anchore / anchore/syft

Add licenses for Go packages on windows

Open
#1,933 4 comments 0 reactions 0 assignees View on GitHub
bug windows
Dominant language
Go
Stars
9.6k
Forks
962
Avg merge
23h 27m
Merged PRs (30d)
48

Description

**What would you like to be added**:
The filled in "licenses" field in the SBOM report for Go packages.

**Why is this needed**:
Now it looks like a disadvantage compared to other dependencies.
Tracking license purity is an important part of software development.

**Additional context**:
License information is easy to get at https://pkg.go.dev
For example:
![image](https://github.com/anchore/syft/assets/19753153/5741f269-6476-4009-90cb-a251e71b2e09)

Contributor guide

Open the contributing guide

Research direction

Start by locating the SBOM generation path for Go packages on Windows and compare its current output with the license information available on pkg.go.dev. Done means the SBOM report's "licenses" field is populated for Go packages on Windows, with coverage checked against representative dependencies.

Written by the indexing model from the issue text.

Assessment

Tech stack
go
Domain
security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
42/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.