From a1b9cdb8b9e4ab86cff75b5471e1455c231ff2b6 Mon Sep 17 00:00:00 2001 From: Jeffrey Sica Date: Mon, 1 Jun 2026 11:58:21 -0500 Subject: [PATCH] update license exception data Signed-off-by: Jeffrey Sica --- .../CNCF-licensing-exceptions.csv | 976 +++++----- .../cncf-exceptions-current.spdx | 1162 ++++++------ license-exceptions/exceptions.json | 1627 +++++++++++------ 3 files changed, 2107 insertions(+), 1658 deletions(-) diff --git a/license-exceptions/CNCF-licensing-exceptions.csv b/license-exceptions/CNCF-licensing-exceptions.csv index b9a9fa3f..493589d7 100644 --- a/license-exceptions/CNCF-licensing-exceptions.csv +++ b/license-exceptions/CNCF-licensing-exceptions.csv @@ -1,488 +1,488 @@ -Package or Category,License Concluded,Project,Scope,Status,Comments,Date Published,Last updated: 2026-02-04 -eclipse-ee4j/expressly,EPL-2.0 OR GPL-2.0-only WITH Classpath-exception-2.0,Keycloak,"required upstream dependency, dynamically linked, unmodified",approved,"Default implementation of Jakarta Expression Language 6.0, transitive dependency for Hibernate Validator",2026-02-05, -libpathrs,MPL-2.0 OR LGPL-3.0-or-later,All CNCF Projects,"vendored component, build-time dependency, or install-time dependency; statically or dynamically linked",approved,Blanket exception: Projects using libpathrs statically linked MUST elect MPL-2.0 and document this. Provides secure path resolution APIs.,2026-02-05, -go-pathrs,MPL-2.0,All CNCF Projects,"vendored component, build-time dependency, or install-time dependency; statically or dynamically linked",approved,Blanket exception: Go bindings for libpathrs. Provides secure path resolution APIs.,2026-02-05, -cyphar/filepath-securejoin,MPL-2.0 AND BSD-3-Clause,All CNCF Projects,"vendored component, build-time dependency, or install-time dependency; statically or dynamically linked",approved,"Blanket exception: Provides secure path resolution APIs on Linux. Used by Kubernetes, containerd, Podman, buildah, cri-o, nerdctl.",2025-11-21, -Liquibase,FSL (Functional Source License),Keycloak,"incorporated code, dynamically linked",denied,Denied: FSL is not an open source license. GB does not approve exceptions for non-OSS licenses.,2025-11-21, -paramiko,LGPL-2.1,oscal-compass,"build-time dependency, dynamically linked",approved,"Pure-Python SSHv2 protocol implementation, used for fetching files",2025-10-17, -certifi,MPL-2.0,oscal-compass,"install-time dependency, dynamically linked",approved,Dependency for requests library,2025-10-17, -pathspec,MPL-2.0,oscal-compass,"build-time dependency, separate process",approved,"Dependency for black, mkdocs, mypy",2025-10-17, -cyphar/filepath-securejoin,BSD-3-Clause AND MPL-2.0,Kubernetes,"vendored component, build-time dependency, statically linked",approved,Provides secure path construction functions. Superseded by blanket exception in issue #1154.,2025-10-17, -hashicorp/terraform-provider-aws,MPL-2.0,Crossplane,"build-time dependency, modified fork",approved,"Fork maintained for Crossplane providers, changes contributed upstream",2024-10-23, -hashicorp/terraform-provider-azurerm,MPL-2.0,Crossplane,"build-time dependency, modified fork",approved,"Fork maintained for Crossplane providers, changes contributed upstream",2024-10-23, -hashicorp/terraform-provider-azuread,MPL-2.0,Crossplane,"build-time dependency, modified fork",approved,"Fork maintained for Crossplane providers, changes contributed upstream",2024-10-23, -apple/swift-nio-ssl,OpenSSL,Connect,"build-time dependency, unmodified",approved,Required for HTTP/2 + TLS with HTTP trailers on iOS. Also used by gRPC Swift.,2024-10-23, -Crossplane Upjet MPL dependencies,MPL-2.0,Crossplane,"build-time dependency, unmodified, linked at build time",approved,"Various hashicorp terraform dependencies for Upjet: hcl, terraform-json, terraform-plugin-framework, terraform-plugin-go, terraform-plugin-sdk, go-plugin, go-uuid, go-version, logutils, terraform-plugin-log, terraform-registry-address, terraform-svchost, yamux",2024-10-23, -Linux kernel uapi headers (btrfs),GPL-2.0-only WITH Linux-syscall-note,containerd,"kernel headers included via #include, no inline functions compiled in",approved,Used by containerd/btrfs for btrfs-related ioctl syscalls. Headers from linux/btrfs.h and linux/btrfs_tree.h.,2024-10-23, -github.com/hashicorp/go-set/v2,MPL-2.0,OpenFGA,"build-time dependency, linked at build time",approved,Unmodified code,2024-10-22, -Keycloak Java dependencies,"0BSD, CDDL-1.1, EPL-1.0, EPL-2.0, GPL-2.0-only, GPL-2.0-with-classpath-exception, LGPL-2.1, LGPL-2.1-only, MIT-0, MPL-2.0, UPL-1.0",Keycloak,"transitive dependencies from Quarkus framework, unmodified",approved,"Multiple Java dependencies including: tslib, h2, mysql-connector-j, jakarta.* APIs, parsson, graalvm SDK, hibernate-*, mariadb-java-client, nashorn-core, reactive-streams",2024-10-22, -github.com/hashicorp/memberlist,MPL-2.0,kubernetes/kops,"build-time dependency, unmodified",approved,Main component of Gossip DNS feature for peer-to-peer network K8s API address propagation,2024-07-16, -Falco kernel module,GPL-2.0-only OR MIT,Falco,"kernel module, dual-licensed",approved,Falco's kernel module is dual-licensed GPL-2.0-only OR MIT,2024-02-27, -In-kernel eBPF programs,"GPL-2.0-only, GPL-2.0-or-later",All CNCF Projects,in-kernel eBPF programs only,approved,"Blanket exception: GPL-2.0 licensed code is permitted for in-kernel eBPF programs only, as this is required by the Linux kernel BPF subsystem.",2023-08-31, -github.com/docker/go-metrics,CC-BY-SA 4.0,,"runtime dependency, statically linked",approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-08-31,2023-08-31, -github.com/hashicorp/go-memdb,MPL-2.0,Cilium,"runtime dependency, dynamically linked",approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-08-31,2023-08-31, -github.com/shoenig/go-m1cpu,MPL-2.0,,build dependency,approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-08-31,2023-08-31, -hashicorp/packer-plugin-sdk,MPL-2.0,,,approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-08-31,2023-08-31, -github.com/hashicorp/consul/api,MPL-2.0,Cilium,"build-time dependency, unmodified",approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27,2023-06-27, -github.com/hashicorp/go-hclog,MPL-2.0,Cilium,"build-time dependency, unmodified",approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27,2023-06-27, -github.com/hashicorp/go-immutable-radix,MPL-2.0,Cilium,"build-time dependency, unmodified",approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27,2023-06-27, -github.com/hashicorp/go-plugin,MPL-2.0,,"build-time dependency, unmodified",approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27,2023-06-27, -github.com/hashicorp/go-rootcerts,MPL-2.0,Cilium,"build-time dependency, unmodified",approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27,2023-06-27, -github.com/hashicorp/go-secure-stdlib,MPL-2.0,,,approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27,2023-06-27, -github.com/hashicorp/go-sockaddr,MPL-2.0,,,approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27,2023-06-27, -github.com/hashicorp/go-uuid,MPL-2.0,,,approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27,2023-06-27, -github.com/hashicorp/serf,MPL-2.0,Cilium,"build-time dependency, unmodified",approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27,2023-06-27, -github.com/hashicorp/vault,MPL-2.0,,"build-time dependency, unmodified",approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27,2023-06-27, -github.com/veraison/go-cose,MPL-2.0,Notary,"build-time dependency, unmodified",approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27,2023-06-27, -hashicorp/consul/api,MPL-2.0,,,approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27,2023-06-27, -hashicorp/go-hclog,MPL-2.0,,,approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27,2023-06-27, -hashicorp/go-immutable-radix,MPL-2.0,,,approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27,2023-06-27, -hashicorp/go-plugin,MPL-2.0,,"build-time dependency, unmodified",approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27,2023-06-27, -hashicorp/go-rootcerts,MPL-2.0,,,approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27,2023-06-27, -hashicorp/go-secure-stdlib,MPL-2.0,,,approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27,2023-06-27, -hashicorp/go-sockaddr,MPL-2.0,,,approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27,2023-06-27, -hashicorp/go-uuid,MPL-2.0,,,approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27,2023-06-27, -hashicorp/go-version,MPL-2.0,,"build-time dependency, unmodified",approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27,2023-06-27, -hashicorp/raft,MPL-2.0,,,approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27,2023-06-27, -hashicorp/serf,MPL-2.0,,,approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27,2023-06-27, -hashicorp/vault,MPL-2.0,,"build-time dependency, unmodified",approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27,2023-06-27, -hashicorp/yamux,MPL-2.0,,"build-time dependency, unmodified",approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27,2023-06-27, -veraison/go-cose,MPL-2.0,Notary,"build-time dependency, unmodified",approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27,2023-06-27, -github.com/eclipse/paho.mqtt.golang,EPL-2.0,,"build-time dependency, unmodified",approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2022-04-12,2022-04-12, -github.com/hashicorp/go-version,MPL-2.0,,"build-time dependency, unmodified",approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2022-04-12,2022-04-12, -github.com/hashicorp/raft,MPL-2.0,Dapr,"build-time dependency, unmodified",approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2022-04-12,2022-04-12, -github.com/hashicorp/raft-boltdb,MPL-2.0,Dapr,"build-time dependency, unmodified",approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2022-04-12,2022-04-12, -github.com/Microsoft/tslib,0BSD,,"build-time dependency, unmodified",approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2022-04-12,2022-04-12, -go-version,MPL-2.0,,"build-time dependency, unmodified",approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2022-04-12,2022-04-12, -paho.mqtt.golang,EPL-2.0,,"build-time dependency, unmodified",approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2022-04-12,2022-04-12, -raft,MPL-2.0,Dapr,"build-time dependency, unmodified",approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2022-04-12,2022-04-12, -raft-boltdb,MPL-2.0,Dapr,"build-time dependency, unmodified",approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2022-04-12,2022-04-12, -tslib,0BSD,,"build-time dependency, unmodified",approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2022-04-12,2022-04-12, -webpki-roots,MPL-2.0,,"build-time dependency, unmodified",approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2022-04-12,2022-04-12, -github.com/hashicorp/go-retryablehttp,MPL-2.0,,"build-time dependency, unmodified",approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2021-07-19,2021-07-19, -go-retryablehttp,MPL-2.0,,"build-time dependency, unmodified",approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2021-07-19,2021-07-19, -Chart.js,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -cloud.google.com/go,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -code.cloudfoundry.org/clock,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -colors,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -defusedxml,Python-2.0,,build-time dependency,allowlisted,allowlisted,2019-11-01, -ejs,(Apache-2.0 AND MIT),,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/abbot/go-http-auth,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/aclements/go-moremath,BSD-3-Clause,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/andygrunwald/go-gerrit,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/aokoli/goutils,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/appc/spec,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/armon/circbuf,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/armon/go-proxyproto,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/armon/go-radix,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/asaskevich/govalidator,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/aws/aws-k8s-tester,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/aws/aws-sdk-go,((MIT OR GPL-3.0) AND BSD-3-Clause AND Apache-2.0 AND MIT),,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/Azure/azure-sdk-for-go,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/Azure/azure-storage-blob-go,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/Azure/go-ansiterm,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/Azure/go-autorest,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/bazelbuild/bazel-gazelle,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/bazelbuild/buildtools,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/beorn7/perks,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/blang/semver,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/bluebreezecf/opentsdb-goclient,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/boltdb/bolt,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/bwmarrin/snowflake,BSD-2-Clause,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/chai2010/gettext-go,BSD-3-Clause,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/cloudflare/cfssl,(BSD-2-Clause AND BSD-3-Clause AND ISC),,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/cloudfoundry-incubator/candiedyaml,(Apache-2.0 AND MIT),,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/clusterhq/flocker-go,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/cockroachdb/cmux,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/codedellemc/goscaleio,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/container-storage-interface/spec,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/containerd/console,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/containerd/containerd,(CC-BY-4.0 AND Apache-2.0),,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/containernetworking/cni,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/containernetworking/plugins,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/coredns/coredns,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/coreos/bbolt,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/coreos/etcd,(BSD-3-Clause AND Apache-2.0),,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/coreos/go-etcd,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/coreos/go-oidc,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/coreos/go-semver,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/coreos/go-systemd,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/coreos/pkg,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/coreos/rkt,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/cpuguy83/go-md2man,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/cyphar/filepath-securejoin,BSD-3-Clause,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/daaku/go.zipexe,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/davecgh/go-spew,ISC,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/daviddengcn/go-colortext,(BSD-3-Clause AND MIT),,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/dchest/safefile,BSD-2-Clause,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/deckarep/golang-set,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/denverdino/aliyungo,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/dgrijalva/jwt-go,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/digitalocean/godo,(BSD-3-Clause AND MIT),,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/djherbis/atime,(BSD-3-Clause AND MIT),,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/docker/cli,(Apache-2.0 AND MIT),,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/docker/distribution,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/docker/docker,(Apache-2.0 AND MIT),,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/docker/engine-api,(BSD-3-Clause AND Apache-2.0),,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/docker/go-connections,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/docker/libcompose,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/docker/libnetwork,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/docker/libtrust,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/docker/machine,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/dustin/go-humanize,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/eapache/channels,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/eapache/go-resiliency,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/eapache/go-xerial-snappy,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/eapache/queue,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/elazarl/go-bindata-assetfs,BSD-2-Clause,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/elazarl/goproxy,BSD-3-Clause,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/emicklei/go-restful,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/emicklei/go-restful-swagger12,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/emirpasic/gods,(BSD-2-Clause AND ISC),,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/euank/go-kmsg-parser,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/evanphx/json-patch,BSD-3-Clause,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/exponent-io/jsonpath,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/fatih/camelcase,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/fatih/structs,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/flynn/go-shlex,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/fsnotify/fsnotify,BSD-3-Clause,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/fsouza/fake-gcs-server,BSD-2-Clause,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/fsouza/go-dockerclient,(BSD-2-Clause AND Apache-2.0),,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/fullsailor/pkcs7,(BSD-3-Clause AND MIT),,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/GeertJohan/go.rice,BSD-2-Clause,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/ghodss/yaml,(BSD-3-Clause AND MIT),,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/globalsign/mgo,(BSD-2-Clause AND BSD-3-Clause),,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/go-ini/ini,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/go-openapi/analysis,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/go-openapi/errors,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/go-openapi/jsonpointer,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/go-openapi/jsonreference,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/go-openapi/loads,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/go-openapi/runtime,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/go-openapi/spec,(CC-BY-4.0 AND Apache-2.0 AND MIT),,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/go-openapi/strfmt,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/go-openapi/swag,(Apache-2.0 AND MIT),,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/go-openapi/validate,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/go-ozzo/ozzo-validation,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/go-yaml/yaml,(Apache-2.0 AND MIT),,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/gobuffalo/envy,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/godbus/dbus,BSD-2-Clause,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/gogo/protobuf,(BSD-2-Clause AND BSD-3-Clause),,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/golang/dep,(LicenseRef-Google-Patents-Notice-Golang AND BSD-3-Clause),,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/golang/glog,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/golang/groupcache,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/golang/lint,BSD-3-Clause,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/golang/mock,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/golang/protobuf,BSD-3-Clause,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/golang/snappy,BSD-3-Clause,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/google/btree,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/google/cadvisor,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/google/certificate-transparency-go,(BSD-3-Clause AND Apache-2.0),,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/google/go-containerregistry,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/google/go-querystring,BSD-3-Clause,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/google/go-tpm,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/google/gofuzz,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/google/uuid,BSD-3-Clause,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/googleapis/gax-go,BSD-3-Clause,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/googleapis/gnostic,(BSD-3-Clause AND Apache-2.0 AND MIT),,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/GoogleCloudPlatform/gke-managed-certs,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/gophercloud/gophercloud,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/gorilla/context,BSD-3-Clause,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/gorilla/mux,BSD-3-Clause,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/gorilla/securecookie,BSD-3-Clause,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/gorilla/sessions,BSD-3-Clause,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/gorilla/websocket,(BSD-2-Clause AND MIT),,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/gregjones/httpcache,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/grpc-ecosystem/go-grpc-middleware,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/grpc-ecosystem/go-grpc-prometheus,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/grpc-ecosystem/grpc-gateway,(BSD-3-Clause AND Apache-2.0),,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/hawkular/hawkular-client-go,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/heketi/heketi REST API,(Apache-2.0 OR LGPL-3.0-or-later),,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/hpcloud/tail,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/huandu/xstrings,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/imdario/mergo,BSD-3-Clause,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/inconshreveable/mousetrap,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/influxdata/influxdb,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/jimmidyson/go-download,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/jinzhu/gorm,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/jinzhu/inflection,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/jmespath/go-jmespath,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/jmhodges/clock,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/jmoiron/sqlx,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/joho/godotenv,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/jonboulle/clockwork,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/jpillora/backoff,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/json-iterator/go,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/kardianos/osext,BSD-3-Clause,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/karrick/godirwalk,BSD-2-Clause,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/kevinburke/ssh_config,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/kisielk/sqlstruct,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/knative/build,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/kr/fs,BSD-3-Clause,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/kr/pretty,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/kr/pty,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/kr/text,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/kubernetes-incubator/apiserver-builder,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/kubernetes-incubator/reference-docs,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/kubernetes-sigs/application,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/kubernetes/repo-infra,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/kylelemons/godebug,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/lib/pq,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/libopenstorage/openstorage,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/libvirt/libvirt-go,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/libvirt/libvirt-go-xml,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/lpabon/godbc,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/lxn/win,BSD-3-Clause,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/magiconair/properties,(BSD-2-Clause AND BSD-3-Clause),,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/mailru/easyjson,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/MakeNowJust/heredoc,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/markbates/inflect,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/marpaia/graphite-golang,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/Masterminds/semver,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/Masterminds/sprig,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/Masterminds/vcs,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/mattn/go-runewidth,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/mattn/go-shellwords,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/mattn/go-zglob,(BSD-3-Clause AND MIT),,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/matttproud/golang_protobuf_extensions,(BSD-3-Clause AND Apache-2.0),,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/mesos/mesos-go,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/mholt/caddy,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/Microsoft/go-winio,(BSD-3-Clause AND MIT),,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/Microsoft/hcsshim,(BSD-3-Clause AND MIT),,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/miekg/coredns,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/miekg/dns,BSD-3-Clause,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/mindprince/gonvml,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/mistifyio/go-zfs,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/mitchellh/go-homedir,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/mitchellh/go-ps,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/mitchellh/go-wordwrap,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/mitchellh/hashstructure,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/mitchellh/mapstructure,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/moby/hyperkit,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/modern-go/concurrent,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/modern-go/reflect2,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/mohae/deepcopy,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/moul/http2curl,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/mrunalp/fileutils,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/mvdan/xurls,BSD-3-Clause,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/mxk/go-flowrate,BSD-3-Clause,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/ncabatoff/process-exporter,(Apache-2.0 AND MIT),,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/nightlyone/lockfile,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/novln/docker-parser,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/NYTimes/gziphandler,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/olekukonko/tablewriter,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/onsi/ginkgo,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/onsi/gomega,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/opencontainers/image-spec,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/opencontainers/runtime-spec,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/opencontainers/selinux,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/openshift/origin,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/opentracing/opentracing-go,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/parnurzeal/gorequest,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/patrickmn/go-cache,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/paultag/sniff,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/pborman/uuid,BSD-3-Clause,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/pelletier/go-buffruneio,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/pelletier/go-toml,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/petar/GoLLRB,BSD-3-Clause,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/peterbourgon/diskv,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/pierrec/lz4,BSD-3-Clause,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/pierrec/xxHash,BSD-3-Clause,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/pkg/browser,BSD-2-Clause,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/pkg/errors,BSD-2-Clause,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/pkg/profile,BSD-2-Clause,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/pkg/sftp,BSD-2-Clause,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/pmezard/go-difflib,BSD-3-Clause,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/pquerna/cachecontrol,(BSD-3-Clause AND Apache-2.0),,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/pquerna/ffjson,(BSD-3-Clause AND Apache-2.0 AND ISC),,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/prometheus/client_golang,(BSD-3-Clause AND Apache-2.0 AND MIT),,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/prometheus/client_model,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/prometheus/common,(BSD-3-Clause AND Apache-2.0),,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/prometheus/procfs,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/PuerkitoBio/purell,BSD-3-Clause,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/PuerkitoBio/urlesc,BSD-3-Clause,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/r2d4/external-storage,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/rackspace/gophercloud,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/rancher/go-rancher,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/rcrowley/go-metrics,BSD-2-Clause-FreeBSD,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/renstrom/dedent,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/Rican7/retry,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/riemann/riemann-go-client,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/robfig/cron,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/russross/blackfriday,BSD-2-Clause,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/samalba/dockerclient,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/satori/go.uuid,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/scalingdata/gcfg,(BSD-2-Clause AND BSD-3-Clause),,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/sdboyer/constext,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/seccomp/libseccomp-golang,BSD-2-Clause,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/sergi/go-diff,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/Shopify/sarama,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/shurcooL/githubv4,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/shurcooL/go,BSD-3-Clause,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/shurcooL/graphql,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/shurcooL/sanitized_anchor_name,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/sirupsen/logrus,(BSD-2-Clause AND BSD-3-Clause AND MIT),,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/skynetservices/skydns,(Apache-2.0 AND MIT),,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/smartystreets/go-aws-auth,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/soheilhy/cmux,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/spf13/afero,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/spf13/cast,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/spf13/cobra,(Apache-2.0 AND MIT),,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/spf13/jwalterweatherman,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/spf13/pflag,BSD-3-Clause,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/spf13/viper,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/storageos/go-api,(BSD-2-Clause AND MIT),,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/streadway/quantile,BSD-2-Clause,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/stretchr/objx,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/stretchr/testify,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/syndtr/gocapability,BSD-2-Clause,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/tchap/go-patricia,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/thockin/glogr,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/thockin/logr,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/tmc/grpc-websocket-proxy,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/tsenart/vegeta,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/ugorji/go,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/Unknwon/goconfig,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/urfave/cli,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/vishvananda/netlink,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/vishvananda/netns,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/vmware/govmomi,(BSD-3-Clause AND Apache-2.0),,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/vmware/photon-controller-go-sdk,(BSD-3-Clause AND Apache-2.0),,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/weaveworks/mesh,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/xanzy/go-cloudstack,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/xeipuuv/gojsonpointer,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/xeipuuv/gojsonreference,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -github.com/xeipuuv/gojsonschema,(Apache-2.0 AND MIT),,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/xiang90/probing,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/zakjan/cert-chain-resolver,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -github.com/ziutek/syslog,BSD-3-Clause,,build-time dependency,allowlisted,allowlisted,2019-11-01, -go.opencensus.io,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -go.uber.org/atomic,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -go.uber.org/multierr,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -go.uber.org/zap,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -go4.org/errorutil,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -golang.org/x/build,(LicenseRef-Google-Patents-Notice-Golang AND BSD-3-Clause),,build-time dependency,allowlisted,allowlisted,2019-11-01, -golang.org/x/exp,(LicenseRef-Google-Patents-Notice-Golang AND BSD-3-Clause),,build-time dependency,allowlisted,allowlisted,2019-11-01, -golang.org/x/lint,BSD-3-Clause,,build-time dependency,allowlisted,allowlisted,2019-11-01, -golang.org/x/oauth2,BSD-3-Clause,,build-time dependency,allowlisted,allowlisted,2019-11-01, -golang.org/x/sync,(LicenseRef-Google-Patents-Notice-Golang AND BSD-3-Clause),,build-time dependency,allowlisted,allowlisted,2019-11-01, -golang.org/x/sys,(LicenseRef-Google-Patents-Notice-Golang AND BSD-2-Clause AND BSD-3-Clause),,build-time dependency,allowlisted,allowlisted,2019-11-01, -golang.org/x/text,(LicenseRef-Google-Patents-Notice-Golang AND BSD-3-Clause),,build-time dependency,allowlisted,allowlisted,2019-11-01, -golang.org/x/time,(LicenseRef-Google-Patents-Notice-Golang AND BSD-3-Clause),,build-time dependency,allowlisted,allowlisted,2019-11-01, -golang.org/x/tools,(LicenseRef-Google-Patents-Notice-Golang AND BSD-3-Clause AND Apache-2.0 AND MIT),,build-time dependency,allowlisted,allowlisted,2019-11-01, -golang/archive/tar,BSD-3-Clause,,build-time dependency,allowlisted,allowlisted,2019-11-01, -gonum.org/v1/gonum,((BSD-3-Clause OR CC0-1.0) AND BSD-3-Clause),,build-time dependency,allowlisted,allowlisted,2019-11-01, -google.golang.org/cloud,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -google.golang.org/genproto,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -gopkg.in/check.v1,(BSD-2-Clause AND BSD-3-Clause),,build-time dependency,allowlisted,allowlisted,2019-11-01, -gopkg.in/cheggaaa/pb.v1,BSD-3-Clause,,build-time dependency,allowlisted,allowlisted,2019-11-01, -gopkg.in/fsnotify,BSD-3-Clause,,build-time dependency,allowlisted,allowlisted,2019-11-01, -gopkg.in/gcfg.v1,BSD-3-Clause,,build-time dependency,allowlisted,allowlisted,2019-11-01, -gopkg.in/go-playground/pool.v3,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -gopkg.in/igm/sockjs-go.v2,BSD-3-Clause,,build-time dependency,allowlisted,allowlisted,2019-11-01, -gopkg.in/inf.v0,BSD-3-Clause,,build-time dependency,allowlisted,allowlisted,2019-11-01, -gopkg.in/natefinch/lumberjack.v2,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -gopkg.in/olivere/elastic.v3,(BSD-3-Clause AND MIT),,build-time dependency,allowlisted,allowlisted,2019-11-01, -gopkg.in/olivere/elastic.v5,(BSD-3-Clause AND MIT),,build-time dependency,allowlisted,allowlisted,2019-11-01, -gopkg.in/robfig/cron.v2,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -gopkg.in/square/go-jose.v2,(BSD-3-Clause AND Apache-2.0),,build-time dependency,allowlisted,allowlisted,2019-11-01, -gopkg.in/src-d,Apache-2.0,,build-time dependency,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, -gopkg.in/tomb.v1,BSD-3-Clause,,build-time dependency,allowlisted,allowlisted,2019-11-01, -jquery.scrollto,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -marked,(BSD-3-Clause AND MIT),,build-time dependency,allowlisted,allowlisted,2019-11-01, -mime,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -minimist,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -node-static,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -optimist,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -ui-router for Angular,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -vbom.ml/util,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -wordwrap,MIT,,build-time dependency,allowlisted,allowlisted,2019-11-01, -VirtualBox Linux Guest Drivers Makefile,GPL-2.0-only,,,approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-05-20,2019-05-20, -Angular,MIT,,,approved,contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11,2019-03-11, -Asciidoctor,MIT,,,approved,contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11,2019-03-11, -Azure acr-docker-credential-helper,MIT,,,approved,modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11,2019-03-11, -Backbone,MIT,,,approved,contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11,2019-03-11, -bitbucket.org/bertimus9/systemstat,MIT,,,approved,not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11,2019-03-11, -bitbucket.org/ww/goautoneg,BSD-3-Clause,,,approved,not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11,2019-03-11, -bootstrap,(CC-BY-3.0 AND MIT),,,approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11,2019-03-11, -dialog-polyfill.css,BSD-3-Clause,,,approved,contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11,2019-03-11, -font-awesome,(CC-BY-3.0 AND MIT AND OFL-1.1),,,approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11,2019-03-11, -Gingko,MIT,,,approved,contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11,2019-03-11, -github.com/Azure/azure-pipeline-go,MIT,,,approved,not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11,2019-03-11, -github.com/bungle/lua-resty-template,BSD-3-Clause,,,approved,modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11,2019-03-11, -github.com/c4milo/gotoolkit,MPL-2.0,,,approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11,2019-03-11, -github.com/client9/misspell,(Unlicense AND BSD-3-Clause AND MIT),,,approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11,2019-03-11, -github.com/d2g/dhcp4,BSD-3-Clause,,,approved,not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11,2019-03-11, -github.com/d2g/dhcp4client,MPL-2.0,,,approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11,2019-03-11, -github.com/dgryski/go-onlinestats,(MIT AND LicenseRef-Public-domain-statement),,,approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11,2019-03-11, -github.com/docker/go-units,(CC-BY-SA-4.0 AND CC-BY-4.0 AND Apache-2.0),,,approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11,2019-03-11, -github.com/docker/spdystream,(CC-BY-SA-4.0 AND CC-BY-4.0 AND BSD-3-Clause AND Apache-2.0),,,approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11,2019-03-11, -github.com/go-sql-driver/mysql,MPL-2.0,,,approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11,2019-03-11, -github.com/gonum/graph,BSD-3-Clause,,,approved,modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11,2019-03-11, -github.com/google/go-github,(BSD-3-Clause AND CC-BY-3.0),,,approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11,2019-03-11, -github.com/grpc-ecosystem/grpc-opentracing,(BSD-3-Clause AND LicenseRef-Google-Patents-Notice-GRPC),,,approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11,2019-03-11, -github.com/hashicorp/errwrap,MPL-2.0,,,approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11,2019-03-11, -github.com/hashicorp/go-cleanhttp,MPL-2.0,,,approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11,2019-03-11, -github.com/hashicorp/go-multierror,MPL-2.0,,,approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11,2019-03-11, -github.com/hashicorp/golang-lru,MPL-2.0,,,approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11,2019-03-11, -github.com/hashicorp/hcl,MPL-2.0,,,approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11,2019-03-11, -github.com/hooklift/iso9660,MPL-2.0,,,approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11,2019-03-11, -github.com/howeyc/gopass,(ISC AND CDDL-1.0),,,approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11,2019-03-11, -github.com/jbenet/go-context,MIT,,,approved,not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11,2019-03-11, -github.com/JeffAshton/win_pdh,BSD-3-Clause,,,approved,not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11,2019-03-11, -github.com/jmank88/nuts,MIT,,,approved,not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11,2019-03-11, -github.com/johanneswuerbach/nfsexports,MIT,,,approved,not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11,2019-03-11, -github.com/joshdk/go-junit,MIT,,,approved,not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11,2019-03-11, -github.com/jteeuwen/go-bindata,CC0-1.0,,,approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11,2019-03-11, -github.com/konsorten/go-windows-terminal-sequences,MIT,,,approved,not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11,2019-03-11, -github.com/marstr/guid,MIT,,,approved,not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11,2019-03-11, -github.com/mattn/go-sqlite3,(MIT AND LicenseRef-Public-domain-statement),,,approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11,2019-03-11, -github.com/multiarch/qemu-user-static,MIT,,,approved,modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11,2019-03-11, -github.com/Nvveen/Gotty,BSD-2-Clause-FreeBSD,,,approved,not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11,2019-03-11, -github.com/opencontainers/go-digest,(CC-BY-SA-4.0 AND CC-BY-4.0 AND Apache-2.0),,,approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11,2019-03-11, -github.com/opencontainers/runc,(LicenseRef-CC-unspecified AND Apache-2.0),,,approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11,2019-03-11, -github.com/quobyte/api,BSD-3-Clause,,,approved,not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11,2019-03-11, -github.com/rubiojr/go-vhd,MIT,,,approved,not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11,2019-03-11, -github.com/sigma/go-inotify,(LicenseRef-Google-Patents-Notice-Golang AND BSD-3-Clause),,,approved,not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11,2019-03-11, -github.com/spotinst/spotinst-sdk-go,(BSD-3-Clause