anchore / anchore/sbom-action

SPDX license list

Open
#4 0 comments 0 reactions 0 assignees View on GitHub
enhancement
Dominant language
TypeScript
Stars
258
Forks
45
Avg merge
1h 14m
Merged PRs (30d)
18

Description

A frequently asked question is: are there open source license violations in my project? This information is captured in Syft and could be provided as part of the [SPDX output](https://spdx.org/licenses/) and possibly summarized and/or rendered separately from the SBOM output. This may also be better suited in a different action.

Contributor guide

Open the contributing guide

Research direction

Start by reviewing how Syft information is currently exposed in the SPDX output. Clarify whether license-violation information belongs in that output or a separate summary or action; done means the chosen scope and resulting license information are defined and covered by appropriate tests.

Written by the indexing model from the issue text.

Assessment

Tech stack
github-actions, typescript
Domain
devops, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.