aboutcode-org / aboutcode-org/workshop

Tool name: DejaCode

Abierto
#26 0 comentarios 0 reacciones 0 asignados Ver en GitHub
foss-tool
Lenguaje dominante
Sin datos de lenguaje
Estrellas
4
Forks
0
Métricas de merge de PR
Sin PR fusionados en 30 d

Descripción

### homepage_url

https://aboutcode.org/dejacode/

### contact_email

hello@aboutcode.org

### code_view_url

https://github.com/aboutcode-org/dejacode

### spdx_license_expression

AGPL-3.0-only

### description

Automate enterprise-wide continuous compliance with open source DejaCode, your system of record for SBOMs backed by open data.

- Run scans and track all the open source and third-party products and components used in your software.
- Apply usage policies at the license or component level, and integrate into ScanCode to ensure compliance.
- Capture software inventories (SBOMs), generate compliance artifacts, and keep historical data.
- Ensure FOSS compliance with enterprise-grade features and integrations for DevOps and software systems.

### primary_languages

Python, Javascript

### short_term_roadmap

Continuous refinement of SBOM generation and ingestion capabilities.

### long_term_roadmap

Continuous improvements to usability.

### proprietary_data

- [ ] Yes, the tool depends on proprietary data sources

### commercial_features

- [x] Yes, the tool has a commercial version with different/additional features

### capabilities

- [x] Identifiers - Use Package-URL (PURL) identifiers
- [x] Identifiers - Use SPDX license expressions
- [x] Scanning - Analyze package manifests and lockfiles
- [x] Scanning - Analyze package files
- [x] Scanning - Scan for copyright
- [x] Scanning - Scan for license
- [x] Scanning - Analyze source code
- [x] Scanning - Analyze containers
- [x] Scanning - Analyze installed system packages (linux distros)
- [x] Scanning - Analyze installed application packages
- [x] Scanning - Other analysis
- [x] Packages - Inventory packages
- [x] Packages - Inventory packages dependencies
- [ ] Packages - Resolve dependencies
- [ ] Packages - Navigate or display dependency graph
- [x] Compliance - Generate CycloneDX SBOMs
- [x] Compliance - Generate SPDX SBOMs
- [ ] Compliance - Validate CycloneDX SBOM
- [ ] Compliance - Validate SPDX SBOMs
- [x] Compliance - Generate CycloneDX VEX
- [x] Compliance - Generate CSAF VEX
- [ ] Compliance - Generate OpenVex
- [ ] Compliance - Generate other compliance documents
- [x] Policies - Define and check license policies
- [x] Policies - Define and check security policies
- [ ] Policies - Define and check other policies
- [x] Data - Database of Package metadata
- [x] Data - Database of Package dependency relationships
- [x] Data - Database of License obligations
- [x] Data - Database of Licenses
- [x] Data - Database of Vulnerabilities
- [x] License - Help triage license issues
- [x] License - Generate license credit and attribution notices
- [x] License - Generate source code redistribution lists
- [x] Vulnerabilities - Detect vulnerable code in packages
- [x] Vulnerabilities - Find known vulnerabilities for package
- [x] Vulnerabilities - Determine reachable vulnerabilities
- [x] Vulnerabilities - Help triage vulnerabilities
- [ ] Binaries - Analyze binaries
- [ ] Binaries - Analyze ELF binaries
- [ ] Binaries - Analyze Windows binaries
- [ ] Binaries - Analyze firmware binaries
- [ ] Binaries - Analyze Other binaries
- [ ] Matching - Match source code
- [ ] Matching - Match binary code
- [ ] Tracing - Trace code execution
- [ ] Tracing - Trace build
- [ ] Code Security - Analyze code statically (SAST/linting)
- [ ] Code Security - Analyze code dynamically (DAST)
- [ ] Download - Source package
- [ ] Download - Source repositories
- [ ] Download - Binary package
- [ ] Deployment - Deployable as containers (Docker/OCI/k8s/etc)
- [ ] Deployment - Deployable in CI/CD pipelines
- [ ] Deployment - Deployable as a library
- [ ] Run - Run as a command line tool
- [x] Run - Run as a web application
- [ ] Run - Run as an API service

### other_capabilities

Integrated with the AboutCode stack (ScanCode Toolkit, ScanCode.io, VulnerableCode, PurlDB) to provide a wide range of services.

Guía de contribución

No hay ninguna guía de contribución indexada para este repositorio

Evaluación

Este issue todavía no se ha evaluado.

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.