scancode-toolkit icon indicating copy to clipboard operation
scancode-toolkit copied to clipboard

Create winexe package only when name is available?

Open JonoYang opened this issue 3 years ago • 0 comments

I scanned a docker image layer from docker://python:3.8-slim-buster using the --system-package option and there were a number of Package data detected from Windows executables that did not provide a name or any other information:

        {
          "type": "winexe",
          "namespace": null,
          "name": null,
          "version": null,
          "qualifiers": {},
          "subpath": null,
          "primary_language": null,
          "description": "",
          "release_date": null,
          "parties": [],
          "keywords": [],
          "homepage_url": null,
          "download_url": null,
          "size": null,
          "sha1": null,
          "md5": null,
          "sha256": null,
          "sha512": null,
          "bug_tracking_url": null,
          "code_view_url": null,
          "vcs_url": null,
          "copyright": null,
          "license_expression": "unknown AND unknown",
          "declared_license": {
            "LegalCopyright": null,
            "LegalTrademarks": "",
            "License": null
          },
          "notice_text": null,
          "source_packages": [],
          "file_references": [],
          "extra_data": {},
          "dependencies": [],
          "repository_homepage_url": null,
          "repository_download_url": null,
          "api_data_url": null,
          "datasource_id": "windows_executable",
          "purl": null
        }

Should we skip package creation for Windows executables if we cannot get a name for it?

JonoYang avatar Aug 17 '22 22:08 JonoYang