:mag: ScanCode detects licenses, copyrights, dependencies by "scanning code" ... to discover and inventory open source and third-party packages used in your code. Sponsored by NLnet project https://nlnet.nl/project/vulnerabilitydatabase, the Google Summer of Code, Azure credits, nexB and others generous sponsors!

copyright copyright-scan cyclonedx dependencies dependency-graph license license-checking license-scan licensing open-source-licensing oss-compliance package-url packages provenance purl sbom sca software-composition-analysis spdx spdx-licenses
1 Open Issue Need Help Last updated: Jul 29, 2025

Open Issues Need Help

View All on GitHub
Parse npmrc about 1 month ago

AI Summary: The task is to enhance the ScanCode toolkit to parse `.npmrc` files, leveraging the information provided in the npmjs documentation to extract relevant configuration data about npm registries and authentication. This will improve ScanCode's ability to analyze JavaScript projects by providing a more complete picture of their dependencies and configurations.

Complexity: 4/5
new feature easy good first issue package-formats

:mag: ScanCode detects licenses, copyrights, dependencies by "scanning code" ... to discover and inventory open source and third-party packages used in your code. Sponsored by NLnet project https://nlnet.nl/project/vulnerabilitydatabase, the Google Summer of Code, Azure credits, nexB and others generous sponsors!

Python
#copyright#copyright-scan#cyclonedx#dependencies#dependency-graph#license#license-checking#license-scan#licensing#open-source-licensing#oss-compliance#package-url#packages#provenance#purl#sbom#sca#software-composition-analysis#spdx#spdx-licenses