Skip to content

fix: include source path on unparseable license findings - #337

Closed
vibgrate-team wants to merge 1 commit into
mainfrom
cursor/license-finding-path-bddb
Closed

vibgrate-team wants to merge 1 commit into
mainfrom
cursor/license-finding-path-bddb

Conversation

@vibgrate-team

Copy link
Copy Markdown
Contributor

Summary

vg scan now keeps a stable, repo-relative path on license findings in machine-readable JSON and SARIF when a local declaration cannot be parsed as SPDX.

For each project directory the scan already knows, it reads a package.json license / licenses field (when that file is present) and the fixed names LICENSE, LICENCE, COPYING, and NOTICE (plus .md / .txt) in that directory. A declaration that does not resolve to a known SPDX id is reported as vibgrate/license-unparseable instead of being dropped:

  • JSON sets location and details.path to the path (LICENSE, packages/foo/package.json)
  • SARIF uses that same path as physicalLocation.artifactLocation.uri and properties.path

The license body is not copied into the artifact. Findings are sorted by path. Registry license strings have no local file, so they stay on the dependency row (license.raw, license.spdxId: null) and are not given a path. Standard license titles (Apache, MIT, GPL, BSD, ISC, MPL, Unlicense) and an SPDX-License-Identifier that parses are not flagged. A failed SPDX tag does not fall through to a later title.

Related issues

Fixes #213

Checklist

  • pnpm test passes
  • pnpm lint is clean
  • pnpm typecheck is clean
  • Docs updated (README / DOCS / ARCHITECTURE) where behavior changed
  • Determinism preserved — identical input still produces identical
    graph.json / report output (content-hashed IDs, stable sorts; no time,
    randomness, or filesystem-order dependence)
  • No proprietary or internal references — public, Apache-2.0 content only
  • Commits use Conventional Commits and are signed off (git commit -s, DCO)

Notes for reviewers

Verification:

  • pnpm test — 460 files, 4904 tests passed
  • pnpm lint — exit 0 (existing unused-var warnings only, none in this change)
  • pnpm typecheck — exit 0
  • Fixture src/core-open/licenses/evidence.test.ts asserts the path LICENSE appears in scan JSON (location, details.path) and SARIF (artifactLocation.uri, properties.path), that the file body is not emitted, and that two collections of the same tree are byte-identical
Open in Web Open in Cursor 

When a local license declaration cannot be parsed as SPDX, vg scan now
emits vibgrate/license-unparseable with the repo-relative path in JSON
and SARIF instead of dropping the file. Registry licenses without a
local file stay on the dependency row.

Signed-off-by: Cursor Agent <cursoragent@cursor.com>

Co-authored-by: vibgrate-team <vibgrate-team@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Enhancement: include source path for license findings in machine-readable scan output

2 participants