Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open Source License Compliance #6606

Closed
sametr35 opened this issue Apr 18, 2024 · 3 comments
Closed

Open Source License Compliance #6606

sametr35 opened this issue Apr 18, 2024 · 3 comments
Labels

Comments

@sametr35
Copy link

Hi,

Does OWASP Dependency-Check scan for open-source license compliance? Typically, SCA tools verify the licenses of the open-source components in your codebase to ensure compliance with their terms. Additionally, if you have documentation or a webpage about it, could you please share the link?

@jeremylong
Copy link
Owner

ODC will report a license if it sees one - but I would not rely on this feature.

@mirabilos
Copy link

Speaking as someone who audits the licences of all dependencies: the licence metadata in the POMs is often wrong or at the very least incomplete anyway. If you want to ensure full compliance, you will have to inspect every single dependency (including transitive dependencies) manually, and yes, that often includes looking at every single file…

@jeremylong
Copy link
Owner

I completely agree with @mirabilos - researching licensing can be a complicated, tedious task.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

3 participants