DependencyTrack / DependencyTrack/dependency-track

Add license attestation report

Open
#651 9 comments 3 reactions 0 assignees View on GitHub
enhancement needs milestone p2
Dominant language
Java
Stars
4.2k
Forks
811
Avg merge
8h 39m
Merged PRs (30d)
237

Description

A license attestation report is a document which contains the information of OSS components used in a specific product. Usually, it identifies following information of each OSS: name, version, copyright notice, licensed under which license and the full license text.

From DT's view, I think that a specific product is represented by the project and its version combination.

This document will then be distributed with the product to fulfill the requirement of software license compliance.

It will be great to be able to download this document from DT directly.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.