aboutcode-org / aboutcode-org/scancode-toolkit

New tool - redistribution check suggestion

Offen
#724 7 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
enhancement
Vorherrschende Sprache
Python
Sterne
2.6k
Forks
791
Ø Merge
1 T. 12 Std.
Gemergte PRs (30 T.)
5

Beschreibung

Given that an audited codebase is different from what is redistributed, part of my job is to scan the redistribution. I run it through extractcode/scancode (only-findings) and produce a json-pp file which I manually go through. These are usually over 100MB. For example, I look for “GPL 3”, “Commercial”, “Restricted”, “Proprietary”, “Patent” and other company important licenses. I also look for jars without source jars. This is rudimentary but catches a surprising number of errors. It’s also time consuming.

It would be more efficient to be able to remove items from the output that cause uninteresting hits. For example,
Binutils
Gdb
.txt, COPYING, Whence, html, … files
LC_MESSAGES/
Testsuite/
Fonts
Etc.
Files that have multiple licenses where one of them is gplv2 or a very permissive license.

Perhaps I've included too many details but I hope I've conveyed the need for some sort of tool help.

Beitragsleitfaden

Beitragsleitfaden öffnen

Bewertung

Dieses Issue wurde noch nicht bewertet.

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.