-
Notifications
You must be signed in to change notification settings - Fork 1
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[pull] master from erlang:master #256
Conversation
…2 updates Bumps the github-actions group with 2 updates in the / directory: [vmactions/freebsd-vm](https://github.com/vmactions/freebsd-vm) and [docker/login-action](https://github.com/docker/login-action). Bumps the github-actions group with 1 update in the /.github/actions/build-base-image directory: [docker/login-action](https://github.com/docker/login-action). Updates `vmactions/freebsd-vm` from 1.1.8 to 1.1.9 - [Release notes](https://github.com/vmactions/freebsd-vm/releases) - [Commits](vmactions/freebsd-vm@848dac7...8873d98) Updates `docker/login-action` from 3.3.0 to 3.4.0 - [Release notes](https://github.com/docker/login-action/releases) - [Commits](docker/login-action@9780b0c...74a5d14) Updates `docker/login-action` from 3.3.0 to 3.4.0 - [Release notes](https://github.com/docker/login-action/releases) - [Commits](docker/login-action@9780b0c...74a5d14) --- updated-dependencies: - dependency-name: vmactions/freebsd-vm dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: docker/login-action dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: docker/login-action dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions ... Signed-off-by: dependabot[bot] <[email protected]>
…1 update Bumps the github-actions group with 1 update in the / directory: [docker/login-action](https://github.com/docker/login-action). Bumps the github-actions group with 1 update in the /.github/actions/build-base-image directory: [docker/login-action](https://github.com/docker/login-action). Updates `docker/login-action` from 3.3.0 to 3.4.0 - [Release notes](https://github.com/docker/login-action/releases) - [Commits](docker/login-action@9780b0c...74a5d14) Updates `docker/login-action` from 3.3.0 to 3.4.0 - [Release notes](https://github.com/docker/login-action/releases) - [Commits](docker/login-action@9780b0c...74a5d14) --- updated-dependencies: - dependency-name: docker/login-action dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: docker/login-action dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions ... Signed-off-by: dependabot[bot] <[email protected]>
…1 update Bumps the github-actions group with 1 update in the / directory: [docker/login-action](https://github.com/docker/login-action). Bumps the github-actions group with 1 update in the /.github/actions/build-base-image directory: [docker/login-action](https://github.com/docker/login-action). Updates `docker/login-action` from 3.3.0 to 3.4.0 - [Release notes](https://github.com/docker/login-action/releases) - [Commits](docker/login-action@9780b0c...74a5d14) Updates `docker/login-action` from 3.3.0 to 3.4.0 - [Release notes](https://github.com/docker/login-action/releases) - [Commits](docker/login-action@9780b0c...74a5d14) --- updated-dependencies: - dependency-name: docker/login-action dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: docker/login-action dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions ... Signed-off-by: dependabot[bot] <[email protected]>
…1 update Bumps the github-actions group with 1 update in the / directory: [docker/login-action](https://github.com/docker/login-action). Bumps the github-actions group with 1 update in the /.github/actions/build-base-image directory: [docker/login-action](https://github.com/docker/login-action). Updates `docker/login-action` from 3.3.0 to 3.4.0 - [Release notes](https://github.com/docker/login-action/releases) - [Commits](docker/login-action@9780b0c...74a5d14) Updates `docker/login-action` from 3.3.0 to 3.4.0 - [Release notes](https://github.com/docker/login-action/releases) - [Commits](docker/login-action@9780b0c...74a5d14) --- updated-dependencies: - dependency-name: docker/login-action dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: docker/login-action dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions ... Signed-off-by: dependabot[bot] <[email protected]>
Bumps the github-actions group with 1 update in the / directory: [docker/login-action](https://github.com/docker/login-action). Updates `docker/login-action` from 3.3.0 to 3.4.0 - [Release notes](https://github.com/docker/login-action/releases) - [Commits](docker/login-action@9780b0c...74a5d14) --- updated-dependencies: - dependency-name: docker/login-action dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions ... Signed-off-by: dependabot[bot] <[email protected]>
When scanning code for licenses, we now also include data from `reuse lint` into the results. This allows us to have more consistent results as reuse scanning is predictable in a way that scancode is not. We still keep scancode as it can find licenses in files that do not yet use the `reuse` standard.
gh: Use data from reuse lint when scanning code
…ec7' * dependabot/github_actions/master/github-actions-38de97dec7: build(deps): bump the github-actions group across 2 directories with 2 updates
…9e' into maint * dependabot/github_actions/maint/github-actions-f5ea2a649e: build(deps): bump the github-actions group across 2 directories with 1 update
…a649e' into maint-26 * dependabot/github_actions/maint-26/github-actions-f5ea2a649e: build(deps): bump the github-actions group across 2 directories with 1 update
…a649e' into maint-27 * dependabot/github_actions/maint-27/github-actions-f5ea2a649e: build(deps): bump the github-actions group across 2 directories with 1 update
…f65df' into maint-25 * dependabot/github_actions/maint-25/github-actions-ffdcbf65df: build(deps): bump docker/login-action
Reviewer's Guide by SourceryThis pull request introduces significant changes to the build and compliance workflows. It integrates OSS Review Toolkit (ORT) for enhanced license scanning and reporting, updates Docker configurations, and refactors scanning logic into a dedicated script. The changes aim to improve the accuracy and efficiency of license detection and ensure compliance with licensing requirements. Sequence diagram for OSS Review Toolkit (scanner) with cachesequenceDiagram
participant GHA as GitHub Actions
participant Docker as Docker Container
participant ORT as OSS Review Toolkit
participant Cache as Scan Result Cache
GHA->Docker: Run ORT scanner with cache
alt Cache exists
Docker->ORT: Initialize scan result from analyzer result
ORT->ORT: Restore license results from cache
ORT->ORT: Scan with ScanCode
else Cache does not exist
Docker->ORT: Initialize scan result from analyzer result
ORT->ORT: Scan with ScanCode
end
ORT->ORT: Overwrite scan results using reuse
ORT->Cache: Copy scan results to cache
GHA->GHA: Upload scan results
File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
See Commits and Changes for more details.
Created by
pull[bot] (v2.0.0-alpha.1)
Can you help keep this open source service alive? 💖 Please sponsor : )
Summary by Sourcery
Updates the CI workflow to use the OSS Review Toolkit (ORT) scanner and reporter for license and copyright detection. The changes include improvements to caching, the introduction of a REUSE tool for license compliance, and modifications to the scanning process to enhance accuracy and efficiency.
CI: