Only OSI approved licenses

This policy checks if there is no violation against the license allow list.

Control evaluation result

Component "/stdlib" has no license declared
Component "debian/adduser" has no license declared
Component "debian/apt" has no license declared
Component "debian/base-files" has no license declared
Component "debian/base-passwd" has no license declared
Component "debian/bash" has no license declared
Component "debian/binutils" has no license declared
Component "debian/binutils-common" has no license declared
Component "debian/binutils-x86-64-linux-gnu" has no license declared
Component "debian/bsdutils" has no license declared
Component "debian/ca-certificates" has no license declared
Component "debian/coreutils" has no license declared
Component "debian/cpp" has no license declared
Component "debian/cpp-12" has no license declared
Component "debian/curl" has no license declared
Component "debian/dash" has no license declared
Component "debian/debconf" has no license declared
Component "debian/debian-archive-keyring" has no license declared
Component "debian/debianutils" has no license declared
Component "debian/diffutils" has no license declared
Component "debian/dirmngr" has no license declared
Component "debian/dpkg" has no license declared
Component "debian/e2fsprogs" has no license declared
Component "debian/findutils" has no license declared
Component "debian/g++" has no license declared
Component "debian/g++-12" has no license declared
Component "debian/gcc" has no license declared
Component "debian/gcc-12" has no license declared
Component "debian/gcc-12-base" has no license declared
Component "debian/gdbm" has no license declared
Component "debian/git" has no license declared
Component "debian/git-man" has no license declared
Component "debian/gnupg" has no license declared
Component "debian/gnupg-l10n" has no license declared
Component "debian/gnupg-utils" has no license declared
Component "debian/gpg" has no license declared
Component "debian/gpg-agent" has no license declared
Component "debian/gpg-wks-client" has no license declared
Component "debian/gpg-wks-server" has no license declared
Component "debian/gpgconf" has no license declared
Component "debian/gpgsm" has no license declared
Component "debian/gpgv" has no license declared
Component "debian/grep" has no license declared
Component "debian/gzip" has no license declared
Component "debian/hostname" has no license declared
Component "debian/init-system-helpers" has no license declared
Component "debian/libacl1" has no license declared
Component "debian/libapr1" has no license declared
Component "debian/libaprutil1" has no license declared
Component "debian/libapt-pkg6.0" has no license declared
Component "debian/libasan8" has no license declared
Component "debian/libassuan0" has no license declared
Component "debian/libatomic1" has no license declared
Component "debian/libattr1" has no license declared
Component "debian/libaudit-common" has no license declared
Component "debian/libaudit1" has no license declared
Component "debian/libbinutils" has no license declared
Component "debian/libblkid1" has no license declared
Component "debian/libbrotli1" has no license declared
Component "debian/libbsd0" has no license declared
Component "debian/libbz2-1.0" has no license declared
Component "debian/libc-bin" has no license declared
Component "debian/libc-dev-bin" has no license declared
Component "debian/libc6" has no license declared
Component "debian/libc6-dev" has no license declared
Component "debian/libcap-ng0" has no license declared
Component "debian/libcap2" has no license declared
Component "debian/libcbor0.8" has no license declared
Component "debian/libcc1-0" has no license declared
Component "debian/libcom-err2" has no license declared
Component "debian/libcrypt-dev" has no license declared
Component "debian/libcrypt1" has no license declared
Component "debian/libctf-nobfd0" has no license declared
Component "debian/libctf0" has no license declared
Component "debian/libcurl3-gnutls" has no license declared
Component "debian/libcurl4" has no license declared
Component "debian/libdb5.3" has no license declared
Component "debian/libdebconfclient0" has no license declared
Component "debian/libedit2" has no license declared
Component "debian/liberror-perl" has no license declared
Component "debian/libexpat1" has no license declared
Component "debian/libext2fs2" has no license declared
Component "debian/libffi8" has no license declared
Component "debian/libfido2-1" has no license declared
Component "debian/libgcc-12-dev" has no license declared
Component "debian/libgcc-s1" has no license declared
Component "debian/libgcrypt20" has no license declared
Component "debian/libgdbm-compat4" has no license declared
Component "debian/libgdbm6" has no license declared
Component "debian/libgmp10" has no license declared
Component "debian/libgnutls30" has no license declared
Component "debian/libgomp1" has no license declared
Component "debian/libgpg-error0" has no license declared
Component "debian/libgprofng0" has no license declared
Component "debian/libgssapi-krb5-2" has no license declared
Component "debian/libhogweed6" has no license declared
Component "debian/libidn2-0" has no license declared
Component "debian/libisl23" has no license declared
Component "debian/libitm1" has no license declared
Component "debian/libjansson4" has no license declared
Component "debian/libk5crypto3" has no license declared
Component "debian/libkeyutils1" has no license declared
Component "debian/libkrb5-3" has no license declared
Component "debian/libkrb5support0" has no license declared
Component "debian/libksba8" has no license declared
Component "debian/libldap-2.5-0" has no license declared
Component "debian/liblsan0" has no license declared
Component "debian/liblz4-1" has no license declared
Component "debian/liblzma5" has no license declared