AND Apache-2.0 AND MIT),,,approved,not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11,2019-03-11, -github.com/src-d/gcfg,BSD-3-Clause,,,approved,not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11,2019-03-11, -github.com/tent/http-link-go,BSD-3-Clause,,,approved,not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11,2019-03-11, -github.com/xanzy/ssh-agent,(Apache-2.0 AND MIT),,,approved,not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11,2019-03-11, -github.com/zchee/go-vmnet,(BSD-2-Clause AND BSD-3-Clause),,,approved,not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11,2019-03-11, -go-srcimporter,BSD-3-Clause,,,approved,modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11,2019-03-11, -go9p,BSD-3-Clause,,,approved,modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11,2019-03-11, -godep,BSD-3-Clause,,,approved,modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11,2019-03-11, -golang.org/x/crypto,(LicenseRef-Google-Patents-Notice-Golang AND BSD-3-Clause AND MIT AND LicenseRef-Public-domain-statement),,,approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11,2019-03-11, -golang.org/x/net,(LicenseRef-Google-Patents-Notice-Golang AND BSD-2-Clause AND BSD-3-Clause AND CC-BY-3.0 AND (BSD-3-Clause OR LicenseRef-W3C-Test-Suite-License-1)),,,approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11,2019-03-11, -golang/expansion,(LicenseRef-Google-Patents-Notice-Golang AND BSD-3-Clause),,,approved,modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11,2019-03-11, -golang/go/types,(LicenseRef-Google-Patents-Notice-Golang AND BSD-3-Clause),,,approved,modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11,2019-03-11, -golang/internal/srcimporter,BSD-3-Clause,,,approved,modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11,2019-03-11, -golang/json,BSD-3-Clause,,,approved,modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11,2019-03-11, -golang/netutil,BSD-3-Clause,,,approved,modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11,2019-03-11, -golang/reflect,(LicenseRef-Google-Patents-Notice-Golang AND BSD-3-Clause),,,approved,modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11,2019-03-11, -golang/template,(LicenseRef-Google-Patents-Notice-Golang AND BSD-3-Clause),,,approved,modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11,2019-03-11, -Google Protocol Buffers,BSD-3-Clause,,,approved,contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11,2019-03-11, -google.golang.org/api,(BSD-3-Clause AND Apache-2.0 AND MIT),,,approved,not auto-allowlist because: No measure of stars / forks; approved by GB exception 2019-03-11,2019-03-11, -google.golang.org/appengine,(BSD-3-Clause AND Apache-2.0),,,approved,not auto-allowlist because: No measure of stars / forks; approved by GB exception 2019-03-11,2019-03-11, -google.golang.org/grpc,(BSD-3-Clause AND Apache-2.0 AND LicenseRef-Google-Patents-Notice-GRPC),,,approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11,2019-03-11, -gopkg.in/warnings.v0,BSD-2-Clause,,,approved,not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11,2019-03-11, -Handlebars,MIT,,,approved,contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11,2019-03-11, -Highlight,BSD-3-Clause,,,approved,contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11,2019-03-11, -highlight.js,(BSD-3-Clause AND MIT AND CC0-1.0 AND LicenseRef-Public-domain-statement),,,approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11,2019-03-11, -htpasswd,BSD-3-Clause,,,approved,not auto-allowlist because: No measure of stars / forks; approved by GB exception 2019-03-11,2019-03-11, -jQuery,MIT,,,approved,contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11,2019-03-11, -jQuery BBQ,(MIT OR GPL-2.0+),,,approved,contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11,2019-03-11, -jQuery hashchange event,(GPL-2.0+ OR MIT),,,approved,contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11,2019-03-11, -jQuery Slideto,MIT,,,approved,contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11,2019-03-11, -jQuery Wiggle,MIT,,,approved,contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11,2019-03-11, -moment.js,MIT,,,approved,contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11,2019-03-11, -normalize.css,MIT,,,approved,contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11,2019-03-11, -Octicons,MIT,,,approved,contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11,2019-03-11, -parseUri,MIT,,,approved,contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11,2019-03-11, -Pause,MIT,,,approved,not auto-allowlist because: No measure of stars / forks; approved by GB exception 2019-03-11,2019-03-11, -Pure CSS,BSD-3-Clause,,,approved,contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11,2019-03-11, -shred,ISC,,,approved,contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11,2019-03-11, -sigs.k8s.io/yaml,(BSD-3-Clause AND MIT),,,approved,fork of github.com/ghodss/yaml; not auto-allowlist because: Modified; approved by GB exception 2019-03-11,2019-03-11, -speter.net/go/exp,(BSD-2-Clause AND BSD-3-Clause),,,approved,not auto-allowlist because: No measure of stars / forks; approved by GB exception 2019-03-11,2019-03-11, -sprintf() for JavaScript,BSD-3-Clause,,,approved,contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11,2019-03-11, -Underscore.js,MIT,,,approved,contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11,2019-03-11, +Package or Category,License Concluded,Project,Scope,Status,Comments,Date Published,Last updated: 2026-06-01 +eclipse-ee4j/expressly,EPL-2.0 OR GPL-2.0-only WITH Classpath-exception-2.0,Keycloak,"Approved for dynamic linking only (static linking not permitted); furthermore, the dependency must be used in unmodified form",approved,"Default implementation of Jakarta Expression Language 6.0, transitive dependency for Hibernate Validator",2025-01-12, +libpathrs,MPL-2.0 OR LGPL-3.0-or-later,All CNCF Projects,"Any CNCF project using libpathrs as a statically linked dependency MUST elect to do so under MPL-2.0 (rather than LGPL-3.0) and declare such election in its documentation. Furthermore, to minimize compliance burdens for CNCF projects and downstream users, it is strongly recommended that projects using libpathrs as a dynamically linked dependency also elect to do so under MPL-2.0 (rather than LGPL-3.0). Furthermore, libpathrs must be maintained either (a) in a distinct directory or module clearly separated from CNCF project code, or (b) retrieved at build/installation time from a third-party repository.",approved,Blanket exception: Projects using libpathrs statically linked MUST elect MPL-2.0 and document this. Provides secure path resolution APIs.,2025-01-12, +go-pathrs,MPL-2.0,All CNCF Projects,"Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository",approved,Blanket exception: Go bindings for libpathrs. Provides secure path resolution APIs.,2025-01-12, +cyphar/filepath-securejoin,MPL-2.0 AND BSD-3-Clause,All CNCF Projects,"Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository",approved,"Blanket exception: Provides secure path resolution APIs on Linux. Used by Kubernetes, containerd, Podman, buildah, cri-o, nerdctl.",2025-11-21, +Liquibase,FSL Functional Source License,Keycloak,Not Applicable (Denied),denied,Denied: FSL is not an open source license. GB does not approve exceptions for non-OSS licenses.,2025-11-21, +paramiko,LGPL-2.1,oscal-compass,Approved only for dynamic linking (static linking is not approved),approved,"Pure-Python SSHv2 protocol implementation, used for fetching files",2025-10-17, +certifi,MPL-2.0,oscal-compass,"Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository",approved,Dependency for requests library,2025-10-17, +pathspec,MPL-2.0,oscal-compass,"Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository",approved,"Dependency for black, mkdocs, mypy",2025-10-17, +cyphar/filepath-securejoin,BSD-3-Clause AND MPL-2.0,Kubernetes,No scope restrictions,approved,Provides secure path construction functions. Superseded by blanket exception in issue #1154.,2025-10-17, +hashicorp/terraform-provider-aws,MPL-2.0,Crossplane,Allowed only if the modified fork is stored in a seperate designated folder separate from the project's own code,approved,"Fork maintained for Crossplane providers, changes contributed upstream",2024-10-23, +hashicorp/terraform-provider-azurerm,MPL-2.0,Crossplane,Allowed only if the modified fork is stored in a seperate designated folder separate from the project's own code,approved,"Fork maintained for Crossplane providers, changes contributed upstream",2024-10-23, +hashicorp/terraform-provider-azuread,MPL-2.0,Crossplane,Allowed only if the modified fork is stored in a seperate designated folder separate from the project's own code,approved,"Fork maintained for Crossplane providers, changes contributed upstream",2024-10-23, +apple/swift-nio-ssl,OpenSSL,Connect,"Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository",approved,Required for HTTP/2 + TLS with HTTP trailers on iOS. Also used by gRPC Swift.,2024-10-23, +Crossplane Upjet MPL dependencies,MPL-2.0,Crossplane,"Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository",approved,"Various hashicorp terraform dependencies for Upjet: hcl, terraform-json, terraform-plugin-framework, terraform-plugin-go, terraform-plugin-sdk, go-plugin, go-uuid, go-version, logutils, terraform-plugin-log, terraform-registry-address, terraform-svchost, yamux",2024-10-23, +Linux kernel uapi headers (btrfs),GPL-2.0-only WITH Linux-syscall-note,containerd,Approved only for ue by containerd as described in the exception request,approved,Used by containerd/btrfs for btrfs-related ioctl syscalls. Headers from linux/btrfs.h and linux/btrfs_tree.h.,2024-10-23, +github.com/hashicorp/go-set/v2,MPL-2.0,OpenFGA,"Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository",approved,Unmodified code,2024-10-23, +Keycloak Java dependencies,"0BSD, CDDL-1.1, EPL-1.0, EPL-2.0, GPL-2.0-only, GPL-2.0-with-classpath-exception, LGPL-2.1, LGPL-2.1-only, MIT-0, MPL-2.0, UPL-1.0",Keycloak,Approved for use by Keycloak only in unmodified form,approved,"Multiple Java dependencies including: tslib, h2, mysql-connector-j, jakarta.* APIs, parsson, graalvm SDK, hibernate-*, mariadb-java-client, nashorn-core, reactive-streams",2024-10-23, +github.com/hashicorp/memberlist,MPL-2.0,kubernetes/kops,"Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository",approved,Main component of Gossip DNS feature for peer-to-peer network K8s API address propagation,2024-07-16, +Falco kernel module,GPL-2.0-only OR MIT,Falco,Approved for use by Falco only,approved,Falco's kernel module is dual-licensed GPL-2.0-only OR MIT,2024-02-27, +In-kernel eBPF programs,"GPL-2.0-only, GPL-2.0-or-later",All CNCF Projects,Exception applies only to code that runs inside the kernel (not to any code running in the user-space),approved,"Blanket exception: GPL-2.0 licensed code is permitted for in-kernel eBPF programs only, as this is required by the Linux kernel BPF subsystem.",2023-08-31, +github.com/docker/go-metrics documentation,CC-BY-SA 4.0,Cilium,Approval applies only to use of documentation in unmodified form,approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-08-31,2023-08-31, +github.com/hashicorp/go-memdb,MPL-2.0,Cilium,,approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-08-31,2023-08-31, +github.com/shoenig/go-m1cpu,MPL-2.0,Kubernetes,"Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository",approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-08-31,2023-08-31, +hashicorp/packer-plugin-sdk,MPL-2.0,All CNCF Projects,"Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository",approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-08-31,2023-08-31, +github.com/hashicorp/consul/api,MPL-2.0,Cilium,"Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository",approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27,2023-06-27, +github.com/hashicorp/go-hclog,MPL-2.0,Cilium,"Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository",approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27,2023-06-27, +github.com/hashicorp/go-immutable-radix,MPL-2.0,Cilium,"Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository",approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27,2023-06-27, +github.com/hashicorp/go-plugin,MPL-2.0,All CNCF Projects,"Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository",approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27,2023-06-27, +github.com/hashicorp/go-rootcerts,MPL-2.0,Cilium,"Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository",approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27,2023-06-27, +github.com/hashicorp/go-secure-stdlib,MPL-2.0,All CNCF Projects,"Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository",approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27,2023-06-27, +github.com/hashicorp/go-sockaddr,MPL-2.0,All CNCF Projects,"Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository",approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27,2023-06-27, +github.com/hashicorp/go-uuid,MPL-2.0,All CNCF Projects,"Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository",approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27,2023-06-27, +github.com/hashicorp/serf,MPL-2.0,Cilium,"Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository",approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27,2023-06-27, +github.com/hashicorp/vault,MPL-2.0,All CNCF Projects,"Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository",approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27,2023-06-27, +github.com/veraison/go-cose,MPL-2.0,Notary,"Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository",approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27,2023-06-27, +hashicorp/consul/api,MPL-2.0,All CNCF Projects,"Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository",approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27,2023-06-27, +hashicorp/go-hclog,MPL-2.0,All CNCF Projects,"Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository",approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27,2023-06-27, +hashicorp/go-immutable-radix,MPL-2.0,All CNCF Projects,"Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository",approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27,2023-06-27, +hashicorp/go-plugin,MPL-2.0,All CNCF Projects,"Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository",approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27,2023-06-27, +hashicorp/go-rootcerts,MPL-2.0,All CNCF Projects,"Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository",approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27,2023-06-27, +hashicorp/go-secure-stdlib,MPL-2.0,All CNCF Projects,"Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository",approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27,2023-06-27, +hashicorp/go-sockaddr,MPL-2.0,All CNCF Projects,"Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository",approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27,2023-06-27, +hashicorp/go-uuid,MPL-2.0,All CNCF Projects,"Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository",approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27,2023-06-27, +hashicorp/go-version,MPL-2.0,All CNCF Projects,"Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository",approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27,2023-06-27, +hashicorp/raft,MPL-2.0,All CNCF Projects,"Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository",approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27,2023-06-27, +hashicorp/serf,MPL-2.0,All CNCF Projects,"Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository",approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27,2023-06-27, +hashicorp/vault,MPL-2.0,All CNCF Projects,"Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository",approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27,2023-06-27, +hashicorp/yamux,MPL-2.0,All CNCF Projects,"Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository",approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27,2023-06-27, +veraison/go-cose,MPL-2.0,Notary,"Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository",approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27,2023-06-27, +github.com/eclipse/paho.mqtt.golang,EPL-2.0,All CNCF Projects,"Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository",approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2022-04-12,2022-04-12, +github.com/hashicorp/go-version,MPL-2.0,All CNCF Projects,"Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository",approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2022-04-12,2022-04-12, +github.com/hashicorp/raft,MPL-2.0,Dapr,"Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository",approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2022-04-12,2022-04-12, +github.com/hashicorp/raft-boltdb,MPL-2.0,Dapr,"Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository",approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2022-04-12,2022-04-12, +github.com/Microsoft/tslib,0BSD,All CNCF Projects,No scope restrictions,approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2022-04-12,2022-04-12, +go-version,MPL-2.0,All CNCF Projects,"Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository",approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2022-04-12,2022-04-12, +paho.mqtt.golang,EPL-2.0,All CNCF Projects,"Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository",approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2022-04-12,2022-04-12, +raft,MPL-2.0,Dapr,"Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository",approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2022-04-12,2022-04-12, +raft-boltdb,MPL-2.0,Dapr,"Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository",approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2022-04-12,2022-04-12, +tslib,0BSD,All CNCF Projects,No scope restrictions,approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2022-04-12,2022-04-12, +webpki-roots,MPL-2.0,All CNCF Projects,"Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository",approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2022-04-12,2022-04-12, +github.com/hashicorp/go-retryablehttp,MPL-2.0,All CNCF Projects,"Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository",approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2021-07-19,2021-07-19, +go-retryablehttp,MPL-2.0,All CNCF Projects,"Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository",approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2021-07-19,2021-07-19, +Chart.js,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +cloud.google.com/go,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +code.cloudfoundry.org/clock,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +colors,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +defusedxml,Python-2.0,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +ejs,Apache-2.0 AND MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/abbot/go-http-auth,Apache-2.0,Kubernetes,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/aclements/go-moremath,BSD-3-Clause,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/andygrunwald/go-gerrit,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/aokoli/goutils,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/appc/spec,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/armon/circbuf,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/armon/go-proxyproto,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/armon/go-radix,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/asaskevich/govalidator,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/aws/aws-k8s-tester,Apache-2.0,Kubernetes,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/aws/aws-sdk-go,(MIT OR GPL-3.0) AND BSD-3-Clause AND Apache-2.0 AND MIT,All CNCF Projects,Allowed as long as the CNCF project imports this SDK through standard dependency management rather than modifying the core SDK code,approved,allowlisted,2019-11-01, +github.com/Azure/azure-sdk-for-go,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/Azure/azure-storage-blob-go,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/Azure/go-ansiterm,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/Azure/go-autorest,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/bazelbuild/bazel-gazelle,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/bazelbuild/buildtools,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/beorn7/perks,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/blang/semver,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/bluebreezecf/opentsdb-goclient,Apache-2.0,Kubernetes,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/boltdb/bolt,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/bwmarrin/snowflake,BSD-2-Clause,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/chai2010/gettext-go,BSD-3-Clause,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/cloudflare/cfssl,BSD-2-Clause AND BSD-3-Clause AND ISC,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/cloudfoundry-incubator/candiedyaml,Apache-2.0 AND MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/clusterhq/flocker-go,Apache-2.0,Kubernetes,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/cockroachdb/cmux,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/codedellemc/goscaleio,Apache-2.0,Kubernetes,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/container-storage-interface/spec,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/containerd/console,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/containerd/containerd,CC-BY-4.0 AND Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/containernetworking/cni,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/containernetworking/plugins,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/coredns/coredns,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/coreos/bbolt,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/coreos/etcd,BSD-3-Clause