Open source · Compliance

DSI License Scan Apache-2.0

Resolves every transitive dependency to an SPDX identifier and fails the build on a copyleft dependency in a proprietary product.

Browse the catalogue

Public repository

https://github.com/dev-sec-it/license-scan

View repository

Releases, issues and the commit history are on the repository, so the license and the maintenance status can be checked against the last tagged release rather than taken on trust.

Catalogue record

The facts a buyer screens on first

Every value below is copied from the catalogue entry and is verifiable against the public repository.

License
Apache-2.0

OSI identifier, as published in the repository.

Stack
Go

Primary language and runtime.

Status
Production

As recorded in the DEV SEC IT catalogue.

Stars
740

Counted from the public repository at the time of writing.

What we maintain

Our contribution to DSI License Scan

This project is on the catalogue because we own part of it. The parts we wrote, review and release are named here; everything else is upstream work we depend on.

Maintenance

Maintained by DEV SEC IT

What we wrote

Transitive resolver and the policy gate

First tagged release

First tagged release in 2024.

Talk to us

Need this running inside your own perimeter?

We maintain this project and the platforms built on it. If you want a deployment, a review or a fix against your environment, the same engineers who ship it can scope it.

All open source