You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This project is the de facto standard for integrating with the SCANOSS platform.
It provides a CLI, SDK, and Container to ease integrating SCANOSS into your development ecosystem.
primary_languages
Python
short_term_roadmap
Add support for SCANOSS Settings
Add container scanning
Add VEX to SBOM exports
Add package checksums to SPDX reports
Provenance
License Policy checker
High Precision Folder Hashing
long_term_roadmap
Provenance v2
Vulnerability Policy checker
Provenance Policy checker
CBOM Reports
Bitbucket integration
proprietary_data
Yes, the tool depends on proprietary data sources
commercial_features
Yes, the tool has a commercial version with different/additional features
capabilities
Identifiers - Use Package-URL (PURL) identifiers
Identifiers - Use SPDX license expressions
Scanning - Analyze package manifests and lockfiles
Scanning - Analyze package files
Scanning - Scan for copyright
Scanning - Scan for license
Scanning - Analyze source code
Scanning - Analyze containers
Scanning - Analyze installed system packages (linux distros)
Scanning - Analyze installed application packages
Scanning - Other analysis
Packages - Inventory packages
Packages - Inventory packages dependencies
Packages - Resolve dependencies
Packages - Navigate or display dependency graph
Compliance - Generate CycloneDX SBOMs
Compliance - Generate SPDX SBOMs
Compliance - Validate CycloneDX SBOM
Compliance - Validate SPDX SBOMs
Compliance - Generate CycloneDX VEX
Compliance - Generate CSAF VEX
Compliance - Generate OpenVex
Compliance - Generate other compliance documents
Policies - Define and check license policies
Policies - Define and check security policies
Policies - Define and check other policies
Data - Database of Package metadata
Data - Database of Package dependency relationships
Data - Database of License obligations
Data - Database of Licenses
Data - Database of Vulnerabilities
License - Help triage license issues
License - Generate license credit and attribution notices
homepage_url
https://www.scanoss.com
contact_email
[email protected]
code_view_url
https://github.com/scanoss/scanoss.py
spdx_license_expression
MIT
description
This project is the de facto standard for integrating with the SCANOSS platform.
It provides a CLI, SDK, and Container to ease integrating SCANOSS into your development ecosystem.
primary_languages
Python
short_term_roadmap
long_term_roadmap
proprietary_data
commercial_features
capabilities
other_capabilities
The text was updated successfully, but these errors were encountered: