anchore / anchore/grant

feat: License compatibility checks

Open
#135 2 comments 2 reactions 0 assignees View on GitHub
enhancement
Dominant language
Go
Stars
183
Forks
18
Avg merge
3d 7h
Merged PRs (30d)
7

Description

**What would you like to be added**:

When analysing SBOMs a check for license incompatibilities between licenses would be nice to have. Other OS-Tools like https://github.com/vinland-technology/flict are doing this, but are not using the SBOM format like grant. Therefore having checks already implemented in grant, would help to find problems within the licenses going beyond allow and deny lists.

**Why is this needed**:
To discover problems with licenses, which are not that easy to find, without proper knowledge of licenses.

**Additional context**:

I don't think it's possible to check for every license combination as for some of them the context is important. But it would really helpful to find common problems between licenses. For Reference https://wiki.geant.org/display/GSD/Reference+information+about+OSS+licences+and+tools#ReferenceinformationaboutOSSlicencesandtools-Licencecompatibility

Contributor guide

Open the contributing guide

Research direction

Start by reviewing grant's existing SBOM license analysis and allow/deny-list checks. Define which common license incompatibilities can be detected without additional context and how context-dependent cases are handled; done means analyzed SBOMs report those conflicts clearly.

Written by the indexing model from the issue text.

Assessment

Tech stack
go
Domain
security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.