Currently, scancode creates package objects from package manifest files. It would be useful to look at other ancillary package files for more information to enhance the data used to create the package object. For example, when reporting a Python package from a METADATA file, we can also find the package files for that package from looking at the RECORD file that is in the same directory as METADATA. This idea can be generalized for other packages, where missing package data can be filled in from multiple sources that are alongside the main package manifest file.
Currently, scancode creates package objects from package manifest files. It would be useful to look at other ancillary package files for more information to enhance the data used to create the package object. For example, when reporting a Python package from a
METADATAfile, we can also find the package files for that package from looking at theRECORDfile that is in the same directory asMETADATA. This idea can be generalized for other packages, where missing package data can be filled in from multiple sources that are alongside the main package manifest file.