aboutcode-org / aboutcode-org/workshop
Tool name: ORT / ORT Server / Double Open Server / OCaaS
- Ngôn ngữ chính
- Không có dữ liệu ngôn ngữ
- Star
- 4
- Fork
- 0
- Chỉ số merge pull request
- Không có pull request nào được merge trong 30 ngày
Mô tả
### homepage_url
https://oss-review-toolkit.org/ort/
### contact_email
ort@oss-review-toolkit.org
### code_view_url
https://github.com/oss-review-toolkit/ort
### spdx_license_expression
Apache-2.0
### description
OSS Review Toolkit (ORT) is a suite of CLI tools to automate software compliance checks. Is works as an abstraction layer and orchestrator to combine results of existing compliance tools in once place, but also has build-in unique Software Composition Analysis (SCA) features. The ORT Server (and its DOS / OCaaS "distributions") take ORT to the next level in terms of usability and scalabilty, as SaaS solutions.
### primary_languages
Kotlin, TypeScript
### short_term_roadmap
As ORT (the core) as matured over the last 8 years, the focus is now on the server to make ORT more accessible to a wider range of target audiences, like legal people, product owners, and curation teams in addition to developers. One important part is to improve the UX, e.g. by integration ORT reports into the ORT Server UI, and to give better guidance through end-to-end compliance processes.
### long_term_roadmap
Initial roadmaps for 2025 can be found [here](https://github.com/orgs/oss-review-toolkit/projects/3) and [here](https://github.com/orgs/eclipse-apoapsis/projects/1), respectively.
### proprietary_data
- [ ] Yes, the tool depends on proprietary data sources
### commercial_features
- [ ] Yes, the tool has a commercial version with different/additional features
### capabilities
- [x] Identifiers - Use Package-URL (PURL) identifiers
- [x] Identifiers - Use SPDX license expressions
- [x] Scanning - Analyze package manifests and lockfiles
- [x] Scanning - Analyze package files
- [x] Scanning - Scan for copyright
- [x] Scanning - Scan for license
- [x] Scanning - Analyze source code
- [ ] Scanning - Analyze containers
- [ ] Scanning - Analyze installed system packages (linux distros)
- [ ] Scanning - Analyze installed application packages
- [ ] Scanning - Other analysis
- [x] Packages - Inventory packages
- [x] Packages - Inventory packages dependencies
- [x] Packages - Resolve dependencies
- [x] Packages - Navigate or display dependency graph
- [x] Compliance - Generate CycloneDX SBOMs
- [x] Compliance - Generate SPDX SBOMs
- [ ] Compliance - Validate CycloneDX SBOM
- [ ] Compliance - Validate SPDX SBOMs
- [ ] Compliance - Generate CycloneDX VEX
- [ ] Compliance - Generate CSAF VEX
- [ ] Compliance - Generate OpenVex
- [x] Compliance - Generate other compliance documents
- [x] Policies - Define and check license policies
- [x] Policies - Define and check security policies
- [x] Policies - Define and check other policies
- [x] Data - Database of Package metadata
- [x] Data - Database of Package dependency relationships
- [x] Data - Database of License obligations
- [x] Data - Database of Licenses
- [x] Data - Database of Vulnerabilities
- [x] License - Help triage license issues
- [x] License - Generate license credit and attribution notices
- [x] License - Generate source code redistribution lists
- [x] Vulnerabilities - Detect vulnerable code in packages
- [x] Vulnerabilities - Find known vulnerabilities for package
- [ ] Vulnerabilities - Determine reachable vulnerabilities
- [ ] Vulnerabilities - Help triage vulnerabilities
- [ ] Binaries - Analyze binaries
- [ ] Binaries - Analyze ELF binaries
- [ ] Binaries - Analyze Windows binaries
- [ ] Binaries - Analyze firmware binaries
- [ ] Binaries - Analyze Other binaries
- [x] Matching - Match source code
- [ ] Matching - Match binary code
- [ ] Tracing - Trace code execution
- [ ] Tracing - Trace build
- [ ] Code Security - Analyze code statically (SAST/linting)
- [ ] Code Security - Analyze code dynamically (DAST)
- [x] Download - Source package
- [x] Download - Source repositories
- [ ] Download - Binary package
- [x] Deployment - Deployable as containers (Docker/OCI/k8s/etc)
- [x] Deployment - Deployable in CI/CD pipelines
- [x] Deployment - Deployable as a library
- [x] Run - Run as a command line tool
- [x] Run - Run as a web application
- [x] Run - Run as an API service
### other_capabilities
_No response_
Hướng dẫn đóng góp
Chưa lập chỉ mục được hướng dẫn đóng góp cho kho mã nguồn này
Đánh giá
Issue này chưa được đánh giá.