Skip to content

fix(scan): include a source path on license findings - #340

Draft
vibgrate-team wants to merge 1 commit into
mainfrom
cursor/license-finding-path-5df5
Draft

vibgrate-team wants to merge 1 commit into
mainfrom
cursor/license-finding-path-5df5

Conversation

@vibgrate-team

Copy link
Copy Markdown
Contributor

Summary

vg scan JSON and SARIF now include a stable source path for a declared license whenever the scan already has an evidence file.

  • A manifest license field is recorded at that manifest (projects[].license.path, finding location).
  • Otherwise the first existing LICENSE / LICENCE / COPYING / NOTICE file (fixed name order) is the evidence path.
  • Text that does not parse as SPDX becomes a warning, vibgrate/unparseable-license, at that path instead of being dropped. A parsed SPDX id is a note, vibgrate/license, at the same path.
  • The license file body is not copied into the artifact. Registry-only dependency licenses still have no local file, so they stay on the dependency row and are not promoted to a finding.
  • License findings are sorted by path, so the output does not follow directory walk order.

Related issues

Fixes #213

Checklist

  • pnpm test passes
  • pnpm lint is clean
  • pnpm typecheck is clean
  • Docs updated (README / DOCS / ARCHITECTURE) where behavior changed
  • Determinism preserved — identical input still produces identical graph.json / report output (content-hashed IDs, stable sorts; no time, randomness, or filesystem-order dependence)
  • No proprietary or internal references — public, Apache-2.0 content only
  • Commits use Conventional Commits and are signed off (git commit -s, DCO)

Notes for reviewers

Verify with pnpm test, pnpm lint, and pnpm typecheck. test/license-findings.test.ts scans a fixture pkg/LICENSE whose body is not a SPDX expression and asserts pkg/LICENSE appears on the project license, the JSON finding, and the SARIF artifactLocation.uri, and that the file body is absent from the artifact.

Open in Web Open in Cursor 

Declared licenses from a manifest or a LICENSE/NOTICE/COPYING file now
carry a stable repo-relative path in scan JSON and SARIF. Text that
does not parse as SPDX is reported at that path instead of being
dropped, and the file body is not copied into the artifact.

Fixes #213

Signed-off-by: Cursor Agent <cursoragent@cursor.com>

Co-authored-by: vibgrate-team <vibgrate-team@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Enhancement: include source path for license findings in machine-readable scan output

2 participants