-
Notifications
You must be signed in to change notification settings - Fork 6
Description
Happen to stumble upon the announcement of this project and wonder if the maintainers of this project are familiar with or have considered OSS Review Toolkit which offers similar functionality as this project.
ORT is a Linux Foundation project maintained by several (mostly automotive) OSPOs and one can use it to automate your FOSS policy using Policy as Code to do licensing, security vulnerabilities and engineering standards checks for your software project and its dependencies. It support detecting dependencies for ~20 different package managers out-of-the-box and is battle-tested with hundreds of thousands of scans done amongst its users over the last 6 years.
ORT users include Bosch, Deutsche Telekom, EPAM, Forvia, HERE Technologies, Porsche and recently the Eclipse foundation indicated its adopting ORT within their IP process.
Happy to do a demo/q&a call, you can reach me via opensource [at] steenbe [.nl]. Will be demo-ing ORT capabilities as part of my Nov 15, 2022 TODO OSPOLogy talk, see also https://community.linuxfoundation.org/events/details/lfhq-todo-group-presents-how-to-automate-your-foss-policy-and-processes/