Optionally include Copyrights/Notices in scan results #4374
Replies: 3 comments
-
|
I agree with @anders-swanson. It would be very help in terms license compliance and also benefits the user/developer to readily consume a notices file with all the relevant licenses and copyright data from the SBOM generated by Trivy. |
Beta Was this translation helpful? Give feedback.
-
|
I also think this would be a valuable feature. Many licenses contain a copyright notice. It usually consists of a copyright holder and a year or version number. Most of these licenses (like MIT, Apache, GPL, LGPL, MPL, etc.) do require you to reproduce the copyright notice(s) of the original authors and any subsequent contributors when you distribute the software. This is usually a core condition of the license. Unfortunately Trivy currently does not exposed this information in any way. |
Beta Was this translation helpful? Give feedback.
-
Beta Was this translation helpful? Give feedback.

Uh oh!
There was an error while loading. Please reload this page.
-
Is it possible for Trivy to include Copyrights and/or Notice texts in scan results, if they are present? This could be a helpful compliance feature.
Beta Was this translation helpful? Give feedback.
All reactions