aboutcode-org / aboutcode-org/scancode.io

maven-heaven: Implement Maven Heaven solution

未关闭
#1,762 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
主要语言
Python
星标
215
派生
203
平均合并
4 天 8 小时
30 天内合并 PR
6

描述

The Apache Maven Central repository is the center of the Java development world, where all open source dependencies are fetched from. Apache Maven Central hosts over 3 million Java packages. Java JAR origin metadata and licensing documentation is declared by their authors as part of a POM metadata, but can be misleading and/or incorrect. Accurate Java origin and license metadata are essential to safely automate the consumption of Java packages in the software supply chain.

The solution to this is to lift the trust in Maven packages and work to fix this problem in multiple steps: Scan, review, curate and fix the metadata of the most popular Java packages. Release this data as open data, and work with the Maven community to provide the data as part of the Maven services and repo, cross-check and report code borrowing and reuse between Java projects.

贡献指南

打开贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。