fossas / fossas/fossa-cli

Cross-reference OpenChain CRA Compliance Checklist

Open Beginner friendly
#1,772 2 comments 0 reactions 0 assignees View on GitHub
Dominant language
Haskell
Stars
1.5k
Forks
205
Avg merge
2d 10h
Merged PRs (30d)
20

Description

Hello FOSSA maintainers,

We are reaching out around the OpenChain CRA Compliance Requirements & Checklist.

We would like to cross-reference relevant CRA, SBOM, SCA, and open source compliance resources so users can find community material that helps with CRA evidence planning. Given FOSSA CLI's role in dependency analysis, license compliance, vulnerability scanning, and SBOM-oriented workflows, would you be open to referencing the OpenChain CRA checklist from the relevant README or documentation, where it fits?

OpenChain CRA checklist:
https://github.com/OpenChain-Project/CRA-Compliance

Annex D external references/adoption section:
https://github.com/OpenChain-Project/CRA-Compliance/blob/main/ANNEX_D_EXTERNAL_REFERENCES_AND_ADOPTION.md

This is only a cross-reference request, not a legal endorsement or conformity assessment claim. If GitHub is not the right place for this, please point us to the best channel.

Thank you.

Contributor guide

No contributing guide indexed for this repository

Research direction

Review the repository README and documentation areas to find the section covering dependency analysis, compliance, vulnerabilities, or SBOM workflows. Compare the OpenChain CRA checklist and its Annex D references, then add an appropriately scoped cross-reference without implying legal endorsement. Done means the relevant documentation links to the checklist clearly and the documentation checks pass.

Written by the indexing model from the issue text.

Assessment

Domain
documentation
Issue type
Documentation
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
65/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.