aboutcode-org / aboutcode-org/workshop

Tool name: Aliens4Friends (Oniro Compliance Toolchain)

オープン
#63 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る
foss-tool
主要言語
言語のデータがありません
スター
4
フォーク
0
PR マージ指標
30日以内にマージされた PR はありません

説明

### homepage_url

https://projects.eclipse.org/projects/oniro.oniro-compliancetoolchain

### contact_email

pianon@array.eu

### code_view_url

https://gitlab.eclipse.org/eclipse/oniro-compliancetoolchain/toolchain

### spdx_license_expression

Apache-2.0

### description

A comprehensive IP compliance toolchain for embedded operating system platforms, based on existing OSS tools (such as ScanCode and Fossology). It currently supports Yocto-based platforms; OpenHarmony and Android support is currently being added.

Key design features:

- reuse of existing license and copyright metadata from reliable sources (Debian distribution)
- efficient management of incremental human audit work, in parallel with the development process, allowing early detection of issues
- dedicated dashboard to monitor the audit work progress and analyze the results
- management of SCA for complex build matrices (multiple targets and variants)

### primary_languages

Python

### short_term_roadmap

- 2024 Q1:
- support for the [OpenHarmony](https://docs.openharmony.cn) build system
- export of curated findings from Fossology to OpenHarmony's internal compliance tool ([OAT](https://gitee.com/openharmony-sig/tools_oat/))
- 2024 Q2:
- support for AOSP build system

### long_term_roadmap

- generalization / abstraction of the data model, to better cover different build systems
- integration with [ORT](https://github.com/oss-review-toolkit/ort) and its data model
- refactoring of support for Yocto-based projects

### proprietary_data

- [ ] Yes, the tool depends on proprietary data sources

### commercial_features

- [ ] Yes, the tool has a commercial version with different/additional features

### capabilities

- [ ] Identifiers - Use Package-URL (PURL) identifiers
- [x] Identifiers - Use SPDX license expressions
- [x] Scanning - Analyze package manifests and lockfiles
- [x] Scanning - Analyze package files
- [x] Scanning - Scan for copyright
- [x] Scanning - Scan for license
- [x] Scanning - Analyze source code
- [ ] Scanning - Analyze containers
- [x] Scanning - Analyze installed system packages (linux distros)
- [x] Scanning - Analyze installed application packages
- [x] Scanning - Other analysis
- [x] Packages - Inventory packages
- [x] Packages - Inventory packages dependencies
- [ ] Packages - Resolve dependencies
- [ ] Packages - Navigate or display dependency graph
- [ ] Compliance - Generate CycloneDX SBOMs
- [x] Compliance - Generate SPDX SBOMs
- [ ] Compliance - Validate CycloneDX SBOM
- [ ] Compliance - Validate SPDX SBOMs
- [ ] Compliance - Generate CycloneDX VEX
- [ ] Compliance - Generate CSAF VEX
- [ ] Compliance - Generate OpenVex
- [ ] Compliance - Generate other compliance documents
- [ ] Policies - Define and check license policies
- [ ] Policies - Define and check security policies
- [ ] Policies - Define and check other policies
- [ ] Data - Database of Package metadata
- [ ] Data - Database of Package dependency relationships
- [ ] Data - Database of License obligations
- [ ] Data - Database of Licenses
- [ ] Data - Database of Vulnerabilities
- [ ] License - Help triage license issues
- [x] License - Generate license credit and attribution notices
- [ ] License - Generate source code redistribution lists
- [ ] Vulnerabilities - Detect vulnerable code in packages
- [ ] Vulnerabilities - Find known vulnerabilities for package
- [ ] Vulnerabilities - Determine reachable vulnerabilities
- [ ] Vulnerabilities - Help triage vulnerabilities
- [ ] Binaries - Analyze binaries
- [ ] Binaries - Analyze ELF binaries
- [ ] Binaries - Analyze Windows binaries
- [ ] Binaries - Analyze firmware binaries
- [ ] Binaries - Analyze Other binaries
- [x] Matching - Match source code
- [ ] Matching - Match binary code
- [ ] Tracing - Trace code execution
- [ ] Tracing - Trace build
- [ ] Code Security - Analyze code statically (SAST/linting)
- [ ] Code Security - Analyze code dynamically (DAST)
- [x] Download - Source package
- [x] Download - Source repositories
- [x] Download - Binary package
- [x] Deployment - Deployable as containers (Docker/OCI/k8s/etc)
- [x] Deployment - Deployable in CI/CD pipelines
- [ ] Deployment - Deployable as a library
- [x] Run - Run as a command line tool
- [ ] Run - Run as a web application
- [ ] Run - Run as an API service

### other_capabilities

_No response_

コントリビューションガイド

このリポジトリのコントリビューションガイドは索引されていません

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。