-
Notifications
You must be signed in to change notification settings - Fork 593
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Capture licenses for all packages #2861
Comments
@kzantow - why is Go marked as checked? How do we get the license of Go modules? |
@mykaul check out the golang section of the Syft configuration file: https://github.com/anchore/syft/wiki/configuration -- there are two settings, |
Thanks! I think what tricked me is that by default (syft-text?) you do not see the license, so I did not even bother to look further. Very helpful, thanks again. |
Any idea why I get different output report when scanning the same package with On one machine - licenses info is presented:
On another machine the license info is missing:
both machines are installed with Fedora release 37 |
Very the configuration file is identical and accessible in both machines. Perhaps run syft with debug will show it. |
seems it is related to the same issue #2798 |
Syft should be able to include license information for packages it finds. Sometimes this information is present in the metadata on disk, other times it is only available by some remote source. This is an uber-issue about capturing licenses for all packages. Each ecosystem will likely have a different mechanism of capturing license information.
Ecosystems:
Some related issues:
The text was updated successfully, but these errors were encountered: