DependencyTrack / DependencyTrack/dependency-track
OSS License Retrieval
- Dominant language
- Java
- Stars
- 4.2k
- Forks
- 811
- Avg merge
- 9h 4m
- Merged PRs (30d)
- 229
Description
### Current Behavior
_Issue created from slack discussion: 🧵 https://owasp.slack.com/archives/C6R3R32H4/p1722448587291769_
OSS License needs to be within the uploaded BOM file.
### Proposed Behavior
Enhance DTrack to have a system/event workflow which would take a projects components and enrich them with LICENSE data based on the purl?
This would centralize license component enrichment within DTrack vs having the license lookup/enrichment "step" as part of my CI/CD BOM-generation pipeline (both for performance and consistency). Once in DTrack, we then have a suite of License Violation Policies for our needs.
### Checklist
- [X] I have read and understand the [contributing guidelines](https://github.com/DependencyTrack/dependency-track/blob/master/CONTRIBUTING.md#filing-issues)
- [X] I have checked the [existing issues](https://github.com/DependencyTrack/dependency-track/issues) for whether this enhancement was already requested
Contributor guide
Research direction
No file, test, or entry point is named. Start by reviewing the proposed system/event workflow and how components are represented by purl; the scope needs maintainer clarification before implementation. Done would require a defined license-enrichment workflow and integration with license-violation policies.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java
- Domain
- security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100