Skip to content

Missing License Info in SBOMs #8083

Closed Answered by DmitriyLewen
tetzla asked this question in Q&A
Discussion options

You must be logged in to vote

Issue about licenses for jar files - #4734

since these archives usually contain a pom file.

This is not always correct.

  1. IIUC JAR files built with gradle may not have POM files
  2. The license from the POM file may be overwritten during the build of the JAR file.

Replies: 3 comments 1 reply

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
1 reply
@DmitriyLewen
Comment options

Answer selected by tetzla
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
triage/support Indicates an issue that is a support question. scan/license Issues relating to license scanning
2 participants