aboutcode-org / aboutcode-org/workshop

Tool name: NTIA Conformance Checker

Ouverte
#22 0 commentaires 0 réactions 0 personnes assignées Voir sur GitHub
foss-tool
Langage dominant
Aucune donnée de langage
Étoiles
4
Forks
0
Métriques de merge des PR
Aucune PR mergée en 30 j

Description

### homepage_url

https://github.com/spdx/ntia-conformance-checker

### contact_email

john.speed.meyers@alumni.tufts.edu

### code_view_url

https://github.com/spdx/ntia-conformance-checker

### spdx_license_expression

Apache-2.0

### description

NTIA Conformance Checker determines whether an SPDX software bill of materials document contains informational items as required by a certain specification. Currently supports:

- 2021 National Telecommunications and Information Administration (NTIA) ["minimum elements."](https://www.ntia.gov/report/2021/minimum-elements-software-bill-materials-sbom)
- 2024 Framing Software Component Transparency (FSCT3) ["Baseline Attributes"](https://www.cisa.gov/resources-tools/resources/framing-software-component-transparency-2024) (experimental)

### primary_languages

Python

### short_term_roadmap

- Add support for SPDX 3
- Add support for different levels of 2024 Framing Software Component Transparency Baseline Attributes

### long_term_roadmap

https://docs.google.com/document/d/1pueRxlxoM9n1eG9g6AihjLvybEBTd77m22mRYBQltpg/edit?usp=sharing

### proprietary_data

- [ ] Yes, the tool depends on proprietary data sources

### commercial_features

- [ ] Yes, the tool has a commercial version with different/additional features

### capabilities

- [ ] Identifiers - Use Package-URL (PURL) identifiers
- [x] Identifiers - Use SPDX license expressions
- [ ] Scanning - Analyze package manifests and lockfiles
- [ ] Scanning - Analyze package files
- [ ] Scanning - Scan for copyright
- [ ] Scanning - Scan for license
- [ ] Scanning - Analyze source code
- [ ] Scanning - Analyze containers
- [ ] Scanning - Analyze installed system packages (linux distros)
- [ ] Scanning - Analyze installed application packages
- [ ] Scanning - Other analysis
- [ ] Packages - Inventory packages
- [ ] Packages - Inventory packages dependencies
- [ ] Packages - Resolve dependencies
- [ ] Packages - Navigate or display dependency graph
- [ ] Compliance - Generate CycloneDX SBOMs
- [ ] Compliance - Generate SPDX SBOMs
- [ ] Compliance - Validate CycloneDX SBOM
- [x] Compliance - Validate SPDX SBOMs
- [ ] Compliance - Generate CycloneDX VEX
- [ ] Compliance - Generate CSAF VEX
- [ ] Compliance - Generate OpenVex
- [ ] Compliance - Generate other compliance documents
- [ ] Policies - Define and check license policies
- [ ] Policies - Define and check security policies
- [ ] Policies - Define and check other policies
- [ ] Data - Database of Package metadata
- [ ] Data - Database of Package dependency relationships
- [ ] Data - Database of License obligations
- [ ] Data - Database of Licenses
- [ ] Data - Database of Vulnerabilities
- [ ] License - Help triage license issues
- [ ] License - Generate license credit and attribution notices
- [ ] License - Generate source code redistribution lists
- [ ] Vulnerabilities - Detect vulnerable code in packages
- [ ] Vulnerabilities - Find known vulnerabilities for package
- [ ] Vulnerabilities - Determine reachable vulnerabilities
- [ ] Vulnerabilities - Help triage vulnerabilities
- [ ] Binaries - Analyze binaries
- [ ] Binaries - Analyze ELF binaries
- [ ] Binaries - Analyze Windows binaries
- [ ] Binaries - Analyze firmware binaries
- [ ] Binaries - Analyze Other binaries
- [ ] Matching - Match source code
- [ ] Matching - Match binary code
- [ ] Tracing - Trace code execution
- [ ] Tracing - Trace build
- [ ] Code Security - Analyze code statically (SAST/linting)
- [ ] Code Security - Analyze code dynamically (DAST)
- [x] Download - Source package
- [x] Download - Source repositories
- [x] Download - Binary package
- [ ] Deployment - Deployable as containers (Docker/OCI/k8s/etc)
- [ ] Deployment - Deployable in CI/CD pipelines
- [ ] Deployment - Deployable as a library
- [x] Run - Run as a command line tool
- [x] Run - Run as a web application
- [ ] Run - Run as an API service

### other_capabilities

_No response_

Guide de contribution

Aucun guide de contribution indexé pour ce dépôt

Évaluation

Cette issue n'a pas encore été évaluée.

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.