3 ms·
Yeah cause our companies love to let third parties “analyze” our code.
by mpolichette 8y ago
Yeah cause our companies love to let third parties “analyze” our code.
- hp 8y agoIt's analogous to something like Code Climate, Coveralls, TravisCI, etc. Some companies require an on-premise version or want to run the scan themselves and only call an "upload my dependencies as JSON" API, which is fine. The scan is only to get the list of deps and their versions, it doesn't care about the actual source code.
- DannyB2 8y agoFor a Java program, just gather the "import" declarations from every single source file. Consolidate those into a single file, removing duplicates, sort them. You now have a list of everything used by your program. Remove all of the internal imports. That is imports from other parts of your own software. (Hint: this is easy since they are sorted by package name.) Now you have a list of all third party software used. I suspect this same procedure works for C / C++ / Python and probably other languages. You don't have to give anyone your source code to discover what third party and open source software you are using.