Scan code for origin, license and vulnerabilities

Technologies
python, javascript, Django+PostgreSQL, C/Rust/Go
Topics
dependencies, vulnerabilities, SoftwareCompositionAnalysis, License, SBOM
Scan code for origin, license and vulnerabilities
AboutCode.org is a community of open source developers who are trying to make open source easier to use by providing open source tools to discover, identify and track open source components (aka. Software Composition Analysis – SCA). This includes tools, data and standards for code origin, FOSS licenses and security vulnerabilities.

Projects

Contributor
Keshav Priyadarshi
Mentor
TG1999, Hritik V, Shivam Sandbhor
Organization
AboutCode
Cross-validate vulnerability coverage of VulnerableCode. VulnTotal Project!
VulnerableCode is a unique project that collates FOSS vulnerability data from numerous sources. This VulnTotal project will help cross-validate the...
Contributor
Kevin Ji
Mentor
Philippe Ombredanne, ayansinha, Jonathan Yang
Organization
AboutCode
Extending license detection to use licenses external to ScanCode Toolkit
When doing license detection, ScanCode uses the licenses and rules in the ScanCode LicenseDB. The goal of this project is to extend the capabilities...
Contributor
lf32
Mentor
Philippe Ombredanne, ayansinha, AvishrantSh, Thomas Druez
Organization
AboutCode
Scancode.io/Scancode Toolkit: Create web application to scan and review a single license text
Create a web app and JSON Rest API to detect any text for license, and submit bugs (SCTK-aaS). This project is to create a web-based mini application...
Contributor
Omkar Phansopkar
Mentor
Philippe Ombredanne, Steven Esser, TG1999, AvishrantSh
Organization
AboutCode
Scancode Workbench improvements
Refactor workbench to a React + Typescript implementation and improve various sections of the application including Table view, file uploads, data...
Contributor
ziad hany
Mentor
TG1999, Hritik V, Shivam Sandbhor
Organization
AboutCode
Add more data sources and mine the graph to find correlations between vulnerabilities
There is a large number of pending tickets for data sources. We want to search for more vulnerability data sources and consume them . So I will...