Some python repo do not list the licence in the METADATA file but there are still present in the package distribution info under the licenses directory. It could be useful to add that info the the report
Open
enhancement
- Dominant language
- Go
- Stars
- 9.6k
- Forks
- 954
- Avg merge
- 1d 5h
- Merged PRs (30d)
- 42
Description
Obviously the correct solution is for the packages to fix their METADATA but as there are quite a lot that have this issue, including famous ones like https://github.com/fastapi/fastapi/discussions/14194 it might be a nice workaround. If this is something you think is useful, I might find tiime to get a shot at it (no promise though).
Contributor guide
Research direction
The issue names no files or tests. Start by tracing how Syft reads Python package METADATA and the licenses directory, then identify the report output path. Done means packages with missing METADATA license fields have available license information included in the report, with regression coverage.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- go, python
- Domain
- security, tooling
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 38/100