alitheg opened a new issue, #432:
URL: https://github.com/apache/tooling-trusted-releases/issues/432

   When generating an SBOM in ATR, I've noticed most components are missing 
licenses. There is a [closed issue for 
this](https://github.com/anchore/syft/issues/933) but I've looked up a few 
component licenses and they are in the list that syft uses. [This 
issue](https://github.com/anchore/syft/issues/2861) suggests license support 
isn't complete but the previous one looks to support python so I'm not sure.
   
   Maybe this is something we could augment for any packages missing licenses 
by looking them up ([ClearlyDefined](https://clearlydefined.io/) or 
[PurlDB](https://aboutcode.readthedocs.io/projects/PURLdb/en/latest/)) could 
work - both seem to provide a way to do this


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to