Skip to content

Add license compliance scanning#8

Merged
EdgarPsda merged 1 commit intomainfrom
v0.5.0/license-compliance
Mar 14, 2026
Merged

Add license compliance scanning#8
EdgarPsda merged 1 commit intomainfrom
v0.5.0/license-compliance

Conversation

@EdgarPsda
Copy link
Owner

Integrate license scanning via Trivy with configurable deny/allow lists in security-config.yml. Flags copyleft licenses (GPL, AGPL, LGPL) by default. Includes severity classification, fail gate threshold support, and parallel execution in the scan orchestrator.

Integrate license scanning via Trivy with configurable deny/allow lists
in security-config.yml. Flags copyleft licenses (GPL, AGPL, LGPL) by
default. Includes severity classification, fail gate threshold support,
and parallel execution in the scan orchestrator.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@EdgarPsda EdgarPsda merged commit e2d9027 into main Mar 14, 2026
1 check passed
@github-actions
Copy link

🔐 DevSecOps Kit Security Summary

  • Gitleaks: 0 leak(s)
  • Trivy FS:
    • CRITICAL: 0
    • HIGH: 0
    • MEDIUM: 0
    • LOW: 0
  • Semgrep: 0 finding(s)

Status:PASS

EdgarPsda added a commit that referenced this pull request Mar 14, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant