There are 2 repositories under oss-compliance topic.
:mag: ScanCode detects licenses, copyrights, dependencies by "scanning code" ... to discover and inventory open source and third-party packages used in your code. Sponsored by NLnet project https://nlnet.nl/project/vulnerabilitydatabase, the Google Summer of Code, Azure credits, nexB and others generous sponsors!
A suite of tools to automate software compliance checks.
Tern is a software composition analysis tool and Python library that generates a Software Bill of Materials for container images and Dockerfiles. The SBOM that Tern generates will give you a layer-by-layer view of what's inside your container in a variety of formats including human-readable, JSON, HTML, SPDX and more.
Chainloop is an Open Source Metadata Vault for your Software Supply Chain metadata, SBOMs, VEX, SARIF files, QA reports, and more.
A compilation of resources in the software supply chain security domain, with emphasis on open source
:bar_chart: ScanCode Workbench is a desktop app to review and conclude license and origin from code scans generated by ScanCode Toolkit.
This repo realizes the idea that OSS compliance activities will be less expensive by applying OSS principles
A light-weight app to audit and inventory large codebases for open source license compliance.
Cool links, tools & papers related to Open Source Licensing
This repo contains license and copyright analysis results of open source packages. It further contains other license compliance relevant artifacts, which might be of value for others
A desktop workbench for OSS Review Toolkit result files.
bitbake layer repository for intergrating osselot into the build process
An ongoing & curated collection of awesome software best practices and techniques, libraries and frameworks, E-books and videos, websites, blog posts, links to github Repositories, technical guidelines and important resources about Secure Software Supply Chain Lifecycle in Cybersecurity.
See who wrote each line of code in your git repository with interactive reports.
Webapp for custom data usage
Legal Notifications, EULAs, ToS, GDPR, Software License Assessments and SPDX Licenses that we use
Deploy scripts for FOSSology Docker container
OpenChain Specification
Check a GitHub organization's repositories' license choices