Skip to content

Optionally only collect the PURL of packages, source packages and dependencies in ScanCode Toolkit #3464

@pombredanne

Description

@pombredanne

I would like to have a minimal and lightweight, fast --package scan option that does not do anything more than collecting PURLs, either for actual packages that are present and for their dependencies. This would then a nice input for other pipelines and tools that are based on PURL only.

Minimal would mean that beyond PURL (and may be a version range for depsn) no other metadata, no license detection and no complex assembly, nor package files or package instance creation would be needed.

This could be a new --purl scan option, with a skinny output data structure to design.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions