aboutcode-org / aboutcode-org/workshop

Tool name: scancode-toolkit

オープン
#67 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る
foss-tool
主要言語
言語のデータがありません
スター
4
フォーク
0
PR マージ指標
30日以内にマージされた PR はありません

説明

### homepage_url

https://github.com/aboutcode-org/scancode-toolkit

### contact_email

pombredanne@aboutcode.org, asmahapatra@aboutcode.org

### code_view_url

https://github.com/aboutcode-org/scancode-toolkit

### spdx_license_expression

apache-2.0 AND cc-by-4.0 AND other-permissive AND other-copyleft

### description

scancode-toolkit is a CLI tool and library to detect licenses, copyrights, packages and dependencies by scanning code, to discover and inventory open source and third-party packages used in your code.

### primary_languages

Python

### short_term_roadmap

1. Finish up the work done to tag scancode license rules with required phrases massively and automatically, to reduce false positives. Also improve the license detection algorithm using these required phrases. https://github.com/aboutcode-org/scancode-toolkit/pull/3924
2. Publish smaller (and seperate) wheels to enable much faster releases and bugfixes https://github.com/aboutcode-org/scancode-toolkit/pull/3761
3. Support python 3.13 https://github.com/aboutcode-org/scancode-toolkit/issues/3921
4. fast-scan: identify and apply performance improvements https://github.com/aboutcode-org/scancode-toolkit/issues/4071

### long_term_roadmap

See https://github.com/aboutcode-org/scancode-toolkit/blob/develop/ROADMAP-ABOUTCODE.rst#sctk-scancode-toolkit for a more detailed roadmap of scancode-toolkit.

### proprietary_data

- [ ] Yes, the tool depends on proprietary data sources

### commercial_features

- [ ] Yes, the tool has a commercial version with different/additional features

### capabilities

- [x] Identifiers - Use Package-URL (PURL) identifiers
- [x] Identifiers - Use SPDX license expressions
- [x] Scanning - Analyze package manifests and lockfiles
- [x] Scanning - Analyze package files
- [x] Scanning - Scan for copyright
- [x] Scanning - Scan for license
- [x] Scanning - Analyze source code
- [ ] Scanning - Analyze containers
- [x] Scanning - Analyze installed system packages (linux distros)
- [x] Scanning - Analyze installed application packages
- [x] Scanning - Other analysis
- [x] Packages - Inventory packages
- [x] Packages - Inventory packages dependencies
- [ ] Packages - Resolve dependencies
- [ ] Packages - Navigate or display dependency graph
- [x] Compliance - Generate CycloneDX SBOMs
- [x] Compliance - Generate SPDX SBOMs
- [ ] Compliance - Validate CycloneDX SBOM
- [ ] Compliance - Validate SPDX SBOMs
- [ ] Compliance - Generate CycloneDX VEX
- [ ] Compliance - Generate CSAF VEX
- [ ] Compliance - Generate OpenVex
- [x] Compliance - Generate other compliance documents
- [x] Policies - Define and check license policies
- [ ] Policies - Define and check security policies
- [ ] Policies - Define and check other policies
- [ ] Data - Database of Package metadata
- [ ] Data - Database of Package dependency relationships
- [ ] Data - Database of License obligations
- [x] Data - Database of Licenses
- [ ] Data - Database of Vulnerabilities
- [x] License - Help triage license issues
- [x] License - Generate license credit and attribution notices
- [x] License - Generate source code redistribution lists
- [ ] Vulnerabilities - Detect vulnerable code in packages
- [ ] Vulnerabilities - Find known vulnerabilities for package
- [ ] Vulnerabilities - Determine reachable vulnerabilities
- [ ] Vulnerabilities - Help triage vulnerabilities
- [ ] Binaries - Analyze binaries
- [ ] Binaries - Analyze ELF binaries
- [ ] Binaries - Analyze Windows binaries
- [ ] Binaries - Analyze firmware binaries
- [ ] Binaries - Analyze Other binaries
- [ ] Matching - Match source code
- [ ] Matching - Match binary code
- [ ] Tracing - Trace code execution
- [ ] Tracing - Trace build
- [ ] Code Security - Analyze code statically (SAST/linting)
- [ ] Code Security - Analyze code dynamically (DAST)
- [ ] Download - Source package
- [ ] Download - Source repositories
- [ ] Download - Binary package
- [x] Deployment - Deployable as containers (Docker/OCI/k8s/etc)
- [x] Deployment - Deployable in CI/CD pipelines
- [x] Deployment - Deployable as a library
- [x] Run - Run as a command line tool
- [ ] Run - Run as a web application
- [ ] Run - Run as an API service

### other_capabilities

_No response_

コントリビューションガイド

このリポジトリのコントリビューションガイドは索引されていません

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。