|
2 | 2 |
|
3 | 3 | Use AboutCode to create SBOMs for your products |
4 | 4 | =============================================== |
5 | | - |
6 | | -You can use **ScanCode.io** to create SBOMs for your products. ScanCode.io will |
7 | | -identify all the licenses associated with your codebase resources, highlighting the ones |
8 | | -that need attention based on your policies. You can also use ScanCode.io to identify |
9 | | -software vulnerabilities. |
10 | | - |
11 | | -You can also use **DejaCode** to create SBOMs for your products. Dejacode will enable |
12 | | -you to review your product inventories, assert license conclusions, and record your |
13 | | -analysis and actions related to any licenses that require attention. You can also |
14 | | -record your analysis and actions related to any software vulnerabilities that you |
15 | | -have discovered. |
| 5 | +You can use **ScanCode.io** to create an SBOM from a scanned package, codebase or |
| 6 | +product. ScanCode.io will identify all the licenses associated with the scanned object, |
| 7 | +highlighting the licenses that need attention based on your policies. You can also use |
| 8 | +ScanCode.io to identify software vulnerabilities. With its library of standard and |
| 9 | +custom pipelines, ScanCode.io performs a deep and comprehensive scanning to meet your |
| 10 | +analysis requirements. |
| 11 | + |
| 12 | +If you need to edit the results of a scan, **Dejacode** will enable you to import those |
| 13 | +results into a product, review your product inventories, assert license conclusions, |
| 14 | +and record your analysis and actions related to any licenses that require attention. |
| 15 | +You can also record your analysis and actions related to any software vulnerabilities |
| 16 | +that have been discovered. You can then use DejaCode to create SBOMs for your products. |
16 | 17 |
|
17 | 18 | 1. Install AboutCode Projects |
18 | 19 | ----------------------------- |
@@ -64,26 +65,32 @@ https://dejacode.readthedocs.io/en/latest/dataspace.html#enable-vulnerablecodedb |
64 | 65 | to integrate with the public version at https://public.vulnerablecode.io/ |
65 | 66 |
|
66 | 67 |
|
67 | | -2. Scan your codebases using ScanCode.io |
68 | | ----------------------------------------- |
| 68 | +2. Scan software using ScanCode.io |
| 69 | +---------------------------------- |
69 | 70 |
|
70 | | -Create new Projects in ScanCode.io to scan your codebases. |
| 71 | +Create new Projects in ScanCode.io to scan packages, codebases, or products. You can |
| 72 | +also load inventories (scan results) created by ScanCode-Toolkit. You can specify |
| 73 | +the exact pipelines to use for particular platforms and technologies. |
71 | 74 |
|
72 | 75 | https://scancodeio.readthedocs.io/en/latest/user-interface.html#creating-a-new-project |
73 | 76 |
|
74 | | -Export the results in the appropriate format to share with your team. |
| 77 | +Export the scan results in the appropriate format to share with your team. ScanCode.io |
| 78 | +will report details of the identified packages if you choose to export SBOMs. |
75 | 79 |
|
76 | 80 | https://scancodeio.readthedocs.io/en/latest/output-files.html#output-files |
77 | 81 |
|
78 | 82 |
|
79 | 83 | 3. Import scan results to DejaCode products |
80 | 84 | ------------------------------------------- |
81 | 85 |
|
82 | | -Create new Products in DejaCode for comprehensive analysis and action. |
| 86 | +Create new Products in DejaCode for comprehensive analysis and action. DejaCode allows |
| 87 | +you and your team members to edit a Product inventory as needed to assert license |
| 88 | +choices and conclusions, and to document your vulnerability status. |
83 | 89 |
|
84 | 90 | https://dejacode.readthedocs.io/en/latest/tutorial-1.html |
85 | 91 |
|
86 | | -Generate Attribution and SBOMs from DejaCode Products. |
| 92 | +Generate Attribution and SBOMs from DejaCode Products. You can generate SBOMs in both |
| 93 | +SPDX and CycloneDX (inlucing VEX) formats. |
87 | 94 |
|
88 | 95 | https://dejacode.readthedocs.io/en/latest/tutorial-5-sboms.html#tutorial-5-working-with-sboms-in-a-product |
89 | 96 |
|
0 commit comments