Is your feature request related to a problem? Please describe.
For legal documentation, we need the original text of the licenses of components.
Describe the solution you'd like
An option to enable integration of the license-text in the BOM file, like the old @cyclonedx/bom package had, would be great to have again here.
read https://cyclonedx.org/news/cyclonedx-v1.3-released/#copyright-and-license-evidence
Acceptance criteria
- the feature to add license texts should be enabled by a CLI switch called
--gather-license-evidence (name to be discussed)
- the feature is disabled per default
- only if the feature is enabled:
- for all components, meta-components, root-components and nested components:
regardless of SPDX license ID, SPDX license expression or named license, the deteced license texts should be added, each as an evidence
Examples:
{
//...
"evidence": {
"licenses": [
{"name":"file: LICENSE", "text": {
"contentType": "text/plain",
"encoding": "base64",
// base64 of content of file `LICENSE`
"content": "bG9yZW0gaXBzdW0="
}}
{"name":"file: NOTICE", "text": {
"contentType": "text/plain",
"encoding": "base64",
// base46 of content of file `NOTICE`
"content": "bG9yZW0gaXBzdW0="
}}
]
},
// ...
}
- if a license text is detected with the package, it would be added to Component's
@.evicence.licenses
@.name would be 'License of : '
@.text would hold the test
- the content type is to be derived from file extension
- the content SHOULD be base64 encoded
- license files patterns are:
LICEN[CS]E*
NOTICE* -- addendum for Apache-2.0 and others
- if no license text is shipped with a package, no license test is added as a evidence.
Nope, no license template is derived from package's declared SPDX license id.
Reason: license templates (like BSD clause 3) are designed to be modified (unlike others, like Apache2, which is not a template but a complete text)
Is your feature request related to a problem? Please describe.
For legal documentation, we need the original text of the licenses of components.
Describe the solution you'd like
An option to enable integration of the license-text in the BOM file, like the old @cyclonedx/bom package had, would be great to have again here.
read https://cyclonedx.org/news/cyclonedx-v1.3-released/#copyright-and-license-evidence
Acceptance criteria
--gather-license-evidence(name to be discussed)regardless of SPDX license ID, SPDX license expression or named license, the deteced license texts should be added, each as an evidence
Examples:
@.evicence.licenses@.namewould be 'License of : '@.textwould hold the testLICEN[CS]E*NOTICE*-- addendum for Apache-2.0 and othersNope, no license template is derived from package's declared SPDX license id.
Reason: license templates (like BSD clause 3) are designed to be modified (unlike others, like Apache2, which is not a template but a complete text)