cap-java / cds-feature-attachments

Support for attachments
Apache License 2.0
1 stars 1 forks source link

License risks in blackduck scans #281

Open yashmeet29 opened 1 week ago

yashmeet29 commented 1 week ago

Hi colleagues, I was checking blackduck scan for SDM plugin & I see below mentioned License risks coming from libraries being used in cds-feature-attachments. All of these being Transitive dependencies.

Blackduck dashboard URL: dashboard

Attaching the screenshots from scan dashboard below:

Screenshot 2024-11-19 at 4 39 10 PM Screenshot 2024-11-19 at 4 39 21 PM Screenshot 2024-11-19 at 4 39 27 PM Screenshot 2024-11-19 at 4 42 07 PM
mofterdinger commented 1 week ago

3 medium severity License risks in "cds4j:jdbc-spi", "CDS Services Implementation" & "CDS Services Utils" libraries.

This library is provided by CAP Java (SAP itself), so I don't see a license issue here. Looks like blackduck is not aware of this.

1 low severity License risks in jms library.

What is the issue with this library ? I don't find any information in the provided screenshot. Can you provide more details about the license issue you got from blackjack.

yashmeet29 commented 1 week ago

Hi Markus, I have added you to the blackduck dashboard portal. You can check here

yashmeet29 commented 1 week ago

@mofterdinger Any update on this?

mofterdinger commented 1 week ago

Still waiting for your answer to my question:

What is the issue with this library ? I don't find any information in the provided screenshot. Can you provide more details about the license issue you got from blackjack.

I'm not an expert for license issues. If you think there is something wrong I need to know how it can be fixed.

Thanks, Markus

yashmeet29 commented 1 week ago

I added you onto the dashboard here. You can check there as well. Also, I am attaching the screenshots from the portal. Looks like there is some issue with the license of these libraries.

Screenshot 2024-11-22 at 3 38 42 PM Screenshot 2024-11-22 at 3 38 28 PM Screenshot 2024-11-22 at 3 38 15 PM Screenshot 2024-11-22 at 3 36 10 PM
mofterdinger commented 1 week ago

@michael-hellenschmidt Hi Michael, can you please have a look at these blackduck issues from the SDM colleagues ?

Thanks, Markus