aboutcode-org / aboutcode-org/scancode.io

maven-heaven: Implement Maven Heaven solution

オープン
#1,762 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る
主要言語
Python
スター
215
フォーク
203
平均マージ
4日 8時間
マージ済み PR(30日)
6

説明

The Apache Maven Central repository is the center of the Java development world, where all open source dependencies are fetched from. Apache Maven Central hosts over 3 million Java packages. Java JAR origin metadata and licensing documentation is declared by their authors as part of a POM metadata, but can be misleading and/or incorrect. Accurate Java origin and license metadata are essential to safely automate the consumption of Java packages in the software supply chain.

The solution to this is to lift the trust in Maven packages and work to fix this problem in multiple steps: Scan, review, curate and fix the metadata of the most popular Java packages. Release this data as open data, and work with the Maven community to provide the data as part of the Maven services and repo, cross-check and report code borrowing and reuse between Java projects.

コントリビューションガイド

コントリビューションガイドを開く

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。