Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

OSS License not properly indicated for v12.2785.0 #176

Open
ethankent opened this issue Jun 27, 2024 · 2 comments
Open

OSS License not properly indicated for v12.2785.0 #176

ethankent opened this issue Jun 27, 2024 · 2 comments

Comments

@ethankent
Copy link

A license scan using Github's dependency review action indicates:

Package Version License Issue Type
bridgecrewio/checkov-action d3328ad Null Unknown License

Additionally, there is no license badge showing on the Marketplace page

I suspect a particular form field needs to get filled out when publishing.

@tsmithv11
Copy link
Contributor

Hi @ethankent, this repository has a license (Apache 2), so this seems like a limitation of GitHub's dependency review. Do you have an example of one that does show the proper license? I would say that we have the proper license in place, so this is not a priority for us.

@ethankent
Copy link
Author

Hi @tsmithv11, thanks for the reply. Everything I see in this repository seems to indicate that the license is configured. So, I don't believe there's a problem on the repo itself. However, the license badge does seem to be missing on the Marketplace page, so possibly there's a gap in the publishing process.

If it helps, I can tell you that I see a similar action in the marketplace that doesn't have any problems with the dependency review action. It's called Trivy & I can see that it has a license badge showing correctly.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants