Goal
Turn a scan result into a pass or fail decision based on two rules:- No component may carry a licence that your organisation does not allow.
- No component may have a known vulnerability at or above a chosen severity.
When to use it
- In a pull request job, after the pull request scan.
- In a release job, before you publish an SBOM.
- In a scheduled job over a refreshed inventory, to catch vulnerabilities disclosed after release.
0 whatever it finds. It does not decide what is
allowed. This recipe writes that decision down as a script.
Prerequisites
-
scanoss-cli,
jq, andSCANOSS_API_KEY(see Recipes) -
A scan result in the raw format (the default) that includes the
licensesandvulnslayers:Adddeps(--include deps,licenses,vulns) to also check the dependencies declared in your manifest files, not only the components detected in your code. -
scanoss/unapproved.jqcommitted to the repository (see Approve components)
The script
Save this asci/scanoss-policy.sh and make it executable.
How the rules read the result
Both rules read fields of the scanoss-cli raw inventory:Adjust the licence pattern
DENY_LICENSES is a regular expression (jq test). The default ^(AGPL|GPL|SSPL)- matches
GPL-2.0-only, GPL-3.0-or-later, AGPL-3.0-only, and SSPL-1.0, but not LGPL-2.1-only.
Some examples:
Approved exceptions
If your organisation accepts a component on the deny-list for your project, approve it with abom.identify rule in scanoss.json and run the check with SKIP_IDENTIFIED=true. The
component then passes the licence rule, but the vulnerability rule still checks it. See
Approve components with scanoss.json.
What the output means
How it fails the pipeline
If the scan before it fails, scanoss-cli exits
1 and the script never runs.