Skip to content

Allow configuring a proprietary non-SPDX-listed license #1038

@Clockwork-Muse

Description

@Clockwork-Muse

My company has enabled this action at the org level, which is great. However, it's throwing up warnings because of missing/unknown license files in repos. I'd like a way to configure a company-specific license to be able to quiet these warnings.

Describe the solution you'd like
Some way to configure a license "source"(s), that isn't part of the standard SPDX list, possibly as a purl reference.

Describe alternatives you've considered
While dependency licenses could be ignored via allow-dependencies-licenses, this is unwieldy at the org level, and could be quite a large list.

Additional context
The current package is a custom github action referenced from inside the same org, so a way to ignore "dependencies from this org" would also work, but only for things referenced directly (and not from larger package ecosystems, like nuget/etc).

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions