<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugzilla.yoctoproject.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.6"
          urlbase="https://bugzilla.yoctoproject.org/"
          
          maintainer="it-coreprojects-helpdesk@linuxfoundation.org"
>

    <bug>
          <bug_id>13322</bug_id>
          
          <creation_ts>2019-05-02 13:20:42 +0000</creation_ts>
          <short_desc>Integrate fossology or scancode license scanning into an OE build</short_desc>
          <delta_ts>2026-06-12 16:09:28 +0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>7</classification_id>
          <classification>Build System, Metadata &amp; Runtime</classification>
          <product>OE-Core</product>
          <component>Scripts and Tools</component>
          <version>5.99</version>
          <rep_platform>x86</rep_platform>
          <op_sys>Multiple</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>OBSOLETE</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard> </status_whiteboard>
          <keywords></keywords>
          <priority>Medium</priority>
          <bug_severity>enhancement</bug_severity>
          <target_milestone>5.99</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Richard Purdie">richard.purdie</reporter>
          <assigned_to name="Unassigned">unassigned</assigned_to>
          <cc>akuster</cc>
    
    <cc>niko.mauno</cc>
    
    <cc>randy.macleod</cc>
    
    <cc>ross.burton</cc>
    
    <cc>tim.orling</cc>
          
          
          <cf_os>---</cf_os>
          <cf_regression_type>---</cf_regression_type>
          
          <cf_docchange>Yes (doc changes required)</cf_docchange>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>83685</commentid>
    <comment_count>0</comment_count>
    <who name="Richard Purdie">richard.purdie</who>
    <bug_when>2019-05-02 13:20:42 +0000</bug_when>
    <thetext>Fossology has split out some of its tools to be usable individually. Ultimately we want to be able to generate SPDX manifests for any output binary we generate. 

This enhancement is to run the license scanner component(s) of fossology and allow a summary to be generated for each recipe. Ultimately this would be used for the final SPDX manifest.

One of the reasons to do this is to explore how these tools can be integrated into our build process. If there are integration issues we should work with the upstream maintainers to try and find ways to allow the integration to work well.

For license scanning we&apos;d want to compare the license in the recipe with the license fossology believed the source to be under.

There are some expected challenges:

a) We&apos;d want to run the tools without a central database/server. Any &quot;fixups&quot; would therefore need to be maintained in some form along with the recipe metadata itself (like a patch file would be?)

b) We may need to allow the fossology tools to be used to verify the &quot;fixup&quot; and export into our metadata as we don&apos;t want to reinvent a GUI for that part of the process</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>86003</commentid>
    <comment_count>1</comment_count>
    <who name="Armin Kuster">akuster</who>
    <bug_when>2020-01-09 16:05:37 +0000</bug_when>
    <thetext>moving to future</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>86985</commentid>
    <comment_count>2</comment_count>
    <who name="Richard Purdie">richard.purdie</who>
    <bug_when>2020-04-14 07:01:54 +0000</bug_when>
    <thetext>Maybe use scancode, not fossology?</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>96927</commentid>
    <comment_count>3</comment_count>
    <who name="Randy MacLeod">randy.macleod</who>
    <bug_when>2023-10-24 14:24:44 +0000</bug_when>
    <thetext>Bulk move from 4.99 or 0.00 to 5.99</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>105859</commentid>
    <comment_count>4</comment_count>
    <who name="Richard Purdie">richard.purdie</who>
    <bug_when>2026-06-12 16:09:28 +0000</bug_when>
    <thetext>I think we have slightly different plans to this now. We can generate license information as needed for our SPDX output.</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>