Handle Duplicate Keys in package.json
and pnpm-lock
Files
#1345
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Ticket
IDETECT-4594
Summary
This Merge Request resolves the issue where Detect fails to handle
package.json
andpnpm-lock
files containing duplicate keys, causing aJsonSyntaxException
. The proposed solution sanitizes the JSON files by removing duplicate keys, retaining the last occurrence of each key. This ensures Detect can gracefully handle duplicate keys without scan failures.Details of the Fix
A new utility class
JsonSanitizer
has been introduced.sanitize(String json)
method uses Gson'sJsonParser.parseString(json).getAsJsonObject()
to remove duplicate keys and returns a sanitized JSON string.JsonObject
, which uses aLinkedTreeMap
to silently overwrite duplicate keys, keeping the last key-value pair.The
sanitize()
method is called in the following locations:PackageJsonReader
class: Before passing JSON content to thegson.fromJson()
method during deserialization.CombinedPackageJsonExtractor
class: To handle JSON data processing that also involves thegson.fromJson()
method.By sanitizing the JSON before parsing, Detect ensures that duplicate keys are removed while retaining valid JSON syntax. Invalid JSON files will still result in a
JsonSyntaxException
.