Open porsche-rishisaxena opened 3 years ago
Also see #3265 and #2819, FYI.
Maybe also @JeroenKnoops's BlackDuck GitHub Action is of interest in this context.
@porsche-rishisaxena Can you update this issue to make clear whether BlackDuck means Protex or Hub?
Clarified in ORT developer meeting of July 7th, 2022 - it's Black Duck Hub not the legacy Black Duck Protex IP
Hello,
We are in the process of designing a common abstraction to represent the snippets in the ORT model. This abstraction will be submitted to the ORT community. Our plan is to support FossID and SCANOSS but we would like, if possible, to support also Blackduck.
Could someone provide a sample response of Blackduck (ideally on the Semver4j project), so we can have a look at their data model for snippets ?
@nnobelis What kind of format do you require? The SPDX output?
As ORT is an orchestrator, it should allow to configure BlackDuck as scanner where code snippet can be scanned and result can be stored in ORT backend storage i.e. PostgreSQL
High Level Consideration