Add fossa cli config for license scanning #892
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Fixes issue #:
None
Description of the changes being introduced by the pull request:
The new way of doing license scans with fossa, uses the fossa cli (e.g. on the CI/CD build) and an API token to publish to app.fossa.com. This PR adds a fossa config file and updates the travis config file accordingly. See commit messages for details.
Note that we can't keep the FOSSA_API_TOKEN secret (e.g. via Travis encrypted or repository setting environment variables), because those are not available for Travis builds of PRs from forked repository, which we need to support. Therefor we use a non-confidential push only API token.
For details see and
Please verify and check that the pull request fulfills the following
requirements: