Implement License Scanning SBOM scanner
Dependent MRs
-
Implement License Scanning SBOM scanner (!109447 - merged) -
👈 You are hereThis MR only tests when the
license_scanning_sbom_scanner
feature flag is set tofalse
, because in order to test when it's set totrue
, we need some of the code added by the dependent MR2.
below. See this comment for more details. -
Fetch latest license scanning build from `Licen... (!109723 - merged)
This MR tests when
license_scanning_sbom_scanner
is set totrue
.
These MRs are constructed so that they can be reviewed individually, but all the changes will be merged in the final MR. See !109447 (comment 1255025150) for more context.
What does this MR do and why?
This MR implements the following methods:
-
#report
- Fetch project dependencies for the given project or pipeline using SBOM component fetchers.
- Normalize component names, unless the SBOM component fetchers already do it. See #384932 (comment 1230139272)
- Get the licenses of package versions using another fetcher.
- Build and return a
Ci::Reports::LicenseScanning::Report
.
-
#has_data?
returns
true
if the pipeline hasSBOM
reports. -
#data_available?
returns
true
if the pipeline is complete and hasSBOM
reports.
It also adds a new license_scanning_sbom_scanner
Feature Flag. When enabled, license scanning will retrieve the components from the SBOM files, and find licenses related to the components.
Screenshots or screen recordings
Screenshots are required for UI changes, and strongly recommended for all other merge requests.
How to set up and validate locally
Numbered steps to set up and validate the change are strongly suggested.
MR acceptance checklist
This checklist encourages us to confirm any changes have been analyzed to reduce risks in quality, performance, reliability, security, and maintainability.
-
I have evaluated the MR acceptance checklist for this MR.
Related to #384932 (closed)