Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add license scan badge to the README #1562

Closed
eddie-knight opened this issue Oct 18, 2022 · 6 comments
Closed

Add license scan badge to the README #1562

eddie-knight opened this issue Oct 18, 2022 · 6 comments

Comments

@eddie-knight
Copy link
Contributor

eddie-knight commented Oct 18, 2022

Part of #1508.

It's not a security item, but maintainers should be able to generate a license scan badge really easily using FOSSA (the alternative is a paid Snyk tool). Once a license scan badge is in the repo, that license scanning check should go green.

  1. Maintainer should sign in to https://fossa.com using GitHub auth
  2. Authorize connectivity, add/import this repo, and begin the scan
  3. After the import is completed, a license badge will be generated, see image below (click badge to open modal)
  4. Add scan to CI (ref)

Screen Shot 2022-10-17 at 9 45 28 PM

@pdrastil
Copy link
Member

@mkilchhofer Can you take a look into this?

@mkilchhofer
Copy link
Member

@crenshaw-dev
Can we use snyk as well? I see that in our (community) repository we inherit the token for Snyk. Can we try the workflow of argo-cd?

https://github.com/argoproj/argo-cd/blob/776d8f97ccc95584b7ac586f0e7091819e39f583/.github/workflows/update-snyk.yaml#L1-L36

@eddie-knight
Copy link
Contributor Author

@mkilchhofer Argo CD doesn't currently have License Scanning identified by CLOMonitor.

ref: https://clomonitor.io/projects/cncf/argo#argo-cd_license

@github-actions
Copy link

This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions.

@mkilchhofer
Copy link
Member

not stale

@github-actions
Copy link

github-actions bot commented Mar 6, 2023

This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions.

@github-actions github-actions bot closed this as not planned Won't fix, can't repro, duplicate, stale Mar 14, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

4 participants