AND Apache-2.0,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/coreos/go-etcd,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/coreos/go-oidc,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/coreos/go-semver,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/coreos/go-systemd,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/coreos/pkg,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/coreos/rkt,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/cpuguy83/go-md2man,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/cyphar/filepath-securejoin,BSD-3-Clause,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/daaku/go.zipexe,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/davecgh/go-spew,ISC,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/daviddengcn/go-colortext,BSD-3-Clause AND MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/dchest/safefile,BSD-2-Clause,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/deckarep/golang-set,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/denverdino/aliyungo,Apache-2.0,Kubernetes,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/dgrijalva/jwt-go,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/digitalocean/godo,BSD-3-Clause AND MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/djherbis/atime,BSD-3-Clause AND MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/docker/cli,Apache-2.0 AND MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/docker/distribution,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/docker/docker,Apache-2.0 AND MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/docker/engine-api,BSD-3-Clause AND Apache-2.0,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/docker/go-connections,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/docker/libcompose,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/docker/libnetwork,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/docker/libtrust,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/docker/machine,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/dustin/go-humanize,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/eapache/channels,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/eapache/go-resiliency,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/eapache/go-xerial-snappy,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/eapache/queue,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/elazarl/go-bindata-assetfs,BSD-2-Clause,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/elazarl/goproxy,BSD-3-Clause,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/emicklei/go-restful,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/emicklei/go-restful-swagger12,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/emirpasic/gods,BSD-2-Clause AND ISC,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/euank/go-kmsg-parser,Apache-2.0,Kubernetes,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/evanphx/json-patch,BSD-3-Clause,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/exponent-io/jsonpath,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/fatih/camelcase,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/fatih/structs,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/flynn/go-shlex,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/fsnotify/fsnotify,BSD-3-Clause,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/fsouza/fake-gcs-server,BSD-2-Clause,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/fsouza/go-dockerclient,BSD-2-Clause AND Apache-2.0,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/fullsailor/pkcs7,BSD-3-Clause AND MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/GeertJohan/go.rice,BSD-2-Clause,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/ghodss/yaml,BSD-3-Clause AND MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/globalsign/mgo,BSD-2-Clause AND BSD-3-Clause,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/go-ini/ini,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/go-openapi/analysis,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/go-openapi/errors,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/go-openapi/jsonpointer,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/go-openapi/jsonreference,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/go-openapi/loads,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/go-openapi/runtime,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/go-openapi/spec,CC-BY-4.0 AND Apache-2.0 AND MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/go-openapi/strfmt,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/go-openapi/swag,Apache-2.0 AND MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/go-openapi/validate,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/go-ozzo/ozzo-validation,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/go-yaml/yaml,Apache-2.0 AND MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/gobuffalo/envy,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/godbus/dbus,BSD-2-Clause,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/gogo/protobuf,BSD-2-Clause AND BSD-3-Clause,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/golang/dep,LicenseRef-Google-Patents-Notice-Golang AND BSD-3-Clause,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/golang/glog,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/golang/groupcache,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/golang/lint,BSD-3-Clause,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/golang/mock,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/golang/protobuf,BSD-3-Clause,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/golang/snappy,BSD-3-Clause,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/google/btree,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/google/cadvisor,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/google/certificate-transparency-go,BSD-3-Clause AND Apache-2.0,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/google/go-containerregistry,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/google/go-querystring,BSD-3-Clause,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/google/go-tpm,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/google/gofuzz,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/google/uuid,BSD-3-Clause,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/googleapis/gax-go,BSD-3-Clause,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/googleapis/gnostic,BSD-3-Clause AND Apache-2.0 AND MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/GoogleCloudPlatform/gke-managed-certs,Apache-2.0,Kubernetes,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/gophercloud/gophercloud,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/gorilla/context,BSD-3-Clause,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/gorilla/mux,BSD-3-Clause,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/gorilla/securecookie,BSD-3-Clause,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/gorilla/sessions,BSD-3-Clause,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/gorilla/websocket,BSD-2-Clause AND MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/gregjones/httpcache,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/grpc-ecosystem/go-grpc-middleware,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/grpc-ecosystem/go-grpc-prometheus,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/grpc-ecosystem/grpc-gateway,BSD-3-Clause AND Apache-2.0,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/hawkular/hawkular-client-go,Apache-2.0,Kubernetes,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/heketi/heketi REST API,Apache-2.0 OR LGPL-3.0-or-later,All CNCF Projects,Approval is limited to the REST API client libraries and does not extend to the Heketi server or other components.,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/hpcloud/tail,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/huandu/xstrings,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/imdario/mergo,BSD-3-Clause,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/inconshreveable/mousetrap,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/influxdata/influxdb,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/jimmidyson/go-download,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/jinzhu/gorm,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/jinzhu/inflection,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/jmespath/go-jmespath,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/jmhodges/clock,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/jmoiron/sqlx,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/joho/godotenv,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/jonboulle/clockwork,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/jpillora/backoff,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/json-iterator/go,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/kardianos/osext,BSD-3-Clause,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/karrick/godirwalk,BSD-2-Clause,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/kevinburke/ssh_config,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/kisielk/sqlstruct,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/knative/build,Apache-2.0,Knative,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/kr/fs,BSD-3-Clause,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/kr/pretty,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/kr/pty,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/kr/text,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/kubernetes-incubator/apiserver-builder,Apache-2.0,Kubernetes,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/kubernetes-incubator/reference-docs,Apache-2.0,Kubernetes,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/kubernetes-sigs/application,Apache-2.0,Kubernetes,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/kubernetes/repo-infra,Apache-2.0,Kubernetes,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/kylelemons/godebug,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/lib/pq,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/libopenstorage/openstorage,Apache-2.0,Kubernetes,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/libvirt/libvirt-go,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/libvirt/libvirt-go-xml,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/lpabon/godbc,Apache-2.0,Kubernetes,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/lxn/win,BSD-3-Clause,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/magiconair/properties,BSD-2-Clause AND BSD-3-Clause,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/mailru/easyjson,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/MakeNowJust/heredoc,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/markbates/inflect,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/marpaia/graphite-golang,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/Masterminds/semver,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/Masterminds/sprig,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/Masterminds/vcs,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/mattn/go-runewidth,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/mattn/go-shellwords,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/mattn/go-zglob,BSD-3-Clause AND MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/matttproud/golang_protobuf_extensions,BSD-3-Clause AND Apache-2.0,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/mesos/mesos-go,Apache-2.0,Kubernetes,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/mholt/caddy,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/Microsoft/go-winio,BSD-3-Clause AND MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/Microsoft/hcsshim,BSD-3-Clause AND MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/miekg/coredns,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/miekg/dns,BSD-3-Clause,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/mindprince/gonvml,Apache-2.0,Kubernetes,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/mistifyio/go-zfs,Apache-2.0,Kubernetes,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/mitchellh/go-homedir,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/mitchellh/go-ps,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/mitchellh/go-wordwrap,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/mitchellh/hashstructure,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/mitchellh/mapstructure,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/moby/hyperkit,Apache-2.0,Kubernetes,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/modern-go/concurrent,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/modern-go/reflect2,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/mohae/deepcopy,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/moul/http2curl,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/mrunalp/fileutils,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/mvdan/xurls,BSD-3-Clause,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/mxk/go-flowrate,BSD-3-Clause,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/ncabatoff/process-exporter,Apache-2.0 AND MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/nightlyone/lockfile,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/novln/docker-parser,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/NYTimes/gziphandler,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/olekukonko/tablewriter,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/onsi/ginkgo,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/onsi/gomega,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/opencontainers/image-spec,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/opencontainers/runtime-spec,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/opencontainers/selinux,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/openshift/origin,Apache-2.0,Kubernetes,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/opentracing/opentracing-go,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/parnurzeal/gorequest,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/patrickmn/go-cache,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/paultag/sniff,Apache-2.0,Kubernetes,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/pborman/uuid,BSD-3-Clause,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/pelletier/go-buffruneio,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/pelletier/go-toml,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/petar/GoLLRB,BSD-3-Clause,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/peterbourgon/diskv,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/pierrec/lz4,BSD-3-Clause,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/pierrec/xxHash,BSD-3-Clause,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/pkg/browser,BSD-2-Clause,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/pkg/errors,BSD-2-Clause,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/pkg/profile,BSD-2-Clause,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/pkg/sftp,BSD-2-Clause,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/pmezard/go-difflib,BSD-3-Clause,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/pquerna/cachecontrol,BSD-3-Clause AND Apache-2.0,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/pquerna/ffjson,BSD-3-Clause AND Apache-2.0 AND ISC,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/prometheus/client_golang,BSD-3-Clause AND Apache-2.0 AND MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/prometheus/client_model,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/prometheus/common,BSD-3-Clause AND Apache-2.0,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/prometheus/procfs,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/PuerkitoBio/purell,BSD-3-Clause,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/PuerkitoBio/urlesc,BSD-3-Clause,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/r2d4/external-storage,Apache-2.0,Kubernetes,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/rackspace/gophercloud,Apache-2.0,Kubernetes,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/rancher/go-rancher,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/rcrowley/go-metrics,BSD-2-Clause-FreeBSD,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/renstrom/dedent,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/Rican7/retry,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/riemann/riemann-go-client,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/robfig/cron,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/russross/blackfriday,BSD-2-Clause,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/samalba/dockerclient,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/satori/go.uuid,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/scalingdata/gcfg,BSD-2-Clause AND BSD-3-Clause,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/sdboyer/constext,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/seccomp/libseccomp-golang,BSD-2-Clause,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/sergi/go-diff,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/Shopify/sarama,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/shurcooL/githubv4,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/shurcooL/go,BSD-3-Clause,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/shurcooL/graphql,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/shurcooL/sanitized_anchor_name,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/sirupsen/logrus,BSD-2-Clause AND BSD-3-Clause AND MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/skynetservices/skydns,Apache-2.0 AND MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/smartystreets/go-aws-auth,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/soheilhy/cmux,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/spf13/afero,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/spf13/cast,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/spf13/cobra,Apache-2.0 AND MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/spf13/jwalterweatherman,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/spf13/pflag,BSD-3-Clause,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/spf13/viper,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/storageos/go-api,BSD-2-Clause AND MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/streadway/quantile,BSD-2-Clause,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/stretchr/objx,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/stretchr/testify,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/syndtr/gocapability,BSD-2-Clause,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/tchap/go-patricia,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/thockin/glogr,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/thockin/logr,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/tmc/grpc-websocket-proxy,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/tsenart/vegeta,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/ugorji/go,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/Unknwon/goconfig,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/urfave/cli,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/vishvananda/netlink,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/vishvananda/netns,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/vmware/govmomi,BSD-3-Clause AND Apache-2.0,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/vmware/photon-controller-go-sdk,BSD-3-Clause AND Apache-2.0,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/weaveworks/mesh,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/xanzy/go-cloudstack,Apache-2.0,Kubernetes,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/xeipuuv/gojsonpointer,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/xeipuuv/gojsonreference,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +github.com/xeipuuv/gojsonschema,Apache-2.0 AND MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/xiang90/probing,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/zakjan/cert-chain-resolver,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +github.com/ziutek/syslog,BSD-3-Clause,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +go.opencensus.io,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +go.uber.org/atomic,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +go.uber.org/multierr,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +go.uber.org/zap,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +go4.org/errorutil,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +golang.org/x/build,LicenseRef-Google-Patents-Notice-Golang AND BSD-3-Clause,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +golang.org/x/exp,LicenseRef-Google-Patents-Notice-Golang AND BSD-3-Clause,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +golang.org/x/lint,BSD-3-Clause,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +golang.org/x/oauth2,BSD-3-Clause,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +golang.org/x/sync,LicenseRef-Google-Patents-Notice-Golang AND BSD-3-Clause,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +golang.org/x/sys,LicenseRef-Google-Patents-Notice-Golang AND BSD-2-Clause AND BSD-3-Clause,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +golang.org/x/text,LicenseRef-Google-Patents-Notice-Golang AND BSD-3-Clause,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +golang.org/x/time,LicenseRef-Google-Patents-Notice-Golang AND BSD-3-Clause,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +golang.org/x/tools,LicenseRef-Google-Patents-Notice-Golang AND BSD-3-Clause AND Apache-2.0 AND MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +golang/archive/tar,BSD-3-Clause,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +gonum.org/v1/gonum,BSD-3-Clause OR CC0-1.0 AND BSD-3-Clause,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +google.golang.org/cloud,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +google.golang.org/genproto,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +gopkg.in/check.v1,BSD-2-Clause AND BSD-3-Clause,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +gopkg.in/cheggaaa/pb.v1,BSD-3-Clause,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +gopkg.in/fsnotify,BSD-3-Clause,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +gopkg.in/gcfg.v1,BSD-3-Clause,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +gopkg.in/go-playground/pool.v3,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +gopkg.in/igm/sockjs-go.v2,BSD-3-Clause,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +gopkg.in/inf.v0,BSD-3-Clause,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +gopkg.in/natefinch/lumberjack.v2,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +gopkg.in/olivere/elastic.v3,BSD-3-Clause AND MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +gopkg.in/olivere/elastic.v5,BSD-3-Clause AND MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +gopkg.in/robfig/cron.v2,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +gopkg.in/square/go-jose.v2,BSD-3-Clause AND Apache-2.0,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +gopkg.in/src-d,Apache-2.0,All CNCF Projects,,apache-2.0,"Apache-2.0, no approval needed",2019-11-01, +gopkg.in/tomb.v1,BSD-3-Clause,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +jquery.scrollto,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +marked,BSD-3-Clause AND MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +mime,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +minimist,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +node-static,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +optimist,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +ui-router for Angular,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +vbom.ml/util,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +wordwrap,MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,allowlisted,2019-11-01, +VirtualBox Linux Guest Drivers Makefile,GPL-2.0-only,Kubernetes,Approved ONLY as an OPTIONl subdependency of Minikube (not approved for use on a standalone basis or as a required dependency),approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-05-20,2019-05-20, +Angular,MIT,All CNCF Projects,No scope restrictions,approved,contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11,2019-03-11, +Asciidoctor,MIT,All CNCF Projects,No scope restrictions,approved,contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11,2019-03-11, +Azure acr-docker-credential-helper,MIT,Kubernetes,No scope restrictions,approved,modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11,2019-03-11, +Backbone,MIT,All CNCF Projects,No scope restrictions,approved,contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11,2019-03-11, +bitbucket.org/bertimus9/systemstat,MIT,Kubernetes,No scope restrictions,approved,not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11,2019-03-11, +bitbucket.org/ww/goautoneg,BSD-3-Clause,All CNCF Projects,No scope restrictions,approved,not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11,2019-03-11, +bootstrap,CC-BY-3.0 AND MIT,All CNCF Projects,No scope restrictions,approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11,2019-03-11, +dialog-polyfill.css,BSD-3-Clause,All CNCF Projects,No scope restrictions,approved,contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11,2019-03-11, +font-awesome,CC-BY-3.0 AND MIT AND OFL-1.1,All CNCF Projects,No scope restrictions,approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11,2019-03-11, +Gingko,MIT,All CNCF Projects,No scope restrictions,approved,contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11,2019-03-11, +github.com/Azure/azure-pipeline-go,MIT,Kubernetes,No scope restrictions,approved,not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11,2019-03-11, +github.com/bungle/lua-resty-template,BSD-3-Clause,Ingress-Nginx,No scope restrictions,approved,modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11,2019-03-11, +github.com/c4milo/gotoolkit,MPL-2.0,All CNCF Projects,"Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository",approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11,2019-03-11, +github.com/client9/misspell,Unlicense AND BSD-3-Clause AND MIT,All CNCF Projects,No scope restrictions,approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11,2019-03-11, +github.com/d2g/dhcp4,BSD-3-Clause,Kubernetes,No scope restrictions,approved,not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11,2019-03-11, +github.com/d2g/dhcp4client,MPL-2.0,Kubernetes,"Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository",approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11,2019-03-11, +github.com/dgryski/go-onlinestats,MIT AND LicenseRef-Public-domain-statement,OpenTelemetry,No scope restrictions,approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11,2019-03-11, +github.com/docker/go-units,CC-BY-SA-4.0 AND CC-BY-4.0 AND Apache-2.0,All CNCF Projects,No scope restrictions,approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11,2019-03-11, +github.com/docker/spdystream,CC-BY-SA-4.0 AND CC-BY-4.0 AND BSD-3-Clause AND Apache-2.0,Kubernetes,No scope restrictions,approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11,2019-03-11, +github.com/go-sql-driver/mysql,MPL-2.0,All CNCF Projects,"Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository",approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11,2019-03-11, +github.com/gonum/graph,BSD-3-Clause,All CNCF Projects,No scope restrictions,approved,modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11,2019-03-11, +github.com/google/go-github,BSD-3-Clause AND CC-BY-3.0,All CNCF Projects,No scope restrictions,approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11,2019-03-11, +github.com/grpc-ecosystem/grpc-opentracing,BSD-3-Clause AND LicenseRef-Google-Patents-Notice-GRPC,All CNCF Projects,No scope restrictions,approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11,2019-03-11, +github.com/hashicorp/errwrap,MPL-2.0,All CNCF Projects,"Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository",approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11,2019-03-11, +github.com/hashicorp/go-cleanhttp,MPL-2.0,All CNCF Projects,"Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository",approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11,2019-03-11, +github.com/hashicorp/go-multierror,MPL-2.0,All CNCF Projects,"Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository",approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11,2019-03-11, +github.com/hashicorp/golang-lru,MPL-2.0,All CNCF Projects,"Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository",approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11,2019-03-11, +github.com/hashicorp/hcl,MPL-2.0,All CNCF Projects,"Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository",approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11,2019-03-11, +github.com/hooklift/iso9660,MPL-2.0,Kubernetes,"Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository",approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11,2019-03-11, +github.com/howeyc/gopass,ISC AND CDDL-1.0,Kubernetes,"Allowed only if the dependency files are either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository",approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11,2019-03-11, +github.com/jbenet/go-context,MIT,All CNCF Projects,No scope restrictions,approved,not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11,2019-03-11, +github.com/JeffAshton/win_pdh,BSD-3-Clause,Kubernetes,No scope restrictions,approved,not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11,2019-03-11, +github.com/jmank88/nuts,MIT,All CNCF Projects,No scope restrictions,approved,not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11,2019-03-11, +github.com/johanneswuerbach/nfsexports,MIT,Kubernetes,No scope restrictions,approved,not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11,2019-03-11, +github.com/joshdk/go-junit,MIT,All CNCF Projects,No scope restrictions,approved,not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11,2019-03-11, +github.com/jteeuwen/go-bindata,CC0-1.0,All CNCF Projects,No scope restrictions,approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11,2019-03-11, +github.com/konsorten/go-windows-terminal-sequences,MIT,All CNCF Projects,No scope restrictions,approved,not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11,2019-03-11, +github.com/marstr/guid,MIT,All CNCF Projects,No scope restrictions,approved,not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11,2019-03-11, +github.com/mattn/go-sqlite3,MIT AND LicenseRef-Public-domain-statement,All CNCF Projects,No scope restrictions,approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11,2019-03-11, +github.com/multiarch/qemu-user-static,MIT,All CNCF Projects,No scope restrictions,approved,modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11,2019-03-11, +github.com/Nvveen/Gotty,BSD-2-Clause-FreeBSD,All CNCF Projects,No scope restrictions,approved,not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11,2019-03-11, +github.com/opencontainers/go-digest,CC-BY-SA-4.0 AND CC-BY-4.0 AND Apache-2.0,All CNCF Projects,No scope restrictions,approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11,2019-03-11, +github.com/opencontainers/runc,CC-BY-4.0 AND Apache-2.0,All CNCF Projects,No scope restrictions,approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11,2019-03-11, +github.com/quobyte/api,BSD-3-Clause,Kubernetes,No scope restrictions,approved,not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11,2019-03-11, +github.com/rubiojr/go-vhd,MIT,Kubernetes,No scope restrictions,approved,not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11,2019-03-11, +github.com/sigma/go-inotify,LicenseRef-Google-Patents-Notice-Golang AND BSD-3-Clause,Kubernetes,No scope restrictions,approved,not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11,2019-03-11, +github.com/spotinst/spotinst-sdk-go,BSD-3-Clause AND Apache-2.0 AND MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11,2019-03-11, +github.com/src-d/gcfg,BSD-3-Clause,All CNCF Projects,No scope restrictions,approved,not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11,2019-03-11, +github.com/tent/http-link-go,BSD-3-Clause,All CNCF Projects,No scope restrictions,approved,not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11,2019-03-11, +github.com/xanzy/ssh-agent,Apache-2.0 AND MIT,OpenTelemetry,No scope restrictions,approved,not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11,2019-03-11, +github.com/zchee/go-vmnet,BSD-2-Clause AND BSD-3-Clause,Kubernetes & Minikube,No scope restrictions,approved,not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11,2019-03-11, +go-srcimporter,BSD-3-Clause,All CNCF Projects,No scope restrictions,approved,modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11,2019-03-11, +go9p,BSD-3-Clause,All CNCF Projects,No scope restrictions,approved,modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11,2019-03-11, +godep,BSD-3-Clause,All CNCF Projects,No scope restrictions,approved,modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11,2019-03-11, +golang.org/x/crypto,LicenseRef-Google-Patents-Notice-Golang AND BSD-3-Clause AND MIT AND LicenseRef-Public-domain-statement,All CNCF Projects,No scope restrictions,approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11,2019-03-11, +golang.org/x/net,LicenseRef-Google-Patents-Notice-Golang AND BSD-2-Clause AND BSD-3-Clause AND CC-BY-3.0 AND BSD-3-Clause OR LicenseRef-W3C-Test-Suite-License-1,All CNCF Projects,No scope restrictions,approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11,2019-03-11, +golang/expansion,LicenseRef-Google-Patents-Notice-Golang AND BSD-3-Clause,All CNCF Projects,No scope restrictions,approved,modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11,2019-03-11, +golang/go/types,LicenseRef-Google-Patents-Notice-Golang AND BSD-3-Clause,All CNCF Projects,No scope restrictions,approved,modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11,2019-03-11, +golang/internal/srcimporter,BSD-3-Clause,All CNCF Projects,No scope restrictions,approved,modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11,2019-03-11, +golang/json,BSD-3-Clause,All CNCF Projects,No scope restrictions,approved,modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11,2019-03-11, +golang/netutil,BSD-3-Clause,All CNCF Projects,No scope restrictions,approved,modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11,2019-03-11, +golang/reflect,LicenseRef-Google-Patents-Notice-Golang AND BSD-3-Clause,All CNCF Projects,No scope restrictions,approved,modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11,2019-03-11, +golang/template,LicenseRef-Google-Patents-Notice-Golang AND BSD-3-Clause,All CNCF Projects,No scope restrictions,approved,modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11,2019-03-11, +Google Protocol Buffers,BSD-3-Clause,All CNCF Projects,No scope restrictions,approved,contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11,2019-03-11, +google.golang.org/api,BSD-3-Clause AND Apache-2.0 AND MIT,All CNCF Projects,See Allowlist Policy requirements,allowlisted,not auto-allowlist because: No measure of stars / forks; approved by GB exception 2019-03-11,2019-03-11, +google.golang.org/appengine,BSD-3-Clause AND Apache-2.0,Kubernetes,No scope restrictions,approved,not auto-allowlist because: No measure of stars / forks; approved by GB exception 2019-03-11,2019-03-11, +google.golang.org/grpc,BSD-3-Clause AND Apache-2.0 AND LicenseRef-Google-Patents-Notice-GRPC,All CNCF Projects,No scope restrictions,approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11,2019-03-11, +gopkg.in/warnings.v0,BSD-2-Clause,All CNCF Projects,No scope restrictions,approved,not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11,2019-03-11, +Handlebars,MIT,All CNCF Projects,No scope restrictions,approved,contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11,2019-03-11, +Highlight,BSD-3-Clause,All CNCF Projects,No scope restrictions,approved,contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11,2019-03-11, +highlight.js,BSD-3-Clause AND MIT AND CC0-1.0 AND LicenseRef-Public-domain-statement,All CNCF Projects,No scope restrictions,approved,not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11,2019-03-11, +htpasswd,BSD-3-Clause,All CNCF Projects,No scope restrictions,approved,not auto-allowlist because: No measure of stars / forks; approved by GB exception 2019-03-11,2019-03-11, +jQuery,MIT,All CNCF Projects,No scope restrictions,approved,contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11,2019-03-11, +jQuery BBQ,MIT OR GPL-2.0+,All CNCF Projects,Any CNCF project using this dependency must elect to do so under the MIT License (rather than GPL-2.0) and declare such election in its documentation,approved,contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11,2019-03-11, +jQuery hashchange event,GPL-2.0+ OR MIT,All CNCF Projects,Any CNCF project using this dependency must elect to do so under the MIT License (rather than GPL-2.0) and declare such election in its documentation,approved,contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11,2019-03-11, +jQuery Slideto,MIT,All CNCF Projects,No scope restrictions,approved,contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11,2019-03-11, +jQuery Wiggle,MIT,All CNCF Projects,No scope restrictions,approved,contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11,2019-03-11, +moment.js,MIT,All CNCF Projects,No scope restrictions,approved,contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11,2019-03-11, +normalize.css,MIT,All CNCF Projects,No scope restrictions,approved,contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11,2019-03-11, +Octicons,MIT,All CNCF Projects,No scope restrictions,approved,contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11,2019-03-11, +parseUri,MIT,All CNCF Projects,No scope restrictions,approved,contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11,2019-03-11, +Pause,MIT,Kubernetes,No scope restrictions,approved,not auto-allowlist because: No measure of stars / forks; approved by GB exception 2019-03-11,2019-03-11, +Pure CSS,BSD-3-Clause,All CNCF Projects,No scope restrictions,approved,contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11,2019-03-11, +shred,ISC,All CNCF Projects,No scope restrictions,approved,contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11,2019-03-11, +sigs.k8s.io/yaml,BSD-3-Clause AND MIT,Kubernetes,Approved for Kubernetes only,approved,fork of github.com/ghodss/yaml; not auto-allowlist because: Modified; approved by GB exception 2019-03-11,2019-03-11, +speter.net/go/exp,BSD-2-Clause AND BSD-3-Clause,Oopentelemetry,No scope restrictions,approved,not auto-allowlist because: No measure of stars / forks; approved by GB exception 2019-03-11,2019-03-11, +sprintf() for JavaScript,BSD-3-Clause,All CNCF Projects,No scope restrictions,approved,contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11,2019-03-11, +Underscore.js,MIT,All CNCF Projects,No scope restrictions,approved,contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11,2019-03-11, diff --git a/license-exceptions/cncf-exceptions-current.spdx b/license-exceptions/cncf-exceptions-current.spdx index 9faa3882..df0c4237 100644 --- a/license-exceptions/cncf-exceptions-current.spdx +++ b/license-exceptions/cncf-exceptions-current.spdx @@ -1,10 +1,10 @@ SPDXVersion: SPDX-2.1 DataLicense: CC0-1.0 SPDXID: SPDXRef-DOCUMENT -DocumentName: cncf-exceptions-2026-02-04 -DocumentNamespace: https://github.com/cncf/foundation/license-exceptions-2026-02-04 +DocumentName: cncf-exceptions-2026-06-01 +DocumentNamespace: https://github.com/cncf/foundation/license-exceptions-2026-06-01 Creator: Organization: CNCF -Created: 2026-02-04T12:00:00Z +Created: 2026-06-01T12:00:00Z ##### Package: eclipse-ee4j/expressly @@ -15,7 +15,7 @@ FilesAnalyzed: false PackageLicenseConcluded: EPL-2.0 OR GPL-2.0-only WITH Classpath-exception-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Project: Keycloak. Scope: required upstream dependency, dynamically linked, unmodified. Status: approved. Default implementation of Jakarta Expression Language 6.0, transitive dependency for Hibernate Validator +PackageComment: Project: Keycloak. Scope: Approved for dynamic linking only (static linking not permitted); furthermore, the dependency must be used in unmodified form. Status: approved. Default implementation of Jakarta Expression Language 6.0, transitive dependency for Hibernate Validator ##### Package: libpathrs @@ -26,7 +26,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MPL-2.0 OR LGPL-3.0-or-later PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Project: All CNCF Projects. Scope: vendored component, build-time dependency, or install-time dependency; statically or dynamically linked. Status: approved. Blanket exception: Projects using libpathrs statically linked MUST elect MPL-2.0 and document this. Provides secure path resolution APIs. +PackageComment: Project: All CNCF Projects. Scope: Any CNCF project using libpathrs as a statically linked dependency MUST elect to do so under MPL-2.0 (rather than LGPL-3.0) and declare such election in its documentation. Furthermore, to minimize compliance burdens for CNCF projects and downstream users, it is strongly recommended that projects using libpathrs as a dynamically linked dependency also elect to do so under MPL-2.0 (rather than LGPL-3.0). Furthermore, libpathrs must be maintained either (a) in a distinct directory or module clearly separated from CNCF project code, or (b) retrieved at build/installation time from a third-party repository.. Status: approved. Blanket exception: Projects using libpathrs statically linked MUST elect MPL-2.0 and document this. Provides secure path resolution APIs. ##### Package: go-pathrs @@ -37,7 +37,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MPL-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Project: All CNCF Projects. Scope: vendored component, build-time dependency, or install-time dependency; statically or dynamically linked. Status: approved. Blanket exception: Go bindings for libpathrs. Provides secure path resolution APIs. +PackageComment: Project: All CNCF Projects. Scope: Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository. Status: approved. Blanket exception: Go bindings for libpathrs. Provides secure path resolution APIs. ##### Package: cyphar/filepath-securejoin @@ -48,7 +48,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MPL-2.0 AND BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Project: All CNCF Projects. Scope: vendored component, build-time dependency, or install-time dependency; statically or dynamically linked. Status: approved. Blanket exception: Provides secure path resolution APIs on Linux. Used by Kubernetes, containerd, Podman, buildah, cri-o, nerdctl. +PackageComment: Project: All CNCF Projects. Scope: Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository. Status: approved. Blanket exception: Provides secure path resolution APIs on Linux. Used by Kubernetes, containerd, Podman, buildah, cri-o, nerdctl. ##### Package: Liquibase @@ -56,10 +56,10 @@ PackageName: Liquibase SPDXID: SPDXRef-Package5 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: FSL (Functional Source License) +PackageLicenseConcluded: FSL Functional Source License PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Project: Keycloak. Scope: incorporated code, dynamically linked. Status: denied. Denied: FSL is not an open source license. GB does not approve exceptions for non-OSS licenses. +PackageComment: Project: Keycloak. Scope: Not Applicable (Denied). Status: denied. Denied: FSL is not an open source license. GB does not approve exceptions for non-OSS licenses. ##### Package: paramiko @@ -70,7 +70,7 @@ FilesAnalyzed: false PackageLicenseConcluded: LGPL-2.1 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Project: oscal-compass. Scope: build-time dependency, dynamically linked. Status: approved. Pure-Python SSHv2 protocol implementation, used for fetching files +PackageComment: Project: oscal-compass. Scope: Approved only for dynamic linking (static linking is not approved). Status: approved. Pure-Python SSHv2 protocol implementation, used for fetching files ##### Package: certifi @@ -81,7 +81,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MPL-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Project: oscal-compass. Scope: install-time dependency, dynamically linked. Status: approved. Dependency for requests library +PackageComment: Project: oscal-compass. Scope: Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository. Status: approved. Dependency for requests library ##### Package: pathspec @@ -92,7 +92,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MPL-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Project: oscal-compass. Scope: build-time dependency, separate process. Status: approved. Dependency for black, mkdocs, mypy +PackageComment: Project: oscal-compass. Scope: Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository. Status: approved. Dependency for black, mkdocs, mypy ##### Package: cyphar/filepath-securejoin @@ -103,7 +103,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-3-Clause AND MPL-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Project: Kubernetes. Scope: vendored component, build-time dependency, statically linked. Status: approved. Provides secure path construction functions. Superseded by blanket exception in issue #1154. +PackageComment: Project: Kubernetes. Scope: No scope restrictions. Status: approved. Provides secure path construction functions. Superseded by blanket exception in issue #1154. ##### Package: hashicorp/terraform-provider-aws @@ -114,7 +114,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MPL-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Project: Crossplane. Scope: build-time dependency, modified fork. Status: approved. Fork maintained for Crossplane providers, changes contributed upstream +PackageComment: Project: Crossplane. Scope: Allowed only if the modified fork is stored in a seperate designated folder separate from the project's own code. Status: approved. Fork maintained for Crossplane providers, changes contributed upstream ##### Package: hashicorp/terraform-provider-azurerm @@ -125,7 +125,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MPL-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Project: Crossplane. Scope: build-time dependency, modified fork. Status: approved. Fork maintained for Crossplane providers, changes contributed upstream +PackageComment: Project: Crossplane. Scope: Allowed only if the modified fork is stored in a seperate designated folder separate from the project's own code. Status: approved. Fork maintained for Crossplane providers, changes contributed upstream ##### Package: hashicorp/terraform-provider-azuread @@ -136,7 +136,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MPL-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Project: Crossplane. Scope: build-time dependency, modified fork. Status: approved. Fork maintained for Crossplane providers, changes contributed upstream +PackageComment: Project: Crossplane. Scope: Allowed only if the modified fork is stored in a seperate designated folder separate from the project's own code. Status: approved. Fork maintained for Crossplane providers, changes contributed upstream ##### Package: apple/swift-nio-ssl @@ -147,7 +147,7 @@ FilesAnalyzed: false PackageLicenseConcluded: OpenSSL PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Project: Connect. Scope: build-time dependency, unmodified. Status: approved. Required for HTTP/2 + TLS with HTTP trailers on iOS. Also used by gRPC Swift. +PackageComment: Project: Connect. Scope: Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository. Status: approved. Required for HTTP/2 + TLS with HTTP trailers on iOS. Also used by gRPC Swift. ##### Package: Crossplane Upjet MPL dependencies @@ -158,7 +158,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MPL-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Project: Crossplane. Scope: build-time dependency, unmodified, linked at build time. Status: approved. Various hashicorp terraform dependencies for Upjet: hcl, terraform-json, terraform-plugin-framework, terraform-plugin-go, terraform-plugin-sdk, go-plugin, go-uuid, go-version, logutils, terraform-plugin-log, terraform-registry-address, terraform-svchost, yamux +PackageComment: Project: Crossplane. Scope: Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository. Status: approved. Various hashicorp terraform dependencies for Upjet: hcl, terraform-json, terraform-plugin-framework, terraform-plugin-go, terraform-plugin-sdk, go-plugin, go-uuid, go-version, logutils, terraform-plugin-log, terraform-registry-address, terraform-svchost, yamux ##### Package: Linux kernel uapi headers (btrfs) @@ -169,7 +169,7 @@ FilesAnalyzed: false PackageLicenseConcluded: GPL-2.0-only WITH Linux-syscall-note PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Project: containerd. Scope: kernel headers included via #include, no inline functions compiled in. Status: approved. Used by containerd/btrfs for btrfs-related ioctl syscalls. Headers from linux/btrfs.h and linux/btrfs_tree.h. +PackageComment: Project: containerd. Scope: Approved only for ue by containerd as described in the exception request. Status: approved. Used by containerd/btrfs for btrfs-related ioctl syscalls. Headers from linux/btrfs.h and linux/btrfs_tree.h. ##### Package: hashicorp/go-set/v2 @@ -180,7 +180,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MPL-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Project: OpenFGA. Scope: build-time dependency, linked at build time. Status: approved. Unmodified code +PackageComment: Project: OpenFGA. Scope: Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository. Status: approved. Unmodified code ##### Package: Keycloak Java dependencies @@ -191,7 +191,7 @@ FilesAnalyzed: false PackageLicenseConcluded: 0BSD, CDDL-1.1, EPL-1.0, EPL-2.0, GPL-2.0-only, GPL-2.0-with-classpath-exception, LGPL-2.1, LGPL-2.1-only, MIT-0, MPL-2.0, UPL-1.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Project: Keycloak. Scope: transitive dependencies from Quarkus framework, unmodified. Status: approved. Multiple Java dependencies including: tslib, h2, mysql-connector-j, jakarta.* APIs, parsson, graalvm SDK, hibernate-*, mariadb-java-client, nashorn-core, reactive-streams +PackageComment: Project: Keycloak. Scope: Approved for use by Keycloak only in unmodified form. Status: approved. Multiple Java dependencies including: tslib, h2, mysql-connector-j, jakarta.* APIs, parsson, graalvm SDK, hibernate-*, mariadb-java-client, nashorn-core, reactive-streams ##### Package: hashicorp/memberlist @@ -202,7 +202,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MPL-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Project: kubernetes/kops. Scope: build-time dependency, unmodified. Status: approved. Main component of Gossip DNS feature for peer-to-peer network K8s API address propagation +PackageComment: Project: kubernetes/kops. Scope: Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository. Status: approved. Main component of Gossip DNS feature for peer-to-peer network K8s API address propagation ##### Package: Falco kernel module @@ -213,7 +213,7 @@ FilesAnalyzed: false PackageLicenseConcluded: GPL-2.0-only OR MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Project: Falco. Scope: kernel module, dual-licensed. Status: approved. Falco's kernel module is dual-licensed GPL-2.0-only OR MIT +PackageComment: Project: Falco. Scope: Approved for use by Falco only. Status: approved. Falco's kernel module is dual-licensed GPL-2.0-only OR MIT ##### Package: In-kernel eBPF programs @@ -224,18 +224,18 @@ FilesAnalyzed: false PackageLicenseConcluded: GPL-2.0-only, GPL-2.0-or-later PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Project: All CNCF Projects. Scope: in-kernel eBPF programs only. Status: approved. Blanket exception: GPL-2.0 licensed code is permitted for in-kernel eBPF programs only, as this is required by the Linux kernel BPF subsystem. +PackageComment: Project: All CNCF Projects. Scope: Exception applies only to code that runs inside the kernel (not to any code running in the user-space). Status: approved. Blanket exception: GPL-2.0 licensed code is permitted for in-kernel eBPF programs only, as this is required by the Linux kernel BPF subsystem. -##### Package: docker/go-metrics +##### Package: docker/go-metrics documentation -PackageName: docker/go-metrics +PackageName: docker/go-metrics documentation SPDXID: SPDXRef-Package21 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false PackageLicenseConcluded: CC-BY-SA 4.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: runtime dependency, statically linked. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-08-31 +PackageComment: Project: Cilium. Scope: Approval applies only to use of documentation in unmodified form. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-08-31 ##### Package: hashicorp/go-memdb @@ -246,7 +246,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MPL-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Project: Cilium. Scope: runtime dependency, dynamically linked. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-08-31 +PackageComment: Project: Cilium. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-08-31 ##### Package: shoenig/go-m1cpu @@ -257,7 +257,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MPL-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build dependency. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-08-31 +PackageComment: Project: Kubernetes. Scope: Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-08-31 ##### Package: hashicorp/packer-plugin-sdk @@ -268,7 +268,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MPL-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-08-31 +PackageComment: Project: All CNCF Projects. Scope: Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-08-31 ##### Package: hashicorp/consul/api @@ -279,7 +279,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MPL-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Project: Cilium. Scope: build-time dependency, unmodified. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27 +PackageComment: Project: Cilium. Scope: Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27 ##### Package: hashicorp/go-hclog @@ -290,7 +290,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MPL-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Project: Cilium. Scope: build-time dependency, unmodified. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27 +PackageComment: Project: Cilium. Scope: Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27 ##### Package: hashicorp/go-immutable-radix @@ -301,7 +301,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MPL-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Project: Cilium. Scope: build-time dependency, unmodified. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27 +PackageComment: Project: Cilium. Scope: Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27 ##### Package: hashicorp/go-plugin @@ -312,7 +312,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MPL-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency, unmodified. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27 +PackageComment: Project: All CNCF Projects. Scope: Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27 ##### Package: hashicorp/go-rootcerts @@ -323,7 +323,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MPL-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Project: Cilium. Scope: build-time dependency, unmodified. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27 +PackageComment: Project: Cilium. Scope: Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27 ##### Package: hashicorp/go-secure-stdlib @@ -334,7 +334,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MPL-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27 +PackageComment: Project: All CNCF Projects. Scope: Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27 ##### Package: hashicorp/go-sockaddr @@ -345,7 +345,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MPL-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27 +PackageComment: Project: All CNCF Projects. Scope: Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27 ##### Package: hashicorp/go-uuid @@ -356,7 +356,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MPL-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27 +PackageComment: Project: All CNCF Projects. Scope: Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27 ##### Package: hashicorp/serf @@ -367,7 +367,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MPL-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Project: Cilium. Scope: build-time dependency, unmodified. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27 +PackageComment: Project: Cilium. Scope: Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27 ##### Package: hashicorp/vault @@ -378,7 +378,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MPL-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency, unmodified. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27 +PackageComment: Project: All CNCF Projects. Scope: Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27 ##### Package: veraison/go-cose @@ -389,7 +389,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MPL-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Project: Notary. Scope: build-time dependency, unmodified. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27 +PackageComment: Project: Notary. Scope: Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27 ##### Package: hashicorp/consul/api @@ -400,7 +400,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MPL-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27 +PackageComment: Project: All CNCF Projects. Scope: Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27 ##### Package: hashicorp/go-hclog @@ -411,7 +411,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MPL-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27 +PackageComment: Project: All CNCF Projects. Scope: Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27 ##### Package: hashicorp/go-immutable-radix @@ -422,7 +422,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MPL-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27 +PackageComment: Project: All CNCF Projects. Scope: Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27 ##### Package: hashicorp/go-plugin @@ -433,7 +433,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MPL-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency, unmodified. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27 +PackageComment: Project: All CNCF Projects. Scope: Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27 ##### Package: hashicorp/go-rootcerts @@ -444,7 +444,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MPL-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27 +PackageComment: Project: All CNCF Projects. Scope: Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27 ##### Package: hashicorp/go-secure-stdlib @@ -455,7 +455,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MPL-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27 +PackageComment: Project: All CNCF Projects. Scope: Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27 ##### Package: hashicorp/go-sockaddr @@ -466,7 +466,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MPL-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27 +PackageComment: Project: All CNCF Projects. Scope: Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27 ##### Package: hashicorp/go-uuid @@ -477,7 +477,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MPL-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27 +PackageComment: Project: All CNCF Projects. Scope: Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27 ##### Package: hashicorp/go-version @@ -488,7 +488,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MPL-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency, unmodified. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27 +PackageComment: Project: All CNCF Projects. Scope: Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27 ##### Package: hashicorp/raft @@ -499,7 +499,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MPL-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27 +PackageComment: Project: All CNCF Projects. Scope: Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27 ##### Package: hashicorp/serf @@ -510,7 +510,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MPL-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27 +PackageComment: Project: All CNCF Projects. Scope: Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27 ##### Package: hashicorp/vault @@ -521,7 +521,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MPL-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency, unmodified. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27 +PackageComment: Project: All CNCF Projects. Scope: Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27 ##### Package: hashicorp/yamux @@ -532,7 +532,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MPL-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency, unmodified. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27 +PackageComment: Project: All CNCF Projects. Scope: Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27 ##### Package: veraison/go-cose @@ -543,7 +543,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MPL-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Project: Notary. Scope: build-time dependency, unmodified. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27 +PackageComment: Project: Notary. Scope: Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27 ##### Package: eclipse/paho.mqtt.golang @@ -554,7 +554,7 @@ FilesAnalyzed: false PackageLicenseConcluded: EPL-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency, unmodified. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2022-04-12 +PackageComment: Project: All CNCF Projects. Scope: Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2022-04-12 ##### Package: hashicorp/go-version @@ -565,7 +565,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MPL-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency, unmodified. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2022-04-12 +PackageComment: Project: All CNCF Projects. Scope: Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2022-04-12 ##### Package: hashicorp/raft @@ -576,7 +576,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MPL-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Project: Dapr. Scope: build-time dependency, unmodified. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2022-04-12 +PackageComment: Project: Dapr. Scope: Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2022-04-12 ##### Package: hashicorp/raft-boltdb @@ -587,7 +587,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MPL-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Project: Dapr. Scope: build-time dependency, unmodified. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2022-04-12 +PackageComment: Project: Dapr. Scope: Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2022-04-12 ##### Package: Microsoft/tslib @@ -598,7 +598,7 @@ FilesAnalyzed: false PackageLicenseConcluded: 0BSD PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency, unmodified. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2022-04-12 +PackageComment: Project: All CNCF Projects. Scope: No scope restrictions. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2022-04-12 ##### Package: go-version @@ -609,7 +609,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MPL-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency, unmodified. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2022-04-12 +PackageComment: Project: All CNCF Projects. Scope: Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2022-04-12 ##### Package: paho.mqtt.golang @@ -620,7 +620,7 @@ FilesAnalyzed: false PackageLicenseConcluded: EPL-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency, unmodified. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2022-04-12 +PackageComment: Project: All CNCF Projects. Scope: Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2022-04-12 ##### Package: raft @@ -631,7 +631,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MPL-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Project: Dapr. Scope: build-time dependency, unmodified. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2022-04-12 +PackageComment: Project: Dapr. Scope: Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2022-04-12 ##### Package: raft-boltdb @@ -642,7 +642,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MPL-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Project: Dapr. Scope: build-time dependency, unmodified. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2022-04-12 +PackageComment: Project: Dapr. Scope: Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2022-04-12 ##### Package: tslib @@ -653,7 +653,7 @@ FilesAnalyzed: false PackageLicenseConcluded: 0BSD PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency, unmodified. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2022-04-12 +PackageComment: Project: All CNCF Projects. Scope: No scope restrictions. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2022-04-12 ##### Package: webpki-roots @@ -664,7 +664,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MPL-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency, unmodified. