appear to be a valid PURL but do not have any Download URL or License. The problem packages are all from pypi.

It seems very strange that SCIO is able to identify a specific, valid version of these problem packages, which can be found online, but it is not getting a Download URL, suggesting that there are special aspects of the pypi repo that it is not handling very well. Please see the attached scan results.

scancodeio_scio-v34.9.5.json

Metadata

Metadata

Labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions