Managing Compliance Licenses

JFrog Security Documentation

ft:sourceType
Paligo

Overview

JFrog Xray's License Management provides a comprehensive list of open-source licenses existing on the market, and provides an indication of which scanned artifacts use each license. Using Xray's License Management, you can also create custom licenses which you can assign to components at any time.

Viewing Compliance Licenses

The list of available licenses is available in the Administration module under Xray | Advanced | Manage Compliance Licenses.

manage_licenses.png

Creating and Editing Licenses

Using Manage Licenses, you can create custom licenses which can then be assigned to components. To create a custom license, click Add a License.

Field

Description

License Name

The abbreviated license name.

License Full Name

The full license name.

Description

A description of the license

References

A list of fully qualified references to components that use this license.

Aliases

A list of aliases associated with the license. An alias needs to be unique and cannot be used more than once or across licenses.

Aliases are Supported from Xray 2.10.0

The aliases will be scanned from version 2.10.0. If you want to add aliases to previous license versions, you need to reindex the relevant artifacts or repository.

Editing or Adding Aliases to a License

You can add or edit aliases to a license in the Manage Licence page.

  1. Click the Manage Aliases icon on the License row in the Manage License page.

    manage_aliases.png

    The Manage Aliases page opens.

  2. Update the alias list in the Manage Alias '<license_name>' .

    manage_aliases_dialog.png
  3. Click Save.