Skip to content

license type and severity - LGPL should not be the same category as GPL #7069

Closed Answered by knqyf263
nartreb asked this question in Q&A
Discussion options

You must be logged in to vote

Please reference the document.
https://aquasecurity.github.io/trivy/v0.53/docs/scanner/license/

As documented, the category is defined according to Google License Classification.

Also, Google has a library classifying licenses.
https://github.com/google/licenseclassifier

Our approach is defining the default category based on the library's category, and making it customizable. You can customize the categories of LGPL, WTFPL, etc.

Replies: 2 comments 3 replies

Comment options

You must be logged in to vote
0 replies
Answer selected by knqyf263
Comment options

You must be logged in to vote
3 replies
@knqyf263
Comment options

@nartreb
Comment options

@knqyf263
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
triage/support Indicates an issue that is a support question.
2 participants