-
Notifications
You must be signed in to change notification settings - Fork 1
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Wrong dump data for Debian packages #1
Comments
@armijnhemel you have eagle yes! thanks for the report. |
The point is that for now the model is to have one download URL == one record in the purldb |
Having thought a bit about this there are some other issues as well, which can possibly interfere (not in this particular case, but in general). First of all, there is the situation where there are multiple files/download URLs that point to the same package. For example, let's look at GNU binutils: https://ftp.gnu.org/gnu/binutils/ For Then there is the situation where multiple components/sources are used in a certain configuration (like in the Debian example). So what I could envision is that
Or something like that. |
Some more thoughts: Debian typically renames the original files (to something like A question: when encountering these (without patches or other files, just standalone), should they be mapped to the original package or to the Debian package? There is something to say for both. |
Not sure if this should go here or another repository, so feel free to move.
I just looked at
deb-purls-aa.json.zst
and saw this line:The package number and the referenced source code file do not match: the file in
download_url
is the original file and is actually the same for multiple patch versions. The version number only becomes-4
after applying the Debian specific patches, so these should probably also be included. The patches for-4
are no longer available via the Debian FTP, but for-5
they are.The
.dsc
file for-5
says:So possibly you should not have this as a single download URL, but as a list of download URLs.
Also, with Debian these URLs tend to get moved (granted, after many years) to their archive. It might be good to take a closer look at aboutcode-org/fetchcode#82
The text was updated successfully, but these errors were encountered: