aws-samples / aws-samples/aws-cdk-cicd-boot-sample

[FEATURE] Flag OpenSource licenses neither in the allow- nor in the deny-lst.

Open
#20 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
TypeScript
Stars
33
Forks
5
PR merge metrics
No merged PRs in 30d

Description

### Describe the feature

The pipeline support addressing OpenSource licenses that are considered "allows" and "denied". Denied licenses result in a pipeline failure and need addressing.

Licenses that are in neither list require usually special approval's per the company's rules around OpenSource. So, it would be beneficial to get a list of libraries and their according licenses that fall outside of established policies, so that I can address those in the according review process.

### Use Case

As a person responsible for doing OpenSource review in software releases, I need to see a list of licenses which are not addressed by my policies, as I need to start an exception process (or make active efforts to replace the related libraries).

### Proposed Solution

Create a seperate output file, listing licenses and libraries outside of the defined policies. There should also be some notification in the pipeline (is there a WARNING state?)

### Other Information

_No response_

### Acknowledgements

- [ ] I may be able to implement this feature request
- [ ] This feature might incur a breaking change

### CICD Boot version used

n/a

### Environment details (OS name and version, etc.)

n/a

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.