anchore / anchore/syft

Some python repo do not list the licence in the METADATA file but there are still present in the package distribution info under the licenses directory. It could be useful to add that info the the report

Open
#4,292 3 comments 0 reactions 0 assignees View on GitHub
enhancement
Dominant language
Go
Stars
9.6k
Forks
954
Avg merge
1d 5h
Merged PRs (30d)
42

Description

Obviously the correct solution is for the packages to fix their METADATA but as there are quite a lot that have this issue, including famous ones like https://github.com/fastapi/fastapi/discussions/14194 it might be a nice workaround. If this is something you think is useful, I might find tiime to get a shot at it (no promise though).

Contributor guide

Open the contributing guide

Research direction

The issue names no files or tests. Start by tracing how Syft reads Python package METADATA and the licenses directory, then identify the report output path. Done means packages with missing METADATA license fields have available license information included in the report, with regression coverage.

Written by the indexing model from the issue text.

Assessment

Tech stack
go, python
Domain
security, tooling
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
38/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.