-
Notifications
You must be signed in to change notification settings - Fork 254
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Roll out FOSSA scanning to all repositories #2574
Labels
area/legal
area/project-infra
Non-GitHub project infra (DockerHub, etc.)
triage:accepted
This issue has been accepted and will be worked.
Comments
This was referenced Feb 15, 2025
Sent a few PRs in the first batch, will wait until next week to send to the remaining repos. |
mx-psi
pushed a commit
to open-telemetry/opentelemetry-collector-contrib
that referenced
this issue
Feb 17, 2025
See open-telemetry/community#2574 for details Co-authored-by: Trask Stalnaker <trask.stalnaker@gmail.com>
github-merge-queue bot
pushed a commit
to open-telemetry/opentelemetry-collector
that referenced
this issue
Feb 17, 2025
See open-telemetry/community#2574 for details Co-authored-by: Trask Stalnaker <trask.stalnaker@gmail.com>
github-merge-queue bot
pushed a commit
to open-telemetry/opentelemetry-collector
that referenced
this issue
Feb 17, 2025
See open-telemetry/community#2574 for details Co-authored-by: Trask Stalnaker <trask.stalnaker@gmail.com>
This was referenced Feb 18, 2025
This was referenced Feb 18, 2025
all PRs are created now |
dmathieu
added a commit
to open-telemetry/opentelemetry-go
that referenced
this issue
Feb 19, 2025
See open-telemetry/community#2574 for details Co-authored-by: otelbot <197425009+otelbot@users.noreply.github.com> Co-authored-by: Damien Mathieu <42@dmathieu.com>
lquerel
pushed a commit
to open-telemetry/otel-arrow
that referenced
this issue
Feb 23, 2025
See open-telemetry/community#2574 for details Co-authored-by: otelbot <197425009+otelbot@users.noreply.github.com>
Just a heads up for anyone watching this, we will come back to this work sometime after KubeCon |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Labels
area/legal
area/project-infra
Non-GitHub project infra (DockerHub, etc.)
triage:accepted
This issue has been accepted and will be worked.
FOSSA does both license and security scanning. Our initial focus is on license scanning since there may be overlap with other tools on the security scanning side.
I'm planning on asking @opentelemetrybot to fork and open PRs to all repos to add a
fossa.yml
workflow like https://github.com/open-telemetry/opentelemetry-java/blob/main/.github/workflows/fossa.yml.Update: expand this for the script @opentelemetrybot is running
Maintainers: if you would like access to FOSSA, just DM me your email address on Slack (note: it needs to be an email address that is not already associated with a FOSSA account). I will collect the email addresses for a few days and then ask the CNCF to send out invites to the first batch (we are under the CNCF's FOSSA enterprise account and don't have access to send out invites ourselves).
Once we get a clean bill of health from FOSSA, we would like to publish the (passing) badges to https://github.com/open-telemetry/community/blob/main/reports/compliance.md. And folks can of course add the badges directly on their repos as well.
We haven't figured out yet the best way to track new licensing issues after initial compliance, though if you request access to FOSSA then you'll be able to have it send you notifications for a given repo(s).
The text was updated successfully, but these errors were encountered: