anchore / syft

CLI tool and library for generating a Software Bill of Materials from container images and filesystems

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Match Data Against ClearlyDefined

henrysachs opened this issue · comments

What would you like to be added:

Add the check against: https://docs.clearlydefined.io/get-involved or a link to the corresponding artifact

Why is this needed:

To improve the Data and maybe check the detected data against that database

Additional context:
I think it would be cool to somehow "fact check" the detected components and licenses against this database

Hi @henrysachs, thanks for the suggestion and sorry for the delay acknowledging. We'll take a look and move this into the backlog for the future. Let us know if you are interested in working on it.