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2022-04-12 +PackageComment: Project: All CNCF Projects. Scope: Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2022-04-12 ##### Package: hashicorp/go-retryablehttp @@ -675,7 +675,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MPL-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency, unmodified. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2021-07-19 +PackageComment: Project: All CNCF Projects. Scope: Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2021-07-19 ##### Package: go-retryablehttp @@ -686,7 +686,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MPL-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency, unmodified. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2021-07-19 +PackageComment: Project: All CNCF Projects. Scope: Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2021-07-19 ##### Package: Chart.js @@ -697,7 +697,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: cloud.google.com/go @@ -708,7 +708,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: code.cloudfoundry.org/clock @@ -719,7 +719,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: colors @@ -730,7 +730,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: defusedxml @@ -741,7 +741,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Python-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: ejs @@ -749,10 +749,10 @@ PackageName: ejs SPDXID: SPDXRef-Package68 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (Apache-2.0 AND MIT) +PackageLicenseConcluded: Apache-2.0 AND MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: abbot/go-http-auth @@ -763,7 +763,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: Kubernetes. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: aclements/go-moremath @@ -774,7 +774,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: andygrunwald/go-gerrit @@ -785,7 +785,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: aokoli/goutils @@ -796,7 +796,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: appc/spec @@ -807,7 +807,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: armon/circbuf @@ -818,7 +818,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: armon/go-proxyproto @@ -829,7 +829,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: armon/go-radix @@ -840,7 +840,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: asaskevich/govalidator @@ -851,7 +851,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: aws/aws-k8s-tester @@ -862,7 +862,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: Kubernetes. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: aws/aws-sdk-go @@ -870,10 +870,10 @@ PackageName: aws/aws-sdk-go SPDXID: SPDXRef-Package79 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: ((MIT OR GPL-3.0) AND BSD-3-Clause AND Apache-2.0 AND MIT) +PackageLicenseConcluded: (MIT OR GPL-3.0) AND BSD-3-Clause AND Apache-2.0 AND MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: Allowed as long as the CNCF project imports this SDK through standard dependency management rather than modifying the core SDK code. Status: approved. allowlisted ##### Package: Azure/azure-sdk-for-go @@ -884,7 +884,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: Azure/azure-storage-blob-go @@ -895,7 +895,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: Azure/go-ansiterm @@ -906,7 +906,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: Azure/go-autorest @@ -917,7 +917,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: bazelbuild/bazel-gazelle @@ -928,7 +928,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: bazelbuild/buildtools @@ -939,7 +939,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: beorn7/perks @@ -950,7 +950,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: blang/semver @@ -961,7 +961,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: bluebreezecf/opentsdb-goclient @@ -972,7 +972,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: Kubernetes. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: boltdb/bolt @@ -983,7 +983,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: bwmarrin/snowflake @@ -994,7 +994,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-2-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: chai2010/gettext-go @@ -1005,7 +1005,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: cloudflare/cfssl @@ -1013,10 +1013,10 @@ PackageName: cloudflare/cfssl SPDXID: SPDXRef-Package92 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (BSD-2-Clause AND BSD-3-Clause AND ISC) +PackageLicenseConcluded: BSD-2-Clause AND BSD-3-Clause AND ISC PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: cloudfoundry-incubator/candiedyaml @@ -1024,10 +1024,10 @@ PackageName: cloudfoundry-incubator/candiedyaml SPDXID: SPDXRef-Package93 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (Apache-2.0 AND MIT) +PackageLicenseConcluded: Apache-2.0 AND MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: clusterhq/flocker-go @@ -1038,7 +1038,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: Kubernetes. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: cockroachdb/cmux @@ -1049,7 +1049,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: codedellemc/goscaleio @@ -1060,7 +1060,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: Kubernetes. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: container-storage-interface/spec @@ -1071,7 +1071,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: containerd/console @@ -1082,7 +1082,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: containerd/containerd @@ -1090,10 +1090,10 @@ PackageName: containerd/containerd SPDXID: SPDXRef-Package99 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (CC-BY-4.0 AND Apache-2.0) +PackageLicenseConcluded: CC-BY-4.0 AND Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: containernetworking/cni @@ -1104,7 +1104,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: containernetworking/plugins @@ -1115,7 +1115,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: coredns/coredns @@ -1126,7 +1126,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: coreos/bbolt @@ -1137,7 +1137,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: coreos/etcd @@ -1145,10 +1145,10 @@ PackageName: coreos/etcd SPDXID: SPDXRef-Package104 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (BSD-3-Clause AND Apache-2.0) +PackageLicenseConcluded: BSD-3-Clause AND Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: coreos/go-etcd @@ -1159,7 +1159,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: coreos/go-oidc @@ -1170,7 +1170,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: coreos/go-semver @@ -1181,7 +1181,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: coreos/go-systemd @@ -1192,7 +1192,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: coreos/pkg @@ -1203,7 +1203,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: coreos/rkt @@ -1214,7 +1214,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: cpuguy83/go-md2man @@ -1225,7 +1225,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: cyphar/filepath-securejoin @@ -1236,7 +1236,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: daaku/go.zipexe @@ -1247,7 +1247,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: davecgh/go-spew @@ -1258,7 +1258,7 @@ FilesAnalyzed: false PackageLicenseConcluded: ISC PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: daviddengcn/go-colortext @@ -1266,10 +1266,10 @@ PackageName: daviddengcn/go-colortext SPDXID: SPDXRef-Package115 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (BSD-3-Clause AND MIT) +PackageLicenseConcluded: BSD-3-Clause AND MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: dchest/safefile @@ -1280,7 +1280,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-2-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: deckarep/golang-set @@ -1291,7 +1291,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: denverdino/aliyungo @@ -1302,7 +1302,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: Kubernetes. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: dgrijalva/jwt-go @@ -1313,7 +1313,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: digitalocean/godo @@ -1321,10 +1321,10 @@ PackageName: digitalocean/godo SPDXID: SPDXRef-Package120 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (BSD-3-Clause AND MIT) +PackageLicenseConcluded: BSD-3-Clause AND MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: djherbis/atime @@ -1332,10 +1332,10 @@ PackageName: djherbis/atime SPDXID: SPDXRef-Package121 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (BSD-3-Clause AND MIT) +PackageLicenseConcluded: BSD-3-Clause AND MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: docker/cli @@ -1343,10 +1343,10 @@ PackageName: docker/cli SPDXID: SPDXRef-Package122 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (Apache-2.0 AND MIT) +PackageLicenseConcluded: Apache-2.0 AND MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: docker/distribution @@ -1357,7 +1357,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: docker/docker @@ -1365,10 +1365,10 @@ PackageName: docker/docker SPDXID: SPDXRef-Package124 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (Apache-2.0 AND MIT) +PackageLicenseConcluded: Apache-2.0 AND MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: docker/engine-api @@ -1376,10 +1376,10 @@ PackageName: docker/engine-api SPDXID: SPDXRef-Package125 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (BSD-3-Clause AND Apache-2.0) +PackageLicenseConcluded: BSD-3-Clause AND Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: docker/go-connections @@ -1390,7 +1390,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: docker/libcompose @@ -1401,7 +1401,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: docker/libnetwork @@ -1412,7 +1412,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: docker/libtrust @@ -1423,7 +1423,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: docker/machine @@ -1434,7 +1434,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: dustin/go-humanize @@ -1445,7 +1445,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: eapache/channels @@ -1456,7 +1456,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: eapache/go-resiliency @@ -1467,7 +1467,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: eapache/go-xerial-snappy @@ -1478,7 +1478,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: eapache/queue @@ -1489,7 +1489,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: elazarl/go-bindata-assetfs @@ -1500,7 +1500,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-2-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: elazarl/goproxy @@ -1511,7 +1511,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: emicklei/go-restful @@ -1522,7 +1522,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: emicklei/go-restful-swagger12 @@ -1533,7 +1533,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: emirpasic/gods @@ -1541,10 +1541,10 @@ PackageName: emirpasic/gods SPDXID: SPDXRef-Package140 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (BSD-2-Clause AND ISC) +PackageLicenseConcluded: BSD-2-Clause AND ISC PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: euank/go-kmsg-parser @@ -1555,7 +1555,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: Kubernetes. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: evanphx/json-patch @@ -1566,7 +1566,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: exponent-io/jsonpath @@ -1577,7 +1577,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: fatih/camelcase @@ -1588,7 +1588,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: fatih/structs @@ -1599,7 +1599,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: flynn/go-shlex @@ -1610,7 +1610,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: fsnotify/fsnotify @@ -1621,7 +1621,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: fsouza/fake-gcs-server @@ -1632,7 +1632,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-2-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: fsouza/go-dockerclient @@ -1640,10 +1640,10 @@ PackageName: fsouza/go-dockerclient SPDXID: SPDXRef-Package149 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (BSD-2-Clause AND Apache-2.0) +PackageLicenseConcluded: BSD-2-Clause AND Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: fullsailor/pkcs7 @@ -1651,10 +1651,10 @@ PackageName: fullsailor/pkcs7 SPDXID: SPDXRef-Package150 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (BSD-3-Clause AND MIT) +PackageLicenseConcluded: BSD-3-Clause AND MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: GeertJohan/go.rice @@ -1665,7 +1665,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-2-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: ghodss/yaml @@ -1673,10 +1673,10 @@ PackageName: ghodss/yaml SPDXID: SPDXRef-Package152 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (BSD-3-Clause AND MIT) +PackageLicenseConcluded: BSD-3-Clause AND MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: globalsign/mgo @@ -1684,10 +1684,10 @@ PackageName: globalsign/mgo SPDXID: SPDXRef-Package153 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (BSD-2-Clause AND BSD-3-Clause) +PackageLicenseConcluded: BSD-2-Clause AND BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: go-ini/ini @@ -1698,7 +1698,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: go-openapi/analysis @@ -1709,7 +1709,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: go-openapi/errors @@ -1720,7 +1720,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: go-openapi/jsonpointer @@ -1731,7 +1731,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: go-openapi/jsonreference @@ -1742,7 +1742,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: go-openapi/loads @@ -1753,7 +1753,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: go-openapi/runtime @@ -1764,7 +1764,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: go-openapi/spec @@ -1772,10 +1772,10 @@ PackageName: go-openapi/spec SPDXID: SPDXRef-Package161 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (CC-BY-4.0 AND Apache-2.0 AND MIT) +PackageLicenseConcluded: CC-BY-4.0 AND Apache-2.0 AND MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: go-openapi/strfmt @@ -1786,7 +1786,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: go-openapi/swag @@ -1794,10 +1794,10 @@ PackageName: go-openapi/swag SPDXID: SPDXRef-Package163 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (Apache-2.0 AND MIT) +PackageLicenseConcluded: Apache-2.0 AND MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: go-openapi/validate @@ -1808,7 +1808,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: go-ozzo/ozzo-validation @@ -1819,7 +1819,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: go-yaml/yaml @@ -1827,10 +1827,10 @@ PackageName: go-yaml/yaml SPDXID: SPDXRef-Package166 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (Apache-2.0 AND MIT) +PackageLicenseConcluded: Apache-2.0 AND MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: gobuffalo/envy @@ -1841,7 +1841,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: godbus/dbus @@ -1852,7 +1852,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-2-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: gogo/protobuf @@ -1860,10 +1860,10 @@ PackageName: gogo/protobuf SPDXID: SPDXRef-Package169 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (BSD-2-Clause AND BSD-3-Clause) +PackageLicenseConcluded: BSD-2-Clause AND BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: golang/dep @@ -1871,10 +1871,10 @@ PackageName: golang/dep SPDXID: SPDXRef-Package170 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (LicenseRef-Google-Patents-Notice-Golang AND BSD-3-Clause) +PackageLicenseConcluded: LicenseRef-Google-Patents-Notice-Golang AND BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: golang/glog @@ -1885,7 +1885,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: golang/groupcache @@ -1896,7 +1896,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: golang/lint @@ -1907,7 +1907,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: golang/mock @@ -1918,7 +1918,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: golang/protobuf @@ -1929,7 +1929,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: golang/snappy @@ -1940,7 +1940,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: google/btree @@ -1951,7 +1951,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: google/cadvisor @@ -1962,7 +1962,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: google/certificate-transparency-go @@ -1970,10 +1970,10 @@ PackageName: google/certificate-transparency-go SPDXID: SPDXRef-Package179 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (BSD-3-Clause AND Apache-2.0) +PackageLicenseConcluded: BSD-3-Clause AND Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: google/go-containerregistry @@ -1984,7 +1984,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: google/go-querystring @@ -1995,7 +1995,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: google/go-tpm @@ -2006,7 +2006,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: google/gofuzz @@ -2017,7 +2017,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: google/uuid @@ -2028,7 +2028,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: googleapis/gax-go @@ -2039,7 +2039,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: googleapis/gnostic @@ -2047,10 +2047,10 @@ PackageName: googleapis/gnostic SPDXID: SPDXRef-Package186 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (BSD-3-Clause AND Apache-2.0 AND MIT) +PackageLicenseConcluded: BSD-3-Clause AND Apache-2.0 AND MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: GoogleCloudPlatform/gke-managed-certs @@ -2061,7 +2061,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: Kubernetes. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: gophercloud/gophercloud @@ -2072,7 +2072,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: gorilla/context @@ -2083,7 +2083,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: gorilla/mux @@ -2094,7 +2094,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: gorilla/securecookie @@ -2105,7 +2105,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: gorilla/sessions @@ -2116,7 +2116,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: gorilla/websocket @@ -2124,10 +2124,10 @@ PackageName: gorilla/websocket SPDXID: SPDXRef-Package193 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (BSD-2-Clause AND MIT) +PackageLicenseConcluded: BSD-2-Clause AND MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: gregjones/httpcache @@ -2138,7 +2138,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: grpc-ecosystem/go-grpc-middleware @@ -2149,7 +2149,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: grpc-ecosystem/go-grpc-prometheus @@ -2160,7 +2160,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: grpc-ecosystem/grpc-gateway @@ -2168,10 +2168,10 @@ PackageName: grpc-ecosystem/grpc-gateway SPDXID: SPDXRef-Package197 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (BSD-3-Clause AND Apache-2.0) +PackageLicenseConcluded: BSD-3-Clause AND Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: hawkular/hawkular-client-go @@ -2182,7 +2182,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: Kubernetes. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: heketi/heketi REST API @@ -2190,10 +2190,10 @@ PackageName: heketi/heketi REST API SPDXID: SPDXRef-Package199 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (Apache-2.0 OR LGPL-3.0-or-later) +PackageLicenseConcluded: Apache-2.0 OR LGPL-3.0-or-later PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Scope: Approval is limited to the REST API client libraries and does not extend to the Heketi server or other components.. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: hpcloud/tail @@ -2204,7 +2204,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: huandu/xstrings @@ -2215,7 +2215,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: imdario/mergo @@ -2226,7 +2226,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: inconshreveable/mousetrap @@ -2237,7 +2237,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: influxdata/influxdb @@ -2248,7 +2248,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: jimmidyson/go-download @@ -2259,7 +2259,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: jinzhu/gorm @@ -2270,7 +2270,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: jinzhu/inflection @@ -2281,7 +2281,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: jmespath/go-jmespath @@ -2292,7 +2292,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: jmhodges/clock @@ -2303,7 +2303,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: jmoiron/sqlx @@ -2314,7 +2314,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: joho/godotenv @@ -2325,7 +2325,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: jonboulle/clockwork @@ -2336,7 +2336,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: jpillora/backoff @@ -2347,7 +2347,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: json-iterator/go @@ -2358,7 +2358,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: kardianos/osext @@ -2369,7 +2369,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: karrick/godirwalk @@ -2380,7 +2380,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-2-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: kevinburke/ssh_config @@ -2391,7 +2391,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: kisielk/sqlstruct @@ -2402,7 +2402,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: knative/build @@ -2413,7 +2413,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: Knative. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: kr/fs @@ -2424,7 +2424,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: kr/pretty @@ -2435,7 +2435,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: kr/pty @@ -2446,7 +2446,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: kr/text @@ -2457,7 +2457,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: kubernetes-incubator/apiserver-builder @@ -2468,7 +2468,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: Kubernetes. