Discover Dependency License Information Using SBOMs and ClearlyDefined
- Track: Software Bill of Materials (SBOM)
- Room: H.2213
- Day: Sunday
- Start: 11:40
- End: 12:00
- Video only: h2213
- Chat: Join the conversation!
SBOM specifications provide comprehensive capabilities for expressing license and legal information. However, SBOM generators often leave information missing or incomplete. Compounding this, package authors sometimes fail to clearly describe the license of their package or omit license information for included and vendored files.
ClearlyDefined is a community-curated repository of discovered license information for software packages. Its data is generated by deep scanning tools, such as ScanCode, which uncover legal information that may not be explicitly declared.
This session explores new SBOM tooling, built using Protobom, that queries licenses, produces NOTICE files, augments and outputs new SBOMs, all using high-fidelity legal information from ClearlyDefined.
Speakers
Jeff Mendoza | |
Qing Tomlinson |