fix: report unparseable license ids instead of dropping them - #326
Draft
vibgrate-team wants to merge 1 commit into
Draft
vibgrate-team wants to merge 1 commit into
vibgrate-team wants to merge 1 commit into
Conversation
A declared license string that is not an SPDX id or expression now produces a stable vibgrate/license-unparseable warning on scan and SBOM export. Valid ids, aliases, and fuzzy family matches are unchanged. Fixes #233 Signed-off-by: Cursor Agent <cursoragent@cursor.com> Co-authored-by: vibgrate-team <vibgrate-team@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
vg scanandvg sbom exportused to turn a license string that is not an SPDX id or expression into a silent unknown: the id was dropped, and nothing told you what failed.An unparseable license now produces one stable warning,
vibgrate/license-unparseable. The message names the failed string and the manifest path (for examplepackage.json) and says to use an SPDX id or expression such asMITorApache-2.0. The text stays on one short line: a license-file body or a credential-shaped token is not copied into the message.A valid SPDX id, alias, or expression still parses as before. A fuzzy family match is not reported as a parse failure.
The same warning is included in text, JSON, SARIF, and Markdown scan output, and in CycloneDX and SPDX SBOM export (the declared string is kept, with the diagnostic attached).
Fixes #233
Related issues
Fixes #233
Checklist
pnpm testpassespnpm lintis cleanpnpm typecheckis cleangraph.json/ report output (content-hashed IDs, stable sorts; no time, randomness, or filesystem-order dependence)git commit -s, DCO)Notes for reviewers
The warning fires when a non-empty declared string does not resolve, and when a constituent id inside an expression does not resolve. Explicit
NOASSERTION/NONEtokens stay quiet, because those are recognized no-assertion values. The changelog entry under Unreleased describes the user-visible change.