Context
If a package license string cannot be parsed into an SPDX-style identifier, silently omitting it from vg scan / report / SBOM paths hides data quality problems. Users should see an actionable message (what failed + what to do), consistent with local-first, no-secrets error style.
What to do
- Reproduce with a fixture package whose license field is malformed / non-SPDX.
- Ensure machine-readable and human output either include a structured warning/finding or a clear stderr note — never a quiet omission with no trace.
- Keep determinism: same fixture → same warning text/code every run.
- Never log registry tokens or file contents that look like secrets.
Acceptance
Refs: #213 (license source path) · #150 (actionable failures)
Context
If a package license string cannot be parsed into an SPDX-style identifier, silently omitting it from
vg scan/ report / SBOM paths hides data quality problems. Users should see an actionable message (what failed + what to do), consistent with local-first, no-secrets error style.What to do
Acceptance
Refs: #213 (license source path) · #150 (actionable failures)