You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Describe the bug
When running a load_sbom errors are reported for Maven dependencies during the create_dependencies operation. 110 package are affected. Example: Could not find resolved_to package entry: pkg:maven/org.apache.logging.log4j/log4j-core@2.24.1?type=jar
{
"type": "framework",
"bom-ref": "pkg:maven/org.apache.logging.log4j/log4j-core@2.24.1?type=jar",
"group": "org.apache.logging.log4j",
"name": "log4j-core",
"version": "2.24.1",
"description": "A versatile, industrial-grade, and reference implementation of the Log4j API.\n It bundles a rich set of components to assist various use cases:\n Appenders targeting files, network sockets, databases, SMTP servers;\n Layouts that can render CSV, HTML, JSON, Syslog, etc. formatted outputs;\n Filters that can be configured using log event rates, regular expressions, scripts, time, etc.\n It contains several extension points to introduce custom components, if needed.",
"licenses": [
{
"license": {
"id": "Apache-2.0",
"url": "https://opensource.org/licenses/Apache-2.0"
}
}
],
"purl": "pkg:maven/org.apache.logging.log4j/log4j-core@2.24.1?type=jar",
"properties": [
{
"name": "GradleProfileName",
"value": "compileClasspath"
}
]
},
Note: This file has been crafted by hand based on the original file which I cannot share. It should result in the aformentioned error for the package log4j-api@2.24.1.
Expected behavior
ScanCode.io should be able to resolve package
Screenshots
n.a.
The text was updated successfully, but these errors were encountered:
Describe the bug
When running a
load_sbom
errors are reported for Maven dependencies during thecreate_dependencies
operation. 110 package are affected. Example:Could not find resolved_to package entry: pkg:maven/org.apache.logging.log4j/log4j-core@2.24.1?type=jar
System configuration
Relevant part from SBOM:
To Reproduce
mwe-scancode-io-1576-v6.json
Note: This file has been crafted by hand based on the original file which I cannot share. It should result in the aformentioned error for the package
log4j-api@2.24.1
.Expected behavior
ScanCode.io should be able to resolve package
Screenshots
n.a.
The text was updated successfully, but these errors were encountered: