anchore / grant

Search an SBOM for licenses and the packages they belong to
Apache License 2.0
64 stars 5 forks source link

default licenses policy #50

Closed tomerse-sg closed 7 months ago

tomerse-sg commented 7 months ago

Hi,

Is it planned to provide a default set of policies for licenses? currently today if a user runs grant he can see all of the licenses, but it will pass. might be useful to provide a default (basic) set of rules which will check for common use-cases (like *GPL).

Thanks for your time!

spiffcs commented 7 months ago

That's interesting - let me check this again. The default should be that there is a failure and the default is deny all.