Only OSI approved licenses
This policy checks if there is no violation against the license allow list.
Control evaluation result
Component "github.com/klauspost/compress" uses non-OSI approved license "non-standard"
Component "github.com/magiconair/properties" uses non-OSI approved license "non-standard"
Component "github.com/munnerz/goautoneg" uses non-OSI approved license "non-standard"
Component "github.com/pelletier/go-toml/v2" uses non-OSI approved license "non-standard"
Component "github.com/pkg/errors" uses non-OSI approved license "non-standard"
Component "github.com/pmezard/go-difflib" uses non-OSI approved license "non-standard"
Component "gitlab.com/gitlab-org/api/client-go" has no license declared
Component "gitlab.opencode.de/open-code/badgebackend/badge-api" has no license declared
Component "golang.org/x/crypto" has no license declared
Component "golang.org/x/exp" has no license declared
Component "golang.org/x/oauth2" has no license declared
Component "golang.org/x/sync" has no license declared
Component "golang.org/x/sys" has no license declared
Component "golang.org/x/term" has no license declared
Component "golang.org/x/text" has no license declared
Component "golang.org/x/time" has no license declared
Component "google.golang.org/protobuf" has no license declared
Component "gopkg.in/ini.v1" has no license declared
Component "gopkg.in/yaml.v3" has no license declared
Status
Evaluation result after comparing the policy with the current state of the asset
19 Violations
Update the attestation using the following command
devguard-scanner attest --predicateType "https://cyclonedx.org/bom" <json file>