github / github/roadmap

Open Source License Compliance [GA]

Đang mở
#1,025 0 bình luận 7 reaction 0 người được giao Xem trên GitHub
Ngôn ngữ chính
Không có dữ liệu ngôn ngữ
Star
8.9k
Fork
1.8k
Chỉ số merge pull request
Không có pull request nào được merge trong 30 ngày

Mô tả

### Value Prop

While using open source software (OSS) brings well-demonstrated benefits like leveraging community innovation and empowering developers to focus on differentiated value, it also introduces risks, from security vulnerabilities to targeted attacks. GitHub has powerful features like Dependabot for managing vulnerable versions of your OSS dependencies. Now, OSS License Compliance extends these capabilities, so customers can ensure that the licenses of the OSS packages they depend on are compliant with a policy defined by their organization.

### Expected Outcome

With GitHub OSS License Compliance, organizations configure a baseline policy that describes which licenses its upstream dependencies are allowed/disallowed to have - we'll provide starter policies that should suit most users, with the ability to customize them. Once configured, the business risk of incorporating dependencies with incompatible licenses is reduced in three key ways:

1. Rulesets will enforce the policy on incoming PRs, ensuring that changes entering your codebase don't introduce new dependencies with incompatible licenses.
2. GitHub Actions that build artifacts have a complete view of the build environment and composition of the resulting artifact, so they can prevent deep transitive dependencies with problematic licenses from being included. Conversely, an artifact whose dependencies consist of only packages with compliant licenses will receive a secure, verifiable attestation to that effect.
3. Existing code may have latent, undiscovered problems with licenses, so we provide a scanning feature to introspect the Software Bill of Materials (SBOMs) of your repositories and find dependencies with noncompliant licenses.

When these workflows detect problems, they'll generate alerts and metrics similar to the existing Dependabot alerts to provide context, auditability, and actionable outcomes.

With GitHub OSS License Compliance, you'll have a comprehensive way to understand and manage the risk inherent in using open source, so you can focus on the benefits.

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Đánh giá

Issue này chưa được đánh giá.

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.