A recent scan of jqlang/jq identified 20 dependencies. Six of these were from Pipfile and were identified without version number; 14 of these were from Pipfile.lock and were identified with specific versions. The scan failed to identify a package in the modules directory of the project.
The non-versioned packages are not useful and can also result in false-positive vulnerability discoveries.
The modules should be identified as dependencies.
Scan results attached.
scancodeio_jqlang-test2.json
A recent scan of jqlang/jq identified 20 dependencies. Six of these were from
Pipfileand were identified without version number; 14 of these were fromPipfile.lockand were identified with specific versions. The scan failed to identify a package in themodulesdirectory of the project.The non-versioned packages are not useful and can also result in false-positive vulnerability discoveries.
The modules should be identified as dependencies.
Scan results attached.
scancodeio_jqlang-test2.json