anchore / grant

Search an SBOM for licenses and the packages they belong to
Apache License 2.0
64 stars 5 forks source link

feature: source content measured against true license text #44

Open spiffcs opened 7 months ago

spiffcs commented 7 months ago

Whenever possible grant should attempt to obtain the originally analyzed license text and compare it to the official OSI license text. This can surface any changes made by the software publisher to the original text and allow the user to flag on or make choices about licenses that are shown to be significantly different than what they're labeled as.