-
Notifications
You must be signed in to change notification settings - Fork 320
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Replacement for git://
URLs does not seem to be working for submodules
#8918
Comments
Wouldn't it suffice if we enforce this on a system level when building the Docker image via |
I guess that should work. |
Would the analyzer result contain |
I believe so, yes. |
Here is a .NET minimal example: <Project Sdk="Microsoft.NET.Sdk">
<PropertyGroup>
<OutputType>Exe</OutputType>
<TargetFramework>net8.0</TargetFramework>
<RootNamespace>antlrl3_test</RootNamespace>
<ImplicitUsings>enable</ImplicitUsings>
<Nullable>enable</Nullable>
</PropertyGroup>
<ItemGroup>
<PackageReference Include="Antlr3.Runtime" Version="3.5.1" />
</ItemGroup>
</Project> put it into a |
Despite 3d27d61, the provenance resolver that runs as part of the scanner does not seem to be able to clone Git repositories that contain submodules which still refer via
git://´ to GitHub repositories (GitHub has deprecated the
git://` protocol):YAML entry:
However, the more severe issue seems to be that as a result of the above, the
PyPI::scikit-image:0.19.3
is not scanned at all, neither as a repository without submodules, nor the source artifact (which was found). At least there is no correspondingprovenance
entry in thescan_results
section.The text was updated successfully, but these errors were encountered: