Fossology has split out some of its tools to be usable individually. Ultimately we want to be able to generate SPDX manifests for any output binary we generate. This enhancement is to run the license scanner component(s) of fossology and allow a summary to be generated for each recipe. Ultimately this would be used for the final SPDX manifest. One of the reasons to do this is to explore how these tools can be integrated into our build process. If there are integration issues we should work with the upstream maintainers to try and find ways to allow the integration to work well. For license scanning we'd want to compare the license in the recipe with the license fossology believed the source to be under. There are some expected challenges: a) We'd want to run the tools without a central database/server. Any "fixups" would therefore need to be maintained in some form along with the recipe metadata itself (like a patch file would be?) b) We may need to allow the fossology tools to be used to verify the "fixup" and export into our metadata as we don't want to reinvent a GUI for that part of the process
moving to future
Maybe use scancode, not fossology?
Bulk move from 4.99 or 0.00 to 5.99
I think we have slightly different plans to this now. We can generate license information as needed for our SPDX output.