# Phantom components found during IQ scans?

## post by djb on Jan 21, 2025

I have experienced numerous phantom components throughout my time scanning projects with IQ. Components that do not appear to exist within the project’s code, its dependencies, or sub-dependencies. Why is this, and what is the best solution to dealing with them? Should we waive, which feels like sweeping an error under the rug, or handle it alternatively?

## post by djb on Feb 13, 2025

For future ref., I spoke to our CSE who enlightened me as to how a-naming works. If a component can be matched without resorting to a-name, great, but if not, then guess and set the component format to a-name (e.g. not ‘npm’, or ‘pypi’).

These phantom components, when misidentified, can be waived to mitigate their false detection.
