Only OSI approved licenses
This policy checks if there is no violation against the license allow list.
Control evaluation result
Component "/stdlib" has no license declared
Component "/tmp" has no license declared
Component "debian/acl" has no license declared
Component "debian/adduser" has no license declared
Component "debian/apr" has no license declared
Component "debian/apr-util" has no license declared
Component "debian/apt" has no license declared
Component "debian/base-files" has no license declared
Component "debian/base-passwd" has no license declared
Component "debian/bash" has no license declared
Component "debian/binutils" has no license declared
Component "debian/bsdutils" has no license declared
Component "debian/ca-certificates" has no license declared
Component "debian/cdebconf" has no license declared
Component "debian/coreutils" has no license declared
Component "debian/cpp" has no license declared
Component "debian/curl" has no license declared
Component "debian/dash" has no license declared
Component "debian/debconf" has no license declared
Component "debian/debian-archive-keyring" has no license declared
Component "debian/debianutils" has no license declared
Component "debian/diffutils" has no license declared
Component "debian/dpkg" has no license declared
Component "debian/e2fsprogs" has no license declared
Component "debian/findutils" has no license declared
Component "debian/g++" has no license declared
Component "debian/g++-12" has no license declared
Component "debian/gcc" has no license declared
Component "debian/gcc-12" has no license declared
Component "debian/gdbm" has no license declared
Component "debian/git" has no license declared
Component "debian/git-man" has no license declared
Component "debian/gnupg2" has no license declared
Component "debian/grep" has no license declared
Component "debian/gzip" has no license declared
Component "debian/hostname" has no license declared
Component "debian/init-system-helpers" has no license declared
Component "debian/isl" has no license declared
Component "debian/jansson" has no license declared
Component "debian/keyutils" has no license declared
Component "debian/libassuan" has no license declared
Component "debian/libattr1" has no license declared
Component "debian/libaudit-common" has no license declared
Component "debian/libaudit1" has no license declared
Component "debian/libblkid1" has no license declared
Component "debian/libbrotli1" has no license declared
Component "debian/libbsd" has no license declared
Component "debian/libbz2-1.0" has no license declared
Component "debian/libc-bin" has no license declared
Component "debian/libc-dev-bin" has no license declared
Component "debian/libc6" has no license declared
Component "debian/libc6-dev" has no license declared
Component "debian/libcap-ng0" has no license declared
Component "debian/libcap2" has no license declared
Component "debian/libcbor0.8" has no license declared
Component "debian/libcrypt-dev" has no license declared
Component "debian/libcrypt1" has no license declared
Component "debian/libcurl3-gnutls" has no license declared
Component "debian/libcurl4" has no license declared
Component "debian/libdb5.3" has no license declared
Component "debian/libedit" has no license declared
Component "debian/liberror-perl" has no license declared
Component "debian/libexpat1" has no license declared
Component "debian/libffi" has no license declared
Component "debian/libfido2-1" has no license declared
Component "debian/libgcrypt20" has no license declared
Component "debian/libgmp10" has no license declared
Component "debian/libgnutls30" has no license declared
Component "debian/libgpg-error" has no license declared
Component "debian/libgssapi-krb5-2" has no license declared
Component "debian/libidn2-0" has no license declared
Component "debian/libk5crypto3" has no license declared
Component "debian/libkrb5-3" has no license declared
Component "debian/libkrb5support0" has no license declared
Component "debian/libksba" has no license declared
Component "debian/libldap-2.5-0" has no license declared
Component "debian/libmd" has no license declared
Component "debian/libmount1" has no license declared
Component "debian/libnghttp2-14" has no license declared
Component "debian/libnsl" has no license declared
Component "debian/libpam-modules" has no license declared
Component "debian/libpam-modules-bin" has no license declared
Component "debian/libpam-runtime" has no license declared
Component "debian/libpam0g" has no license declared
Component "debian/libperl5.36" has no license declared
Component "debian/libproc2-0" has no license declared
Component "debian/libpsl" has no license declared
Component "debian/libpython3-stdlib" has no license declared
Component "debian/libpython3.11-minimal" has no license declared
Component "debian/libpython3.11-stdlib" has no license declared
Component "debian/librtmp1" has no license declared
Component "debian/libsasl2-2" has no license declared
Component "debian/libsasl2-modules-db" has no license declared
Component "debian/libseccomp2" has no license declared
Component "debian/libselinux1" has no license declared
Component "debian/libsemanage" has no license declared
Component "debian/libsemanage2" has no license declared
Component "debian/libsepol" has no license declared
Component "debian/libsmartcols1" has no license declared
Component "debian/libssh2-1" has no license declared
Component "debian/libstdc++-12-dev" has no license declared
Component "debian/libstdc++6" has no license declared
Component "debian/libsvn1" has no license declared
Component "debian/libtasn1-6" has no license declared
Component "debian/libtirpc-common" has no license declared
Component "debian/libtirpc-dev" has no license declared
Component "debian/libtirpc3" has no license declared
Component "debian/libunistring" has no license declared
Component "debian/libuuid1" has no license declared
Component "debian/libzstd1" has no license declared
Component "debian/linux-libc-dev" has no license declared
Component "debian/login" has no license declared
Component "debian/lz4" has no license declared
Component "debian/make-dfsg" has no license declared
Component "debian/mawk" has no license declared
Component "debian/media-types" has no license declared
Component "debian/mercurial" has no license declared
Component "debian/mount" has no license declared
Component "debian/mpclib3" has no license declared
Component "debian/mpfr4" has no license declared
Component "debian/ncurses" has no license declared
Component "debian/netbase" has no license declared
Component "debian/nettle" has no license declared
Component "debian/npth" has no license declared
Component "debian/openssh-client" has no license declared
Component "debian/openssl" has no license declared
Component "debian/p11-kit" has no license declared
Component "debian/passwd" has no license declared
Component "debian/pcre2" has no license declared
Component "debian/perl" has no license declared
Component "debian/perl-base" has no license declared
Component "debian/perl-modules-5.36" has no license declared
Component "debian/pinentry" has no license declared
Component "debian/pkgconf" has no license declared
Component "debian/procps" has no license declared
Component "debian/python3" has no license declared
Component "debian/python3-minimal" has no license declared
Component "debian/python3.11" has no license declared
Component "debian/python3.11-minimal" has no license declared
Component "debian/readline" has no license declared
Component "debian/rpcsvc-proto" has no license declared
Component "debian/sed" has no license declared
Component "debian/sensible-utils" has no license declared
Component "debian/serf" has no license declared
Component "debian/sq" has no license declared
Component "debian/sqlite3" has no license declared
Component "debian/subversion" has no license declared
Component "debian/systemd" has no license declared
Component "debian/sysvinit" has no license declared
Component "debian/tar" has no license declared
Component "debian/tzdata" has no license declared
Component "debian/ucf" has no license declared
Component "debian/usrmerge" has no license declared
Component "debian/utf8proc" has no license declared
Component "debian/util-linux" has no license declared
Component "debian/util-linux-extra" has no license declared
Component "debian/wget" has no license declared
Component "debian/xxhash" has no license declared
Component "debian/xz-utils" has no license declared
Component "debian/zlib1g" has no license declared
Status
Evaluation result after comparing the policy with the current state of the asset
160 Violations
Update the attestation using the following command
devguard-scanner attest --predicateType "https://cyclonedx.org/bom" <json file>