nexB / purldb

Tools to create and expose a database of purls (Package URLs). This project is sponsored by NLnet project https://nlnet.nl/project/vulnerabilitydatabase/ and nexB for https://www.aboutcode.org/ Chat is at https://gitter.im/aboutcode-org/discuss
https://purldb.readthedocs.io/
29 stars 21 forks source link

Double check that package_content are set correctly in Maven package sets. #396

Open pombredanne opened 2 months ago

pombredanne commented 2 months ago

Some PURLs may not be classified correctly in their Package set:

    "package_content": "source_repo",
    "purl": "pkg:maven/org.apache.htrace/htrace-core@3.1.0-incubating?classifier=sources

.... should be a source_archive

    "package_content": "source_archive",
    "purl": "pkg:maven/org.apache.htrace/htrace-core@3.1.0-incubating",

... should be a binary archive