Skip to content

Add scanoss logging to the repo. - #477

Open
arav-agarwal2 wants to merge 1 commit into
masterfrom
feat/scanoss
Open

arav-agarwal2 wants to merge 1 commit into
masterfrom
feat/scanoss

Conversation

@arav-agarwal2

Copy link
Copy Markdown
Contributor

Hello folks! As part of AI-code policy changes at MLC, we're trying to role out AI-generated code checks to catch if licensed code from bad licenses end up in the codebase.

This PR adds a SCANOSS license & BOM check that runs after merge to master (and on manual dispatch). It's informational only and never blocks.

  • .github/workflows/scanoss.yml: scans only the files changed in the pushed range (before..sha), not the whole tree, using scanoss-py against api.osskb.org. It then:
    • converts the results to a CycloneDX BOM
    • runs the copyleft and undeclared-component inspections (these steps use continue-on-error)
    • writes a report to the run's Summary: a file → component / match % / license table that flags copyleft, non-commercial, or non-permissive licenses, plus the remaining per-key osskb quota when SCANOSS_API_KEY is set
    • uploads everything in scanoss-reports/ as an artifact that's kept for 30 days
  • .github/scanoss.json: scan settings that skip tests, vendored and third-party dirs, node_modules, and generated protobuf files, and declare pkg:github/mlcommons/mobile_app_open in the BOM.

@arav-agarwal2
arav-agarwal2 requested review from a team as code owners September 29, 2026 16:31
@github-actions

Copy link
Copy Markdown

MLCommons CLA bot All contributors have signed the MLCommons CLA ✍️ ✅

@ShriyaRishab

Copy link
Copy Markdown
Contributor

@arav-agarwal2 thanks for sharing this. We'll review it in the Training WG and provide feedback.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants