From 2feb3a1d1b80ae8a8ed52b4ed4e33454af83eca8 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Maximilian=20Comb=C3=BCchen?= Date: Wed, 11 Dec 2024 09:58:30 +0100 Subject: [PATCH] fix: handle empty package supplier name in SPDX Closes #92. --- lib/ecosystems/enrich_spdx.go | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/lib/ecosystems/enrich_spdx.go b/lib/ecosystems/enrich_spdx.go index d2106e6..b97b57e 100644 --- a/lib/ecosystems/enrich_spdx.go +++ b/lib/ecosystems/enrich_spdx.go @@ -76,7 +76,7 @@ func enrichSPDXSupplier(pkg *v2_3.Package, data *packages.Package) { if data.RepoMetadata != nil { meta := *data.RepoMetadata if ownerRecord, ok := meta["owner_record"].(map[string]interface{}); ok { - if name, ok := ownerRecord["name"].(string); ok { + if name, ok := ownerRecord["name"].(string); ok && name != "" { pkg.PackageSupplier = &common.Supplier{ SupplierType: "Organization", Supplier: name,