Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Is there any feature to download/list the following details. #2002

Closed
parvjain639 opened this issue Aug 7, 2023 · 9 comments
Closed

Is there any feature to download/list the following details. #2002

parvjain639 opened this issue Aug 7, 2023 · 9 comments
Labels
license relating to software licensing question Further information is requested

Comments

@parvjain639
Copy link

parvjain639 commented Aug 7, 2023

How to get license details in tabular form??
or Any template example which shows the following items in list:
Package Name
Package Version
Package type
Copyright Detail
License Detail

@parvjain639 parvjain639 added the enhancement New feature or request label Aug 7, 2023
@parvjain639 parvjain639 changed the title is there any feature to download/list the following details. Is there any feature to download/list the following details. Aug 7, 2023
@tgerla
Copy link
Contributor

tgerla commented Aug 7, 2023

Hi @parvjain639, this should be possible using a custom template: https://github.com/anchore/syft#using-templates. There is a new blog post about templates (in Grype, but the concepts are similar) if you need a bit more info: https://anchore.com/blog/customizing-grype-vulnerability-reports-with-templates/ -- and please let us know if you need any help.

@tgerla tgerla added question Further information is requested and removed enhancement New feature or request labels Aug 7, 2023
@parvjain639
Copy link
Author

parvjain639 commented Aug 7, 2023

Thank you so much we have just solved it by using a Template...

Please clear our one more Query:

  1. Does Syft and Grype have open source license files keyword scanners to facilitate obligations compliance. Having a tool to scan OSS components license files for keywords such as

IP: patents, royalties, legal,
ECC: export, cryptography, AI, newtech,
GDRP: privacy, regulations, chatgpt,
OSS: attribution, contribution, distribution streamlined obligations compliance.

@tgerla
Copy link
Contributor

tgerla commented Aug 7, 2023

At the moment, no, the tools don't have keyword scanners like you suggest. It might be difficult to automate these kinds of things, but we would be happy to consider contributions if you implemented a new scanner.

@parvjain639
Copy link
Author

Thank you so much for your response.
We will see what we can contribute!!

I am having one more doubt!
How to integrate SYFT and GRYPE with GITLAB 16??

@tgerla
Copy link
Contributor

tgerla commented Aug 9, 2023

You're welcome! For Gitlab integration, I would start here and read through the Gitlab docs: https://docs.gitlab.com/ee/development/integrations/secure.html

Good luck!

@wagoodman wagoodman added the license relating to software licensing label Aug 10, 2023
@wagoodman
Copy link
Contributor

wagoodman commented Aug 10, 2023

When it comes to a keyword search within license text that is really outside of the intended use case for syft (which is to create SBOMs). However, we don't support raising up the raw license text in the SBOM, which would at least enable downstream tooling to do this (and is supported in SPDX and CycloneDX).

If we supported such a feature (getting full license text in the SBOM) would that be useful to you?

@parvjain639
Copy link
Author

If we supported such a feature (getting full license text in the SBOM) would that be useful to you?

Yes, this will be very helpful to us. And What about Dependencies and Depth (Level) of Dependencies??

If you can add this feature, this will be also very helpful for us and other users too.

@wagoodman
Copy link
Contributor

indeed! that work is being tracked under #572

@tgerla
Copy link
Contributor

tgerla commented Oct 19, 2023

We will close this issue but please let us know if you need any more help. Thanks!

@tgerla tgerla closed this as not planned Won't fix, can't repro, duplicate, stale Oct 19, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
license relating to software licensing question Further information is requested
Projects
Archived in project
Development

No branches or pull requests

3 participants