intuit / innersource-scanner
A java api and command line tool for scanning, reporting and fixing a git repository's InnerSource Readiness based on a supplied specification which defines the files and file contents necessary for a repository to be considered ready for InnerSource contribution.
☆20Updated last year
Alternatives and similar repositories for innersource-scanner:
Users that are interested in innersource-scanner are comparing it to the libraries listed below
- Materials for the ISPO working group☆23Updated this week
- Generates SPDX bill-of-material files from a package input and license scan☆13Updated 11 months ago
- OSPO Landscape☆34Updated 3 weeks ago
- GitHub Action to get a license overview in SPDX format☆14Updated 3 years ago
- The FINOS InnerSource SIG is a community of people implementing, or interested in implementing, InnerSource within their financial servic…☆29Updated last year
- CHAOSS Value Working Group☆39Updated last month
- Documentation and guidance for handling outbound open source for organizations☆20Updated 2 years ago
- Doc, wiki and organizational content for ClearlyDefined☆94Updated 3 weeks ago
- This repo is for tracking activities that we work on during TODO Group Work Days☆15Updated 2 years ago
- Awesome InnerSource Content☆33Updated 10 months ago
- Lists all InnerSource projects of a company in an interactive and easy to use way. Can be used as a template for implementing the "InnerS…☆146Updated last week
- Automating Compliance Tooling Project☆21Updated 3 years ago
- Accelerate financial services firms’ journeys toward open source readiness, by advancing the readiness of participants’ firms and informi…☆37Updated 3 weeks ago
- This repo realizes the idea that OSS compliance activities will be less expensive by applying OSS principles☆84Updated this week
- 📖 OSPOlogy - The Study of OSPOs☆201Updated this week
- The old version of the ISC site☆41Updated 4 years ago
- opengovernance.dev☆40Updated 5 years ago
- Website for OmniBOR, reproducible identifiers & fine-grained build dependency tracking for software artifacts.☆21Updated 2 months ago
- Machine-readable specification for the attestation of security-relevant data.☆57Updated this week
- The service side of clearlydefined.io☆48Updated last week
- GitHub action to produce a SBOM report from a given Black Duck project☆12Updated 3 months ago
- QMSTR compliance tool☆32Updated 2 years ago
- ☆21Updated 4 months ago
- A collection of guidelines and resources from Citi's Open Source Program Office☆48Updated 11 months ago
- OpenSSF Endusers Working Group☆28Updated last year
- A light-weight app to audit and inventory large codebases for open source license compliance.☆61Updated this week
- A CLI tool for creating secure by design/default source repos.☆25Updated 8 months ago
- A small application which needs a better name and collects oss-license metadata and combines it☆31Updated 2 months ago
- sigstore maven plugin☆18Updated 8 months ago
- Curations and configuration files for the OSS Review Toolkit.☆18Updated last week