Automate dependency license scanning to check for potentially risky third-party dependencies
Open
- Dominant language
- Go
- Stars
- 8
- Forks
- 13
- PR merge metrics
- No merged PRs in 30d
Description
This issue has no description.
Contributor guide
Research direction
The issue body names no files, tests, entry points, scanner, or risk criteria. Start by inspecting the repository's dependency manifests and existing automation, then establish how a dependency license scan should run and what output counts as a potentially risky dependency.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- go
- Domain
- security, tooling
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100