Skip to content

fix: report unparseable license ids instead of dropping them - #326

Draft
vibgrate-team wants to merge 1 commit into
mainfrom
cursor/license-parse-diagnostic-15f8
Draft

vibgrate-team wants to merge 1 commit into
mainfrom
cursor/license-parse-diagnostic-15f8

Conversation

@vibgrate-team

@vibgrate-team vibgrate-team commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Summary

vg scan and vg sbom export used to turn a license string that is not an SPDX id or expression into a silent unknown: the id was dropped, and nothing told you what failed.

An unparseable license now produces one stable warning, vibgrate/license-unparseable. The message names the failed string and the manifest path (for example package.json) and says to use an SPDX id or expression such as MIT or Apache-2.0. The text stays on one short line: a license-file body or a credential-shaped token is not copied into the message.

A valid SPDX id, alias, or expression still parses as before. A fuzzy family match is not reported as a parse failure.

The same warning is included in text, JSON, SARIF, and Markdown scan output, and in CycloneDX and SPDX SBOM export (the declared string is kept, with the diagnostic attached).

Fixes #233

Related issues

Fixes #233

Checklist

  • pnpm test passes
  • pnpm lint is clean
  • pnpm typecheck is clean
  • Docs updated (README / DOCS / ARCHITECTURE) where behavior changed
  • Determinism preserved — identical input still produces identical graph.json / report output (content-hashed IDs, stable sorts; no time, randomness, or filesystem-order dependence)
  • No proprietary or internal references — public, Apache-2.0 content only
  • Commits use Conventional Commits and are signed off (git commit -s, DCO)

Notes for reviewers

The warning fires when a non-empty declared string does not resolve, and when a constituent id inside an expression does not resolve. Explicit NOASSERTION / NONE tokens stay quiet, because those are recognized no-assertion values. The changelog entry under Unreleased describes the user-visible change.

Open in Web Open in Cursor 

A declared license string that is not an SPDX id or expression now
produces a stable vibgrate/license-unparseable warning on scan and
SBOM export. Valid ids, aliases, and fuzzy family matches are unchanged.

Fixes #233

Signed-off-by: Cursor Agent <cursoragent@cursor.com>

Co-authored-by: vibgrate-team <vibgrate-team@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Bug: surface actionable errors when license IDs fail SPDX-style parse (no silent drop)

2 participants