Skip to content

Why not use ORT built-in SPDX report? #12

Description

I'm looking into license scanning solutions and I already found ORT as a batteries-included solution around scancode-toolkit. This repo was linked as an example for a github action, which is still a todo there.

Looking into your solution I noticed you use your own spdx-builder. Why did you choose a roll-your-own solution, rather than the built-in spdx report from ORT? Was this a timing issue that it was not yet available in ORT?

Also: thanks for developing this in public, it is an interesting solution that has some nice ideas like pushing the SPDX documents to a central repo.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions