fix: keep components when a package URL cannot be encoded - #331
Closed
vibgrate-team wants to merge 1 commit into
Closed
vibgrate-team wants to merge 1 commit into
vibgrate-team wants to merge 1 commit into
Conversation
A name that cannot be a Package URL was percent-encoded into a purl-shaped string, or the purl was omitted with no signal. The component stays in the SBOM, the purl is left off, and the output records vibgrate:purlStatus=unavailable with a warning that names the package and ecosystem. Fixes #250 Signed-off-by: Cursor Agent <cursoragent@cursor.com> Co-authored-by: vibgrate-team <vibgrate-team@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
vg sbom exportkept a component only when it could turn the package name into a Package URL. A space, an empty path segment, or another character outside the purl name alphabet was percent-encoded into a purl-shaped string such aspkg:npm/foo%20bar@1.0.0, or the purl was left off with no signal. A project type with no purl type was reported as npm.The component now stays in the document. When the name cannot be encoded:
purland addsvibgrate:purlStatus=unavailableplusvibgrate:purlWarning.externalRefand records the same status and warning on the package.vg sbom exportprints that warning. It names the package and ecosystem and says to use a name with no spaces or empty path segments, then regenerate the SBOM. It does not include a filesystem path or the declared spec.A component that already encodes to a valid purl is unchanged, including scoped npm names and the other registries. CycloneDX graph export and a release frozen from a scan artifact use the same rule, so a valid npm purl stays
pkg:npm/<name>@<version>and a name that cannot be encoded is kept without an invented purl.Related issues
Fixes #250
Checklist
pnpm testpassespnpm lintis cleanpnpm typecheckis cleangraph.json/ report output (content-hashed IDs, stable sorts; no time,randomness, or filesystem-order dependence)
git commit -s, DCO)Notes for reviewers
The unavailable result is a warning, not a failed export: the SBOM is still written so the rest of the inventory remains usable.
bom-reffor a component without a purl is a stablevibgrate:<ecosystem>:<name>@<version>string, not apkg:URL.