Get the latest tech news
Open source projects could sell SBOM fragments
Scanning source files for licensing information (because the package managers‘ metadata is insufficient) is a lot of work, and a lot of wasted effort, becaus...
Scanning source files for licensing information (because the package managers‘ metadata is insufficient) is a lot of work, and a lot of wasted effort, because only rarely do companies pool their resources. One example is OSSelot, another is ClearlyDefined. "Instead of scanning for copyright notices and license texts yourself, just sponsor us on GitHub and get access to always up-to-date SBOM information by the people who really know what‘s inside".
Or read this on Hacker News