Module continuous_delivery_scripts.report_third_party_ip
Script providing information about licensing and third party IP in order to comply with OpenChain.
The current script uses the SDK provided by the SPDX organisation (i.e. https://github.com/spdx/tools-python). This SDK only supports version 1.2 of the specification and not 2.1. Therefore, some changes will have to be carried out when the later version is supported so that third-party IP gets documented as described by the specification (i.e. with relationships).
Functions
def generate_spdx_project_reports(project: SpdxProject, output_directory: pathlib.Path) ‑> SpdxProject-
Expand source code
def generate_spdx_project_reports(project: "SpdxProject", output_directory: Path) -> "SpdxProject": """Generates all the SPDX reports for a given project.""" logger.info("Generating SPDX report.") project.generate_tag_value_files(output_directory) logger.info("Generating licensing summary.") project.generate_licensing_summary(output_directory) return projectGenerates all the SPDX reports for a given project.
def generate_spdx_reports(output_directory: pathlib.Path,
lookup_scancode: bool = False,
skip_dependency_download: bool = False) ‑> SpdxProject | None-
Expand source code
def generate_spdx_reports( output_directory: Path, lookup_scancode: bool = False, skip_dependency_download: bool = False ) -> Optional["SpdxProject"]: """Generates all the SPDX reports for the current project.""" project = get_language_specifics().get_current_spdx_project(skip_dependency_download=skip_dependency_download) if not project: return None if lookup_scancode: project.enable_scancode_lookup() return generate_spdx_project_reports(project, output_directory)Generates all the SPDX reports for the current project.
def main() ‑> int-
Expand source code
def main() -> int: """Script CLI.""" parser = argparse.ArgumentParser(description="Generate licence and third-party IP reports.") def convert_to_path(arg: Any) -> Path: """Converts argument to a path.""" return Path(arg) parser.add_argument( "-o", "--output-dir", help="Output directory where the files are generated", required=True, type=convert_to_path, ) parser.add_argument( "--lookup-scancode", action="store_true", help="Consult ScanCode LicenseDB for unclassified licences or missing assessment rules.", ) parser.add_argument( "--skip-dependency-download", action="store_true", help="Skip automatic dependency downloads before licence checks and SPDX dependency analysis.", ) parser.add_argument( "-v", "--verbose", action="count", default=0, help="Verbosity, by default errors are reported.", ) args = parser.parse_args() set_log_level(args.verbose) try: if get_language_specifics().can_get_project_metadata(): project = generate_spdx_reports( args.output_dir, lookup_scancode=args.lookup_scancode, skip_dependency_download=args.skip_dependency_download, ) if project: project.check_licence_compliance() if args.lookup_scancode: for warning in project.scancode_follow_up_warnings(): print(f"WARNING: {warning}", file=sys.stderr) return 0 except Exception as e: log_exception(logger, e) return 1Script CLI.