DependencyTrack / DependencyTrack/dependency-track

Support licenses without spdx ids; add scancode LicenseDB as an additional datasource

Open
#1,211 5 comments 2 reactions 0 assignees View on GitHub
enhancement gnomes help wanted p2
Dominant language
Java
Stars
4.2k
Forks
811
Avg merge
8h 39m
Merged PRs (30d)
237

Description

Hi there,

First of all, dependency-track is a great piece of software - thanks for your work.

### Current Behavior:
Actually only licenses with spdx ids are supported.

### Proposed Behavior:
Full support licenses without spdx ids (categorization, alerting etc.) - by adding them manually (with api/ui) and/or by using https://scancode-licensedb.aboutcode.org.

OSS Review Toolkit, for example, uses scancode license ids as an additional identifier: https://github.com/oss-review-toolkit/ort/tree/master/spdx-utils/src/main/resources/licenserefs

Best Regards,
Marco

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.