aboutcode-org / aboutcode-org/workshop
Tool name: OSSelot
- Vorherrschende Sprache
- Keine Sprachdaten
- Sterne
- 4
- Forks
- 0
- PR-Merge-Kennzahlen
- Keine gemergten PRs in 30 T.
Beschreibung
### homepage_url
https://www.osselot.org/
### contact_email
oliver.fendt@fossea.de
### code_view_url
https://github.com/Open-Source-Compliance/package-analysis
### spdx_license_expression
CC0-1.0
### description
The Open Source Curation Database
Sharing and Reusing Open Spurce Compliance Materials
A major advantage of FOSS is the possibility to reuse existing components. Thus, it seems obvious to adopt the same strategy for FOSS compliance materials in those areas where the required efforts are similar for all users of the software. With standard formats, such as SPDX, it is possible to share the results of data curation with the community, and thereby reduce the individual effort. The project is doing precisely this:
* Creating meta information, SPDX reports and a disclosure document for frequently used FOSS components.
* Sharing curated compliance materials licensed under CC0-1.0 in a publicly available database.
* Providing a REST API, tools and typical use cases to facilitate using the data.
* All internal and external contributions must meet the same high quality standard.
* Any inconsistencies or problems that are found while curating data are communicated to the respective projects.
* To increase the project’s practical relevance, a discussion is encouraged on how the data can be used with existing tools and what adaptions are required to do so.
* Contributions, review of existing data and bug reports are encouraged.
### primary_languages
text
### short_term_roadmap
* curate the dependencies of the already curated packages
* provide curations of commonly needed packages
* provide the curation of more Linux kernels
### long_term_roadmap
Curations, curations, curations for all ecosystems and domains
### proprietary_data
- [ ] Yes, the tool depends on proprietary data sources
### commercial_features
- [ ] Yes, the tool has a commercial version with different/additional features
### capabilities
- [x] Identifiers - Use Package-URL (PURL) identifiers
- [x] Identifiers - Use SPDX license expressions
- [ ] Scanning - Analyze package manifests and lockfiles
- [ ] Scanning - Analyze package files
- [x] Scanning - Scan for copyright
- [x] Scanning - Scan for license
- [x] Scanning - Analyze source code
- [ ] Scanning - Analyze containers
- [ ] Scanning - Analyze installed system packages (linux distros)
- [ ] Scanning - Analyze installed application packages
- [ ] Scanning - Other analysis
- [ ] Packages - Inventory packages
- [ ] Packages - Inventory packages dependencies
- [ ] Packages - Resolve dependencies
- [ ] Packages - Navigate or display dependency graph
- [ ] Compliance - Generate CycloneDX SBOMs
- [ ] Compliance - Generate SPDX SBOMs
- [ ] Compliance - Validate CycloneDX SBOM
- [ ] Compliance - Validate SPDX SBOMs
- [ ] Compliance - Generate CycloneDX VEX
- [ ] Compliance - Generate CSAF VEX
- [ ] Compliance - Generate OpenVex
- [x] Compliance - Generate other compliance documents
- [ ] Policies - Define and check license policies
- [ ] Policies - Define and check security policies
- [ ] Policies - Define and check other policies
- [ ] Data - Database of Package metadata
- [ ] Data - Database of Package dependency relationships
- [ ] Data - Database of License obligations
- [ ] Data - Database of Licenses
- [ ] Data - Database of Vulnerabilities
- [ ] License - Help triage license issues
- [x] License - Generate license credit and attribution notices
- [ ] License - Generate source code redistribution lists
- [ ] Vulnerabilities - Detect vulnerable code in packages
- [ ] Vulnerabilities - Find known vulnerabilities for package
- [ ] Vulnerabilities - Determine reachable vulnerabilities
- [ ] Vulnerabilities - Help triage vulnerabilities
- [ ] Binaries - Analyze binaries
- [ ] Binaries - Analyze ELF binaries
- [ ] Binaries - Analyze Windows binaries
- [ ] Binaries - Analyze firmware binaries
- [ ] Binaries - Analyze Other binaries
- [ ] Matching - Match source code
- [ ] Matching - Match binary code
- [ ] Tracing - Trace code execution
- [ ] Tracing - Trace build
- [ ] Code Security - Analyze code statically (SAST/linting)
- [ ] Code Security - Analyze code dynamically (DAST)
- [ ] Download - Source package
- [ ] Download - Source repositories
- [ ] Download - Binary package
- [ ] Deployment - Deployable as containers (Docker/OCI/k8s/etc)
- [ ] Deployment - Deployable in CI/CD pipelines
- [ ] Deployment - Deployable as a library
- [ ] Run - Run as a command line tool
- [ ] Run - Run as a web application
- [x] Run - Run as an API service
### other_capabilities
_No response_
Beitragsleitfaden
Für dieses Repository ist kein Beitragsleitfaden indexiert
Bewertung
Dieses Issue wurde noch nicht bewertet.