Skip to main content

Discover Dependency License Information Using SBOMs and ClearlyDefined

H.2213 | Day 2 | 11:40 - 12:00 | Speakers: Jeff Mendoza

Discover Dependency License Information Using SBOMs and ClearlyDefined
A picture of a devroom at FOSDEM 2024
Open in browser
Get involved in the conversation!Join the chat

Notes

Abstract

SBOM specifications provide comprehensive capabilities for expressing license and legal information. However, SBOM generators often leave information missing or incomplete. Compounding this, package authors sometimes fail to clearly describe the license of their package or omit license information for included and vendored files.

ClearlyDefined is a community-curated repository of discovered license information for software packages. Its data is generated by deep scanning tools, such as ScanCode, which uncover legal information that may not be explicitly declared.

This session explores new SBOM tooling, built using Protobom, that queries licenses, produces NOTICE files, augments and outputs new SBOMs, all using high-fidelity legal information from ClearlyDefined.

Attachments

Speakers

Jeff Mendoza

Notice: The placeholder video image is licensed under CC BY-SA 4.0. The original image can be found hereChanges made to the image are: Cropped the image to a new ratio, part of the image was cut off.