Ignore license by package name #6342
Replies: 4 comments
-
I found this similar thread related to the license scanner which was closed with the most recent trivy release- #6118 Any plans to add it to the license scanner which was originally requested? Apart from that why it was decided to use PURLs?
Thanks and looking forward to some reply |
Beta Was this translation helpful? Give feedback.
-
A rego policy looks like a workaround - https://github.com/aquasecurity/trivy/pull/6004/files |
Beta Was this translation helpful? Give feedback.
-
I am also interested in this request. When using trivy to help monitor and report on license usage in a product, occasionally there may be a restricted license that gets flagged as a HIGH severity, but then after review and evaluation of the specific package it is deemed as acceptable for use within the product. In such cases, it would be nice to be able to ignore / suppress / lower the severity of that specific package, while not ignoring all packages using that specific license. Today, trivy supports using Bonus request: |
Beta Was this translation helpful? Give feedback.
-
Hi @kanton10062006 ! You are right, you can use Rego to filter licenses. Using Rego will allow you the flexibility to customize the filtering. /cc @tstraley |
Beta Was this translation helpful? Give feedback.
-
Description
Hello,
It would be nice if you added the ability to ignore some particular packages within package.json during license scanning.
The main reason for this is that for now, it is possible to ignore the entire license using the License ID which is not as flexible as I hoped.
For example - I bought a license for some particular package and would like to ignore it within my checks rather than ignoring the entire license at all.
Something like this:
Thanks
Target
Filesystem
Scanner
License
Beta Was this translation helpful? Give feedback.
All reactions