scancode.io
scancode.io copied to clipboard
ScanCode.io is a server to script and automate software composition analysis pipelines with ScanPipe pipelines. This project is sponsored by NLnet project https://nlnet.nl/project/vulnerabilitydatabas...
I create a `map_deploy_to_develop` project with these Java inputs: - https://repo1.maven.org/maven2/org/apache/htrace/htrace-core/4.0.0-incubating/htrace-core-4.0.0-incubating-sources.jar#from - https://repo1.maven.org/maven2/org/apache/htrace/htrace-core/4.0.0-incubating/htrace-core-4.0.0-incubating.jar#to I would like to improve access to the issues in this d2d: 1. **I would like to...
to/debian-binary files SHOULD not be mapped nor matched in any pipeline and the PurlDB should notb natch them either. They are present in every .deb package - [ ] nexB/purldb#422
It would be useful to add a test for ELF d2d using a Debian packages source and binary. This will support this issue: - https://github.com/nexB/purldb/issues/421
- [ ] Searching a project by pipeline is fairly slow: On the main project list page if I want to filter by Pipeline it takes up to one minute...
I think it would be good to provide license and copyright scans for source URLs present in `script` tags in a HTML page. For example: ''' script-tag src="http://ajax.googleapis.com/ajax/libs/jquery/1.10.2/jquery.min.js"script-tag ''' It...
We should rebuild published containers daily. This also applies to purldb and dejacode
Reference: https://github.com/aboutcode-org/scancode.io/issues/1407 Reference: https://github.com/aboutcode-org/scancode-toolkit/releases/tag/v32.3.0
- Closes https://github.com/aboutcode-org/federatedcode/issues/23
There are two conflicting use cases that needs to be addressed: 1. Running a fast package scan to only get package information from manifests and lockfiles 2. Running a more...