Component "debian/libmd0" has no license declared
Component "debian/libmount1" has no license declared
Component "debian/libmpc3" has no license declared
Component "debian/libmpfr6" has no license declared
Component "debian/libncursesw6" has no license declared
Component "debian/libnettle8" has no license declared
Component "debian/libnghttp2-14" has no license declared
Component "debian/libnpth0" has no license declared
Component "debian/libnsl" has no license declared
Component "debian/libnsl-dev" has no license declared
Component "debian/libnsl2" has no license declared
Component "debian/libp11-kit0" has no license declared
Component "debian/libpam-modules" has no license declared
Component "debian/libpam-modules-bin" has no license declared
Component "debian/libpam-runtime" has no license declared
Component "debian/libpam0g" has no license declared
Component "debian/libpcre2-8-0" has no license declared
Component "debian/libperl5.36" has no license declared
Component "debian/libpkgconf3" has no license declared
Component "debian/libproc2-0" has no license declared
Component "debian/libpsl5" has no license declared
Component "debian/libpython3-stdlib" has no license declared
Component "debian/libpython3.11-minimal" has no license declared
Component "debian/libpython3.11-stdlib" has no license declared
Component "debian/libquadmath0" has no license declared
Component "debian/libreadline8" has no license declared
Component "debian/librtmp1" has no license declared
Component "debian/libsasl2-2" has no license declared
Component "debian/libsasl2-modules-db" has no license declared
Component "debian/libseccomp2" has no license declared
Component "debian/libselinux1" has no license declared
Component "debian/libsemanage-common" has no license declared
Component "debian/libsemanage2" has no license declared
Component "debian/libsepol2" has no license declared
Component "debian/libserf-1-1" has no license declared
Component "debian/libsmartcols1" has no license declared
Component "debian/libsqlite3-0" has no license declared
Component "debian/libss2" has no license declared
Component "debian/libssh2-1" has no license declared
Component "debian/libssl3" has no license declared
Component "debian/libstdc++-12-dev" has no license declared
Component "debian/libstdc++6" has no license declared
Component "debian/libsvn1" has no license declared
Component "debian/libsystemd0" has no license declared
Component "debian/libtasn1-6" has no license declared
Component "debian/libtinfo6" has no license declared
Component "debian/libtirpc-common" has no license declared
Component "debian/libtirpc-dev" has no license declared
Component "debian/libtirpc3" has no license declared
Component "debian/libtsan2" has no license declared
Component "debian/libubsan1" has no license declared
Component "debian/libudev1" has no license declared
Component "debian/libunistring2" has no license declared
Component "debian/libutf8proc2" has no license declared
Component "debian/libuuid1" has no license declared
Component "debian/libxxhash0" has no license declared
Component "debian/libzstd1" has no license declared
Component "debian/linux-libc-dev" has no license declared
Component "debian/login" has no license declared
Component "debian/logsave" has no license declared
Component "debian/make" has no license declared
Component "debian/mawk" has no license declared
Component "debian/media-types" has no license declared
Component "debian/mercurial" has no license declared
Component "debian/mercurial-common" has no license declared
Component "debian/mount" has no license declared
Component "debian/ncurses-base" has no license declared
Component "debian/ncurses-bin" has no license declared
Component "debian/netbase" has no license declared
Component "debian/nettle" has no license declared
Component "debian/openssh-client" has no license declared
Component "debian/openssl" has no license declared
Component "debian/passwd" has no license declared
Component "debian/perl" has no license declared
Component "debian/perl-base" has no license declared
Component "debian/perl-modules-5.36" has no license declared
Component "debian/pinentry-curses" has no license declared
Component "debian/pkg-config" has no license declared
Component "debian/pkgconf" has no license declared
Component "debian/pkgconf-bin" has no license declared
Component "debian/procps" has no license declared
Component "debian/python3" has no license declared
Component "debian/python3-minimal" has no license declared
Component "debian/python3.11" has no license declared
Component "debian/python3.11-minimal" has no license declared
Component "debian/readline" has no license declared
Component "debian/readline-common" has no license declared
Component "debian/rpcsvc-proto" has no license declared
Component "debian/sed" has no license declared
Component "debian/sensible-utils" has no license declared
Component "debian/sq" has no license declared
Component "debian/subversion" has no license declared
Component "debian/systemd" has no license declared
Component "debian/sysvinit-utils" has no license declared
Component "debian/tar" has no license declared
Component "debian/tzdata" has no license declared
Component "debian/ucf" has no license declared
Component "debian/usr-is-merged" has no license declared
Component "debian/util-linux" has no license declared
Component "debian/util-linux-extra" has no license declared
Component "debian/wget" has no license declared
Component "debian/zlib1g" has no license declared
Component "github.com/l3montree-dev/devguard-action" has no license declared

Status

Evaluation result after comparing the policy with the current state of the asset
212 Violations

Update the attestation using the following command
devguard-scanner attest --predicateType "https://cyclonedx.org/bom" <json file>
Copyright © 2025 L3montree GmbH and the DevGuard Contributors. All rights reserved. Version d51ba4d3f2ef56cdcc49e35bed410d86e1263d7a