Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

SCIO scan_package pipeline does not analyze yarn.lock file #1570

Open
mjherzog opened this issue Jan 28, 2025 · 5 comments
Open

SCIO scan_package pipeline does not analyze yarn.lock file #1570

mjherzog opened this issue Jan 28, 2025 · 5 comments
Labels
bug Something isn't working

Comments

@mjherzog
Copy link
Member

I ran the scan_package pipeline on a yarn.lock file to get the list of packages, but SCIO returned only 1 Resource record for the file itself.
The header of the yarn.lock files says: (yarn lockfile v1).

The pipeline was run on SCIO v34.93 (SCTK v32.3.1)

@mjherzog mjherzog added the bug Something isn't working label Jan 28, 2025
@pombredanne
Copy link
Member

@mjherzog if the only thing we have is a yarn.lock, then there are no file we can attach to it beyond the file itself. The files would be attached to an actual package designated by a package.json instead.

@mjherzog
Copy link
Member Author

mjherzog commented Jan 30, 2025

So what do you run in SCIO to analyze a package manifest on its own? Does SCTK handle it?

@DennisClark
Copy link
Member

@mjherzog and @pombredanne I tested a scan of Michael's yarn.lock file and it did show that it read and interpreted the file in the scan results, but all of the download URLs were to a secured private repo requiring credentials so it did not provide any additional information about those packages.

@mjherzog
Copy link
Member Author

mjherzog commented Jan 30, 2025

@DennisClark Thank you for the research - that makes sense. Did you test the scan_package pipeline with a yarn.lock file that has public download URLs? I recall that you did and the results were better. Please document here for posterity.

@DennisClark
Copy link
Member

@mjherzog yes I ran a successful scan on a yarn.lock file containing public download URLs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

No branches or pull requests

3 participants