+
Skip to content

Refactor Java metadata: use top-level maven metadata & deprecate scope from PomProperties #3377

@kzantow

Description

@kzantow

Today, when scanning a source repository, including resolving packages from Maven pom.xml, Syft uses the metadata type pkg.JavaArchive, which is not really representative of what was scanned. These could perhaps use JavaPomProject as the top-level metadata.

Additionally, the dependency scope is being captured in JavaPomProperties, which is not the correct spot for this information -- it should be part of the relationship, but this is not being tracked as any part of the relationship today.

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    Status

    No status

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions

      点击 这是indexloc提供的php浏览器服务,不要输入任何密码和下载