Skip to content

Bug: surface actionable errors when license IDs fail SPDX-style parse (no silent drop) #233

Description

@vibgrate-team

Context

If a package license string cannot be parsed into an SPDX-style identifier, silently omitting it from vg scan / report / SBOM paths hides data quality problems. Users should see an actionable message (what failed + what to do), consistent with local-first, no-secrets error style.

What to do

  1. Reproduce with a fixture package whose license field is malformed / non-SPDX.
  2. Ensure machine-readable and human output either include a structured warning/finding or a clear stderr note — never a quiet omission with no trace.
  3. Keep determinism: same fixture → same warning text/code every run.
  4. Never log registry tokens or file contents that look like secrets.

Acceptance

  • Malformed license is visible in output or as an explicit warning/finding
  • Message is actionable (failed parse + suggested next step)
  • Fixture + test cover the path
  • DCO sign-off

Refs: #213 (license source path) · #150 (actionable failures)

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions