-
Notifications
You must be signed in to change notification settings - Fork 56
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Formal statement format for project with no OSS BOM #9
Comments
We do not provide a single "source of truth" statement for such a matter. It is really up to the in-house procurement and legal times. Conceptually, it might be something like this: |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Hi all,
Is there a formal statement to give to customers for the projects which has no OSS components.?
we cannot give confirmation that no OSS is being used because we cannot ensure 100% accuracy since there is always limitations to the tools. So we need come up with a statement which sets the tools limitations in place & also state that no OSS evidence has been found after performing the so & so scan.
I wanted to know does there are any statements already in place in Open chain. I searched here https://github.com/OpenChain-Project/Reference-Material
but I did not find anything related to it.
Thanks
The text was updated successfully, but these errors were encountered: