Aman-Mittal commented on PR #5932:
URL: https://github.com/apache/fineract/pull/5932#issuecomment-4621278835

   > Sometimes the versions prevents to use a non Apache License compliance 
library. How this change prevents it?
   
   @IOhacker It does not address that, however for your question prevention for 
non compliant library we need to create a new check 
   
   Create SBOM via cycloneDX (Dependency is already here in project) and the 
write a custom script which will then flag category X dependency) hope this 
helps. As RAT check do not seem to scan external dependencies. 


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to