philips-software/Get SPDX license overview

Get SPDX license overview

View on GitHub

Trust Signals

Scorecard Score
Scorecard 2–4scored Jul 6, 2026
Maintenance Recency
Stalelast commit Dec 24, 2021
License
MIT

Pinned Snippet

workflow.ymlSHA-pinned
uses: philips-software/spdx-action@d3e3c46c2e1521e4b8786d8985df8a92cfc8a19f # v0.9.2

tags can be moved; commit SHAs can't. why a SHA?

namedescriptionrequireddefault
projectprojectyesspdx-builder
spdx-builder-versionspdx-builder-versionyesv0.9.2
modeScan mode. Can be 'ort', 'blackduck' or 'tree'yesort
scanner-urlscanner-url (license-scanner)no
bombase-urlbombase-url (in case of mode: 'tree')no
upload-urlupload-url (f.e. BOM-bar)no
ort-versionphilipssoftware/ort version (in case of mode: 'ort')no2021-11-24
ort-fileSpecifies an ort-file to override ORT scanning in this action. (in case of mode: 'ort')no
treefile with tree input (in case of mode: 'tree')no
formatformat input (in case of mode: 'tree')no
blackduck-urlBlackduck url (in case of mode: 'blackduck')no
blackduck-tokenBlackduck token (in case of mode: 'blackduck')no
blackduck-projectBlackduck project (in case of mode: 'blackduck')no
blackduck-versionBlackduck version (in case of mode: 'blackduck')no
optional-argumentsOptional arguments like `--tree`, `--release`, `--force` and `--custom`no
capture-stdout-fileCapture stdout in a file. When given, this will be used as the filename of the outputno
namedescription
spdx-filespdx-license file
ort-fileort-license file