Dependency Submission API doesn't allow arbitrary package URL types
#87501
-
Select Topic AreaBug BodyAs noted in package-url/purl-spec#286, the GitHub's Dependency Submission API, which consumes pURL(s) appears to be rejecting pURLs with arbitrary I've asked for clarification in package-url/purl-spec#286 for the spec's purposes, and also raising here for visibility. I would expect that the API would allow augmenting with any package data, rather than requiring it just be "known" types. As noted in package-url/purl-spec#286 (comment), the (Aside: I believe that in the above case, a translation from However, there will still be package types that aren't "known" - for instance organisation-specific ones - and therefore restricting usage of them in the API is a little frustrating. |
Beta Was this translation helpful? Give feedback.
Replies: 3 comments 1 reply
This comment was marked as off-topic.
This comment was marked as off-topic.
This comment was marked as duplicate.
This comment was marked as duplicate.
-
|
This is now supported 👏🏽 https://github.blog/changelog/2025-04-03-dependency-graph-supports-all-purl-identified-package-ecosystems |
Beta Was this translation helpful? Give feedback.
This is now supported 👏🏽 https://github.blog/changelog/2025-04-03-dependency-graph-supports-all-purl-identified-package-ecosystems