Repository navigation
fix(report): preserve archive member provenance in JSON - #816
Open
mohgupta-ship-it wants to merge 1 commit into
Open
mohgupta-ship-it wants to merge 1 commit into
mohgupta-ship-it wants to merge 1 commit into
Conversation
Signed-off-by: Mohit Gupta <mohgupta@nvidia.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
JSON component rows omitted archive provenance already present in the scanner inventory. A consumer therefore received paths such as
bundle.whl!/package/module.pywithout the structured container and member fields needed to interpret them.Preserve
outer_path,nested_path, and container metadata for archive members while keeping the existing virtualpath, executable flags, source identity, findings, risk scoring, and completeness behavior. Ordinary filenames containing!/remain ordinary files. Document how consumers should interpret the additive fields; existing consumer validators still need to adopt them.Validation:
Prepared by Codex on Mohit's behalf.