-
Notifications
You must be signed in to change notification settings - Fork 720
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Enable FOSSA license scanning across all Kubernetes orgs #164
Comments
@justaugustus can you please point us to the page that describes the permissions needed by this app? |
@dims -- here you go: https://github.com/fossas/fossa-docs/blob/master/src/md/getting-started/repository-permissions.md added to the issue description as well. |
I see this already happens to be enabled for google and GoogleCloudPlatform, so I figure if it's good enough for them... But seriously, discussed in private with the rest of @kubernetes/owners, it's been enabled for kubernetes-sigs for a bit and nothing has caught on fire, so we're ok with this |
This is fine as a first step. +1 At what kind of cadence does this provide results? Ideally we find a solution that allows us to prevent merges of bad licenses, in addition to flagging problems after the fact. |
@justaugustus +1. Thanks for doing this! |
+1 in support of this. |
/close |
@spiffxp: Closing this issue. In response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. |
Organization or repository
All k8s orgs
Name of integration
FOSSA
Link to integration website
Describe what is attempting to be accomplished
As a project, we'd like to be able to scan software licenses with some framework and it seems the general consensus has been to use FOSSA.
There are multiple tracking issues and threads to catch up on, so I'll point there instead:
k/steering
issue: Kubernetes license scanning steering#57k/sig-release
tracking: [Umbrella] License Auditing & Remediation sig-release#223k/steering
issue: Third party dependencies in kubernetes steering#21Additional context for request
N/A
/area github-integration
/assign
/cc @kubernetes/owners @nikhita @dims @swinslow
The text was updated successfully, but these errors were encountered: