Skip to content

fix: keep components when a package URL cannot be encoded - #331

Closed
vibgrate-team wants to merge 1 commit into
mainfrom
cursor/purl-encoding-unavailable-f207
Closed

vibgrate-team wants to merge 1 commit into
mainfrom
cursor/purl-encoding-unavailable-f207

Conversation

@vibgrate-team

Copy link
Copy Markdown
Contributor

Summary

vg sbom export kept a component only when it could turn the package name into a Package URL. A space, an empty path segment, or another character outside the purl name alphabet was percent-encoded into a purl-shaped string such as pkg:npm/foo%20bar@1.0.0, or the purl was left off with no signal. A project type with no purl type was reported as npm.

The component now stays in the document. When the name cannot be encoded:

  • CycloneDX omits purl and adds vibgrate:purlStatus=unavailable plus vibgrate:purlWarning.
  • SPDX omits the purl externalRef and records the same status and warning on the package.
  • vg sbom export prints that warning. It names the package and ecosystem and says to use a name with no spaces or empty path segments, then regenerate the SBOM. It does not include a filesystem path or the declared spec.
  • The same tree produces the same document and the same warnings.

A component that already encodes to a valid purl is unchanged, including scoped npm names and the other registries. CycloneDX graph export and a release frozen from a scan artifact use the same rule, so a valid npm purl stays pkg:npm/<name>@<version> and a name that cannot be encoded is kept without an invented purl.

Related issues

Fixes #250

Checklist

  • pnpm test passes
  • pnpm lint is clean
  • pnpm typecheck is clean
  • Docs updated (README / DOCS / ARCHITECTURE) where behavior changed
  • Determinism preserved — identical input still produces identical
    graph.json / report output (content-hashed IDs, stable sorts; no time,
    randomness, or filesystem-order dependence)
  • No proprietary or internal references — public, Apache-2.0 content only
  • Commits use Conventional Commits and are signed off (git commit -s, DCO)

Notes for reviewers

The unavailable result is a warning, not a failed export: the SBOM is still written so the rest of the inventory remains usable. bom-ref for a component without a purl is a stable vibgrate:<ecosystem>:<name>@<version> string, not a pkg: URL.

Open in Web Open in Cursor 

A name that cannot be a Package URL was percent-encoded into a purl-shaped
string, or the purl was omitted with no signal. The component stays in the
SBOM, the purl is left off, and the output records
vibgrate:purlStatus=unavailable with a warning that names the package and
ecosystem.

Fixes #250

Signed-off-by: Cursor Agent <cursoragent@cursor.com>

Co-authored-by: vibgrate-team <vibgrate-team@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Bug: surface actionable errors when component PURL encoding fails (no silent omit)

2 participants