wolfi-dev / wolfictl

A CLI used to work with the Wolfi OSS project
Apache License 2.0
53 stars 53 forks source link

What is the license of the wolfi and chainguard secdb? #680

Open pombredanne opened 6 months ago

pombredanne commented 6 months ago

I could not find any license information for the secdb data for wolfi and chainguard. Can you clarify what would be the license? These are the data published at:

I need a license to integrate this in https://github.com/nexb/vulnerablecode

For reference, the Alpine secdb has a license at https://secdb.alpinelinux.org/license.txt Something similar would be awesome! Thanks

PS: I am not sure if this issue should be filed only here, or at https://github.com/chainguard-dev/vulnerability-scanner-support/ or should be split in two? Please advise!

pombredanne commented 3 weeks ago

@luhring gentle ping. Without a proper license, there is no way this data can be reused. Alpine's secdb CC-BY-SA is a fine license and would likely apply if any of these advisories is derived from Alpine's db.

luhring commented 3 weeks ago

Thanks for the poke, @pombredanne! I'll get you an answer shortly. 🙇

luhring commented 3 weeks ago

We've updated our documentation for the feeds to clarify the license for them: Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International (CC BY-NC-ND 4.0).

Does this help?