mirror of
https://github.com/NVIDIA/OpenShell.git
synced 2026-10-02 07:34:45 +08:00
* feat(sbom): add SBOM generation, license resolution, and CSV export tooling Add mise-integrated SBOM pipeline for container images using Syft. Includes license resolution via crates.io/npm/PyPI APIs and CycloneDX JSON to CSV conversion. Adds agent skill for on-demand SBOM operations. Closes #237 * fix(sbom): chain task dependencies to run generate → resolve → csv sequentially * fix(sbom): add concurrent license resolution, progress logging, and exclude dev artifacts * feat(notices): add mise run notices to generate THIRD-PARTY-NOTICES with full license texts Use cargo-about for Rust crate licenses and pip-licenses for Python packages. Produces a single attribution file with per-package copyright notices and full license text for open-source compliance.
28 lines
713 B
TOML
28 lines
713 B
TOML
# SPDX-FileCopyrightText: Copyright (c) 2025-2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved.
|
|
# SPDX-License-Identifier: Apache-2.0
|
|
|
|
# cargo-about configuration for generating third-party license notices.
|
|
# See https://embarkstudios.github.io/cargo-about/
|
|
|
|
# Accepted licenses (SPDX expressions). All permissive/weak-copyleft licenses
|
|
# found in this workspace's dependency tree.
|
|
accepted = [
|
|
"0BSD",
|
|
"Apache-2.0",
|
|
"Apache-2.0 WITH LLVM-exception",
|
|
"BSD-1-Clause",
|
|
"BSD-2-Clause",
|
|
"BSD-3-Clause",
|
|
"BSL-1.0",
|
|
"CC0-1.0",
|
|
"CDLA-Permissive-2.0",
|
|
"ISC",
|
|
"LGPL-2.1-or-later",
|
|
"MIT",
|
|
"MIT-0",
|
|
"OpenSSL",
|
|
"Unicode-3.0",
|
|
"Unlicense",
|
|
"Zlib",
|
|
]
|