Bug 13322 - Integrate fossology or scancode license scanning into an OE build
Summary: Integrate fossology or scancode license scanning into an OE build
Status: RESOLVED OBSOLETE
Alias: None
Product: OE-Core
Classification: Build System, Metadata & Runtime
Component: Scripts and Tools (show other bugs)
Version: 5.99
Hardware: x86 Multiple
: Medium enhancement
Target Milestone: 5.99
Assignee: Unassigned
QA Contact:
URL:
Whiteboard:
Depends on:
Blocks:
 
Reported: 2019-05-02 13:20 UTC by Richard Purdie
Modified: 2026-06-12 16:09 UTC (History)
5 users (show)

See Also:
OS type for building Yocto: ---
Type of Regression: ---
Verified:
Documentation change: Yes (doc changes required)


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Richard Purdie 2019-05-02 13:20:42 UTC
Fossology has split out some of its tools to be usable individually. Ultimately we want to be able to generate SPDX manifests for any output binary we generate. 

This enhancement is to run the license scanner component(s) of fossology and allow a summary to be generated for each recipe. Ultimately this would be used for the final SPDX manifest.

One of the reasons to do this is to explore how these tools can be integrated into our build process. If there are integration issues we should work with the upstream maintainers to try and find ways to allow the integration to work well.

For license scanning we'd want to compare the license in the recipe with the license fossology believed the source to be under.

There are some expected challenges:

a) We'd want to run the tools without a central database/server. Any "fixups" would therefore need to be maintained in some form along with the recipe metadata itself (like a patch file would be?)

b) We may need to allow the fossology tools to be used to verify the "fixup" and export into our metadata as we don't want to reinvent a GUI for that part of the process
Comment 1 Armin Kuster 2020-01-09 16:05:37 UTC
moving to future
Comment 2 Richard Purdie 2020-04-14 07:01:54 UTC
Maybe use scancode, not fossology?
Comment 3 Randy MacLeod 2023-10-24 14:24:44 UTC
Bulk move from 4.99 or 0.00 to 5.99
Comment 4 Richard Purdie 2026-06-12 16:09:28 UTC
I think we have slightly different plans to this now. We can generate license information as needed for our SPDX output.