Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Enabled Snyk on collector, collector contrib, and collector releases #2228

Closed
austinlparker opened this issue Jul 19, 2024 · 6 comments
Closed
Labels
area/repo-maintenance Maintenance of repos in the open-telemetry org

Comments

@austinlparker
Copy link
Member

Documenting that the Snyk integration (thru CNCF) has been enabled on collector repositories per @jpkrohling.

@austinlparker austinlparker added the area/repo-maintenance Maintenance of repos in the open-telemetry org label Jul 19, 2024
@codeboten
Copy link
Contributor

Just a follow up on this, what's the requirements around the license check for snyk? We have the license check failing on MPL license in open-telemetry/opentelemetry-collector-contrib#34199

@evan-bradley
Copy link
Contributor

@austinlparker @jpkrohling Could the maintainers of each Collector repo the integration runs on be given access to the corresponding dashboard? Right now it runs on PRs, and it would be nice to know why a particular PR causes a failure.

@trask
Copy link
Member

trask commented Jul 22, 2024

Just a follow up on this, what's the requirements around the license check for snyk? We have the license check failing on MPL license in open-telemetry/opentelemetry-collector-contrib#34199

check out https://github.com/cncf/foundation/blob/main/allowed-third-party-license-policy.md#cncf-allowlist-license-policy

(we have a somewhat similar issue in Java instrumentation: open-telemetry/opentelemetry-java-instrumentation#10705 (comment))

@codeboten
Copy link
Contributor

thanks @trask, have you applied for an exception?

@trask
Copy link
Member

trask commented Aug 12, 2024

hey @codeboten, no I haven't, it looks like we need to open an issue similar to these: https://github.com/cncf/foundation/issues?q=is%3Aissue+is%3Aopen+label%3Alicensing

@jpkrohling
Copy link
Member

@evan-bradley , absolutely! To maintainers reading this: just ping me and tell me your email addressed and I'll add you to Snyk.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
area/repo-maintenance Maintenance of repos in the open-telemetry org
Projects
None yet
Development

No branches or pull requests

5 participants