Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Donate the SPDX header checker to this org? #327

Open
npmccallum opened this issue Aug 19, 2021 · 5 comments
Open

Donate the SPDX header checker to this org? #327

npmccallum opened this issue Aug 19, 2021 · 5 comments

Comments

@npmccallum
Copy link

I know that this issue doesn't really belong to this repo. But it seemed the best fit for my proposal.

Enarx is a Linux Foundation project under the auspices of the Confidential Computing Consortium. We have developed a GitHub Action which scans source code files in a software repo and highlights any which have missing SPDX license headers or use unapproved licenses.

Would this organization be interested in taking ownership of this tool? We would continue to develop it. But it may make more sense in your organization.

@goneall
Copy link
Member

goneall commented Aug 19, 2021

@npmccallum thanks for developing this tool. It does seem to fit the mission for SPDX and this repo. I'll take a look and bring this up to the SPDX tech tools group which part of part Automated Compliance Tooling (ACT) project. There is also an Free Software Foundation Europe project which has a similar mission is REUSE.

@kestewart @zvr - any thoughts?

@npmccallum
Copy link
Author

@goneall @kestewart @zvr Do you have interest in this?

@zvr
Copy link
Member

zvr commented Feb 21, 2022

Ooops, sorry -- I missed this when it first appeared.
It's definitely interesting and I am +1 for taking the repo under the SPDX umbrella/organization. Something like https://github.com/spdx/check-headers-action or similar.

@goneall
Copy link
Member

goneall commented Feb 21, 2022

I'll send an update to SPDX tech list and if there are no general objections by next week, we can go ahead and move it to SPDX.

@swinslow
Copy link
Member

+1 from me to moving this over, this looks very useful!

I agree with @zvr, I think it'd be appropriate for the destination repo to have a name which clarifies it's checking headers and/or licenses. check-headers-action seems fine to me.

@npmccallum thank you and the Enarx team for developing and contributing this!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants