-
Notifications
You must be signed in to change notification settings - Fork 574
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
source License not found..? it is bug? #1548
Comments
or i missing ENV vaule? |
@JUNGJUNCHUL there are no licenses included in the In this case, you have a
|
@kzantow Is there any way to retrieve the license in a normal source scan, not in a runtime environment? i have multiple project... |
@JUNGJUNCHUL if the |
@kzantow syft is very good at extracting dependency lists, but it has the disadvantage of having to link with other tools because it is difficult to get license information. Among other tools, SBOM (SPDX, Cyclondx) does not have the ability to add only the dependency list, so other tools are being considered rather than syft. If that part is supplemented, it will be very useful and good to use. Thank you for your answer. |
git clone https://github.com/OWASP/NodeGoat
syft ./ -o syft-json=sbom.syft.json -o cyclonedx-json=cyclone.json -o spdx-json=spdx.json
All format shows well with dependency but the license is empty..
it is bug?
The text was updated successfully, but these errors were encountered: