ort scanner error: IOException: Could not resolve provenance for package 'NPM:@adam-family:am-common-lib:18.3.0' for source code origins [VCS, ARTIFACT]." #9386
-
Hi all, I think this is why the ort scanner produces the error Can anyone help me regading this issue or how to work with private repo packages and to scan these ones? thx |
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 1 reply
-
This is not necessarily a problem. If no
This means that ORT found neither a VCS repository nor an artifact that provides the source code. While you have your credentials in |
Beta Was this translation helpful? Give feedback.
This is not necessarily a problem. If no
repository
was defined in your privatepackage.json
, then these fields will be empty. ORT then tries to get the source code from an NPM.tgz
artifact instead.This means that ORT found neither a VCS repository nor an artifact that provides the source code. While you have your credentials in
.npmrc
, the scanner does not use NPM to download the artifacts, which means tha…