aboutcode-org / aboutcode-org/workshop

Tool name: ScanCode.io

Offen
#28 0 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
foss-tool
Vorherrschende Sprache
Keine Sprachdaten
Sterne
4
Forks
0
PR-Merge-Kennzahlen
Keine gemergten PRs in 30 T.

Beschreibung

### homepage_url

https://github.com/aboutcode-org/scancode.io

### contact_email

hello@aboutcode.org

### code_view_url

https://github.com/aboutcode-org/scancode.io

### spdx_license_expression

Apache-2.0

### description

ScanCode.io is a server to script and automate software composition analysis pipelines with ScanPipe pipelines.

### primary_languages

Python

### short_term_roadmap

Back2Source https://github.com/aboutcode-org/scancode.io/issues/1437

### long_term_roadmap

Performances optimizations.

### proprietary_data

- [ ] Yes, the tool depends on proprietary data sources

### commercial_features

- [ ] Yes, the tool has a commercial version with different/additional features

### capabilities

- [x] Identifiers - Use Package-URL (PURL) identifiers
- [x] Identifiers - Use SPDX license expressions
- [x] Scanning - Analyze package manifests and lockfiles
- [x] Scanning - Analyze package files
- [x] Scanning - Scan for copyright
- [x] Scanning - Scan for license
- [x] Scanning - Analyze source code
- [x] Scanning - Analyze containers
- [x] Scanning - Analyze installed system packages (linux distros)
- [x] Scanning - Analyze installed application packages
- [x] Scanning - Other analysis
- [x] Packages - Inventory packages
- [x] Packages - Inventory packages dependencies
- [x] Packages - Resolve dependencies
- [x] Packages - Navigate or display dependency graph
- [x] Compliance - Generate CycloneDX SBOMs
- [x] Compliance - Generate SPDX SBOMs
- [x] Compliance - Validate CycloneDX SBOM
- [x] Compliance - Validate SPDX SBOMs
- [x] Compliance - Generate CycloneDX VEX
- [ ] Compliance - Generate CSAF VEX
- [ ] Compliance - Generate OpenVex
- [x] Compliance - Generate other compliance documents
- [x] Policies - Define and check license policies
- [x] Policies - Define and check security policies
- [x] Policies - Define and check other policies
- [x] Data - Database of Package metadata
- [x] Data - Database of Package dependency relationships
- [x] Data - Database of License obligations
- [x] Data - Database of Licenses
- [x] Data - Database of Vulnerabilities
- [x] License - Help triage license issues
- [x] License - Generate license credit and attribution notices
- [ ] License - Generate source code redistribution lists
- [x] Vulnerabilities - Detect vulnerable code in packages
- [x] Vulnerabilities - Find known vulnerabilities for package
- [x] Vulnerabilities - Determine reachable vulnerabilities
- [x] Vulnerabilities - Help triage vulnerabilities
- [x] Binaries - Analyze binaries
- [x] Binaries - Analyze ELF binaries
- [x] Binaries - Analyze Windows binaries
- [x] Binaries - Analyze firmware binaries
- [x] Binaries - Analyze Other binaries
- [x] Matching - Match source code
- [x] Matching - Match binary code
- [ ] Tracing - Trace code execution
- [ ] Tracing - Trace build
- [ ] Code Security - Analyze code statically (SAST/linting)
- [ ] Code Security - Analyze code dynamically (DAST)
- [x] Download - Source package
- [x] Download - Source repositories
- [x] Download - Binary package
- [x] Deployment - Deployable as containers (Docker/OCI/k8s/etc)
- [x] Deployment - Deployable in CI/CD pipelines
- [x] Deployment - Deployable as a library
- [x] Run - Run as a command line tool
- [x] Run - Run as a web application
- [x] Run - Run as an API service

### other_capabilities

_No response_

Beitragsleitfaden

Für dieses Repository ist kein Beitragsleitfaden indexiert

Bewertung

Dieses Issue wurde noch nicht bewertet.

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.