Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
tsteenbe
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
4 ms
·
1.
▲
by
tsteenbe
2y ago
This is why several German automotive OSPOs are working together to build OSS Review Toolkit (ORT) - it kinda glues various open source tools like ScanCode but adds features like the ability to manually correct findings and a policy as code
2.
▲
by
tsteenbe
4y ago
> Do HN got a recommendation for other CLI based SBOM generators? Try ORT https://github.com/oss-review-toolkit/ort (full disclosure I am one of its maintainers and also the lead of the SPDX Defects/Security Pr
3.
▲
by
tsteenbe
5y ago
Good catch I missed that openCVE is Business Source License which I actually do not consider to be open source.
4.
▲
by
tsteenbe
5y ago
Are you aware of https://github.com/nexB/vulnerablecode ? which offers a similar solution, is also open source and written in Python.
5.
▲
by
tsteenbe
7y ago
> It makes license scanning a doddle. As someone working in the field of license compliance (leading an Open Source Program Office) and dealing with the licensing of tens of thousands of OSS dependencies on a daily basis for a large comp
6.
▲
by
tsteenbe
7y ago
> A trivial solution would be to create a crowd-sourced dependency vetting platform. Such a platform is already being developed by various organizations, see https://clearlydefined.io/about and it already in use by GitHu
7.
▲
by
tsteenbe
7y ago
If you want to do license compliance for various package managers then I recommend you checkout https://github.com/heremaps/oss-review-toolkit . Full disclosure: I am one of the maintainers of OSS Review Toolkit.