anchore / anchore/syft

Describe intellectual property rights

Open
#3,918 1 comment 2 reactions 0 assignees View on GitHub
enhancement help-wanted license
Dominant language
Go
Stars
9.6k
Forks
954
Avg merge
23h 27m
Merged PRs (30d)
48

Description

Today there are license claims that are attached directly to packages, however, there is a wider lens to consider when interpreting what a license applies to and surrounding statements of claim. Such considerations could be:
- copyright claims (as proposed in #3156)
- trademarks

These should be described alongside licenses.

[Example from debian](https://github.com/anchore/syft/pull/3156#issuecomment-2891136675)

Contributor guide

Open the contributing guide

Research direction

Start by reviewing how Syft currently represents license claims, then read the copyright discussion in #3156 and the linked Debian example. The work is done when copyright and trademark claims have a defined representation alongside licenses, with the relevant output and behavior documented.

Written by the indexing model from the issue text.

Assessment

Tech stack
go
Domain
cli
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.