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: kubernetes-incubator/reference-docs @@ -2479,7 +2479,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: Kubernetes. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: kubernetes-sigs/application @@ -2490,7 +2490,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: Kubernetes. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: kubernetes/repo-infra @@ -2501,7 +2501,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: Kubernetes. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: kylelemons/godebug @@ -2512,7 +2512,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: lib/pq @@ -2523,7 +2523,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: libopenstorage/openstorage @@ -2534,7 +2534,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: Kubernetes. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: libvirt/libvirt-go @@ -2545,7 +2545,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: libvirt/libvirt-go-xml @@ -2556,7 +2556,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: lpabon/godbc @@ -2567,7 +2567,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: Kubernetes. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: lxn/win @@ -2578,7 +2578,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: magiconair/properties @@ -2586,10 +2586,10 @@ PackageName: magiconair/properties SPDXID: SPDXRef-Package235 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (BSD-2-Clause AND BSD-3-Clause) +PackageLicenseConcluded: BSD-2-Clause AND BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: mailru/easyjson @@ -2600,7 +2600,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: MakeNowJust/heredoc @@ -2611,7 +2611,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: markbates/inflect @@ -2622,7 +2622,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: marpaia/graphite-golang @@ -2633,7 +2633,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: Masterminds/semver @@ -2644,7 +2644,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: Masterminds/sprig @@ -2655,7 +2655,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: Masterminds/vcs @@ -2666,7 +2666,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: mattn/go-runewidth @@ -2677,7 +2677,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: mattn/go-shellwords @@ -2688,7 +2688,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: mattn/go-zglob @@ -2696,10 +2696,10 @@ PackageName: mattn/go-zglob SPDXID: SPDXRef-Package245 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (BSD-3-Clause AND MIT) +PackageLicenseConcluded: BSD-3-Clause AND MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: matttproud/golang_protobuf_extensions @@ -2707,10 +2707,10 @@ PackageName: matttproud/golang_protobuf_extensions SPDXID: SPDXRef-Package246 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (BSD-3-Clause AND Apache-2.0) +PackageLicenseConcluded: BSD-3-Clause AND Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: mesos/mesos-go @@ -2721,7 +2721,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: Kubernetes. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: mholt/caddy @@ -2732,7 +2732,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: Microsoft/go-winio @@ -2740,10 +2740,10 @@ PackageName: Microsoft/go-winio SPDXID: SPDXRef-Package249 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (BSD-3-Clause AND MIT) +PackageLicenseConcluded: BSD-3-Clause AND MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: Microsoft/hcsshim @@ -2751,10 +2751,10 @@ PackageName: Microsoft/hcsshim SPDXID: SPDXRef-Package250 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (BSD-3-Clause AND MIT) +PackageLicenseConcluded: BSD-3-Clause AND MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: miekg/coredns @@ -2765,7 +2765,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: miekg/dns @@ -2776,7 +2776,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: mindprince/gonvml @@ -2787,7 +2787,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: Kubernetes. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: mistifyio/go-zfs @@ -2798,7 +2798,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: Kubernetes. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: mitchellh/go-homedir @@ -2809,7 +2809,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: mitchellh/go-ps @@ -2820,7 +2820,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: mitchellh/go-wordwrap @@ -2831,7 +2831,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: mitchellh/hashstructure @@ -2842,7 +2842,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: mitchellh/mapstructure @@ -2853,7 +2853,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: moby/hyperkit @@ -2864,7 +2864,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: Kubernetes. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: modern-go/concurrent @@ -2875,7 +2875,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: modern-go/reflect2 @@ -2886,7 +2886,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: mohae/deepcopy @@ -2897,7 +2897,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: moul/http2curl @@ -2908,7 +2908,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: mrunalp/fileutils @@ -2919,7 +2919,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: mvdan/xurls @@ -2930,7 +2930,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: mxk/go-flowrate @@ -2941,7 +2941,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: ncabatoff/process-exporter @@ -2949,10 +2949,10 @@ PackageName: ncabatoff/process-exporter SPDXID: SPDXRef-Package268 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (Apache-2.0 AND MIT) +PackageLicenseConcluded: Apache-2.0 AND MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: nightlyone/lockfile @@ -2963,7 +2963,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: novln/docker-parser @@ -2974,7 +2974,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: NYTimes/gziphandler @@ -2985,7 +2985,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: olekukonko/tablewriter @@ -2996,7 +2996,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: onsi/ginkgo @@ -3007,7 +3007,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: onsi/gomega @@ -3018,7 +3018,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: opencontainers/image-spec @@ -3029,7 +3029,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: opencontainers/runtime-spec @@ -3040,7 +3040,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: opencontainers/selinux @@ -3051,7 +3051,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: openshift/origin @@ -3062,7 +3062,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: Kubernetes. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: opentracing/opentracing-go @@ -3073,7 +3073,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: parnurzeal/gorequest @@ -3084,7 +3084,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: patrickmn/go-cache @@ -3095,7 +3095,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: paultag/sniff @@ -3106,7 +3106,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: Kubernetes. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: pborman/uuid @@ -3117,7 +3117,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: pelletier/go-buffruneio @@ -3128,7 +3128,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: pelletier/go-toml @@ -3139,7 +3139,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: petar/GoLLRB @@ -3150,7 +3150,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: peterbourgon/diskv @@ -3161,7 +3161,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: pierrec/lz4 @@ -3172,7 +3172,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: pierrec/xxHash @@ -3183,7 +3183,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: pkg/browser @@ -3194,7 +3194,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-2-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: pkg/errors @@ -3205,7 +3205,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-2-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: pkg/profile @@ -3216,7 +3216,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-2-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: pkg/sftp @@ -3227,7 +3227,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-2-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: pmezard/go-difflib @@ -3238,7 +3238,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: pquerna/cachecontrol @@ -3246,10 +3246,10 @@ PackageName: pquerna/cachecontrol SPDXID: SPDXRef-Package295 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (BSD-3-Clause AND Apache-2.0) +PackageLicenseConcluded: BSD-3-Clause AND Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: pquerna/ffjson @@ -3257,10 +3257,10 @@ PackageName: pquerna/ffjson SPDXID: SPDXRef-Package296 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (BSD-3-Clause AND Apache-2.0 AND ISC) +PackageLicenseConcluded: BSD-3-Clause AND Apache-2.0 AND ISC PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: prometheus/client_golang @@ -3268,10 +3268,10 @@ PackageName: prometheus/client_golang SPDXID: SPDXRef-Package297 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (BSD-3-Clause AND Apache-2.0 AND MIT) +PackageLicenseConcluded: BSD-3-Clause AND Apache-2.0 AND MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: prometheus/client_model @@ -3282,7 +3282,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: prometheus/common @@ -3290,10 +3290,10 @@ PackageName: prometheus/common SPDXID: SPDXRef-Package299 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (BSD-3-Clause AND Apache-2.0) +PackageLicenseConcluded: BSD-3-Clause AND Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: prometheus/procfs @@ -3304,7 +3304,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: PuerkitoBio/purell @@ -3315,7 +3315,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: PuerkitoBio/urlesc @@ -3326,7 +3326,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: r2d4/external-storage @@ -3337,7 +3337,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: Kubernetes. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: rackspace/gophercloud @@ -3348,7 +3348,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: Kubernetes. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: rancher/go-rancher @@ -3359,7 +3359,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: rcrowley/go-metrics @@ -3370,7 +3370,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-2-Clause-FreeBSD PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: renstrom/dedent @@ -3381,7 +3381,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: Rican7/retry @@ -3392,7 +3392,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: riemann/riemann-go-client @@ -3403,7 +3403,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: robfig/cron @@ -3414,7 +3414,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: russross/blackfriday @@ -3425,7 +3425,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-2-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: samalba/dockerclient @@ -3436,7 +3436,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: satori/go.uuid @@ -3447,7 +3447,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: scalingdata/gcfg @@ -3455,10 +3455,10 @@ PackageName: scalingdata/gcfg SPDXID: SPDXRef-Package314 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (BSD-2-Clause AND BSD-3-Clause) +PackageLicenseConcluded: BSD-2-Clause AND BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: sdboyer/constext @@ -3469,7 +3469,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: seccomp/libseccomp-golang @@ -3480,7 +3480,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-2-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: sergi/go-diff @@ -3491,7 +3491,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: Shopify/sarama @@ -3502,7 +3502,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: shurcooL/githubv4 @@ -3513,7 +3513,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: shurcooL/go @@ -3524,7 +3524,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: shurcooL/graphql @@ -3535,7 +3535,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: shurcooL/sanitized_anchor_name @@ -3546,7 +3546,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: sirupsen/logrus @@ -3554,10 +3554,10 @@ PackageName: sirupsen/logrus SPDXID: SPDXRef-Package323 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (BSD-2-Clause AND BSD-3-Clause AND MIT) +PackageLicenseConcluded: BSD-2-Clause AND BSD-3-Clause AND MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: skynetservices/skydns @@ -3565,10 +3565,10 @@ PackageName: skynetservices/skydns SPDXID: SPDXRef-Package324 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (Apache-2.0 AND MIT) +PackageLicenseConcluded: Apache-2.0 AND MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: smartystreets/go-aws-auth @@ -3579,7 +3579,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: soheilhy/cmux @@ -3590,7 +3590,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: spf13/afero @@ -3601,7 +3601,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: spf13/cast @@ -3612,7 +3612,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: spf13/cobra @@ -3620,10 +3620,10 @@ PackageName: spf13/cobra SPDXID: SPDXRef-Package329 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (Apache-2.0 AND MIT) +PackageLicenseConcluded: Apache-2.0 AND MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: spf13/jwalterweatherman @@ -3634,7 +3634,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: spf13/pflag @@ -3645,7 +3645,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: spf13/viper @@ -3656,7 +3656,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: storageos/go-api @@ -3664,10 +3664,10 @@ PackageName: storageos/go-api SPDXID: SPDXRef-Package333 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (BSD-2-Clause AND MIT) +PackageLicenseConcluded: BSD-2-Clause AND MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: streadway/quantile @@ -3678,7 +3678,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-2-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: stretchr/objx @@ -3689,7 +3689,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: stretchr/testify @@ -3700,7 +3700,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: syndtr/gocapability @@ -3711,7 +3711,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-2-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: tchap/go-patricia @@ -3722,7 +3722,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: thockin/glogr @@ -3733,7 +3733,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: thockin/logr @@ -3744,7 +3744,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: tmc/grpc-websocket-proxy @@ -3755,7 +3755,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: tsenart/vegeta @@ -3766,7 +3766,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: ugorji/go @@ -3777,7 +3777,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: Unknwon/goconfig @@ -3788,7 +3788,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: urfave/cli @@ -3799,7 +3799,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: vishvananda/netlink @@ -3810,7 +3810,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: vishvananda/netns @@ -3821,7 +3821,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: vmware/govmomi @@ -3829,10 +3829,10 @@ PackageName: vmware/govmomi SPDXID: SPDXRef-Package348 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (BSD-3-Clause AND Apache-2.0) +PackageLicenseConcluded: BSD-3-Clause AND Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: vmware/photon-controller-go-sdk @@ -3840,10 +3840,10 @@ PackageName: vmware/photon-controller-go-sdk SPDXID: SPDXRef-Package349 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (BSD-3-Clause AND Apache-2.0) +PackageLicenseConcluded: BSD-3-Clause AND Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: weaveworks/mesh @@ -3854,7 +3854,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: xanzy/go-cloudstack @@ -3865,7 +3865,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: Kubernetes. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: xeipuuv/gojsonpointer @@ -3876,7 +3876,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: xeipuuv/gojsonreference @@ -3887,7 +3887,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: xeipuuv/gojsonschema @@ -3895,10 +3895,10 @@ PackageName: xeipuuv/gojsonschema SPDXID: SPDXRef-Package354 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (Apache-2.0 AND MIT) +PackageLicenseConcluded: Apache-2.0 AND MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: xiang90/probing @@ -3909,7 +3909,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: zakjan/cert-chain-resolver @@ -3920,7 +3920,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: ziutek/syslog @@ -3931,7 +3931,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: go.opencensus.io @@ -3942,7 +3942,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: go.uber.org/atomic @@ -3953,7 +3953,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: go.uber.org/multierr @@ -3964,7 +3964,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: go.uber.org/zap @@ -3975,7 +3975,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: go4.org/errorutil @@ -3986,7 +3986,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: x/build @@ -3994,10 +3994,10 @@ PackageName: x/build SPDXID: SPDXRef-Package363 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (LicenseRef-Google-Patents-Notice-Golang AND BSD-3-Clause) +PackageLicenseConcluded: LicenseRef-Google-Patents-Notice-Golang AND BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: x/exp @@ -4005,10 +4005,10 @@ PackageName: x/exp SPDXID: SPDXRef-Package364 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (LicenseRef-Google-Patents-Notice-Golang AND BSD-3-Clause) +PackageLicenseConcluded: LicenseRef-Google-Patents-Notice-Golang AND BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: x/lint @@ -4019,7 +4019,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: x/oauth2 @@ -4030,7 +4030,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: x/sync @@ -4038,10 +4038,10 @@ PackageName: x/sync SPDXID: SPDXRef-Package367 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (LicenseRef-Google-Patents-Notice-Golang AND BSD-3-Clause) +PackageLicenseConcluded: LicenseRef-Google-Patents-Notice-Golang AND BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: x/sys @@ -4049,10 +4049,10 @@ PackageName: x/sys SPDXID: SPDXRef-Package368 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (LicenseRef-Google-Patents-Notice-Golang AND BSD-2-Clause AND BSD-3-Clause) +PackageLicenseConcluded: LicenseRef-Google-Patents-Notice-Golang AND BSD-2-Clause AND BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: x/text @@ -4060,10 +4060,10 @@ PackageName: x/text SPDXID: SPDXRef-Package369 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (LicenseRef-Google-Patents-Notice-Golang AND BSD-3-Clause) +PackageLicenseConcluded: LicenseRef-Google-Patents-Notice-Golang AND BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: x/time @@ -4071,10 +4071,10 @@ PackageName: x/time SPDXID: SPDXRef-Package370 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (LicenseRef-Google-Patents-Notice-Golang AND BSD-3-Clause) +PackageLicenseConcluded: LicenseRef-Google-Patents-Notice-Golang AND BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: x/tools @@ -4082,10 +4082,10 @@ PackageName: x/tools SPDXID: SPDXRef-Package371 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (LicenseRef-Google-Patents-Notice-Golang AND BSD-3-Clause AND Apache-2.0 AND MIT) +PackageLicenseConcluded: LicenseRef-Google-Patents-Notice-Golang AND BSD-3-Clause AND Apache-2.0 AND MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: golang/archive/tar @@ -4096,7 +4096,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: gonum.org/v1/gonum @@ -4104,10 +4104,10 @@ PackageName: gonum.org/v1/gonum SPDXID: SPDXRef-Package373 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: ((BSD-3-Clause OR CC0-1.0) AND BSD-3-Clause) +PackageLicenseConcluded: BSD-3-Clause OR CC0-1.0 AND BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: google.golang.org/cloud @@ -4118,7 +4118,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: google.golang.org/genproto @@ -4129,7 +4129,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: gopkg.in/check.v1 @@ -4137,10 +4137,10 @@ PackageName: gopkg.in/check.v1 SPDXID: SPDXRef-Package376 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (BSD-2-Clause AND BSD-3-Clause) +PackageLicenseConcluded: BSD-2-Clause AND BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: gopkg.in/cheggaaa/pb.v1 @@ -4151,7 +4151,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: gopkg.in/fsnotify @@ -4162,7 +4162,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: gopkg.in/gcfg.v1 @@ -4173,7 +4173,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: gopkg.in/go-playground/pool.v3 @@ -4184,7 +4184,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: gopkg.in/igm/sockjs-go.v2 @@ -4195,7 +4195,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: gopkg.in/inf.v0 @@ -4206,7 +4206,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: gopkg.in/natefinch/lumberjack.v2 @@ -4217,7 +4217,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: gopkg.in/olivere/elastic.v3 @@ -4225,10 +4225,10 @@ PackageName: gopkg.in/olivere/elastic.v3 SPDXID: SPDXRef-Package384 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (BSD-3-Clause AND MIT) +PackageLicenseConcluded: BSD-3-Clause AND MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: gopkg.in/olivere/elastic.v5 @@ -4236,10 +4236,10 @@ PackageName: gopkg.in/olivere/elastic.v5 SPDXID: SPDXRef-Package385 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (BSD-3-Clause AND MIT) +PackageLicenseConcluded: BSD-3-Clause AND MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: gopkg.in/robfig/cron.v2 @@ -4250,7 +4250,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: gopkg.in/square/go-jose.v2 @@ -4258,10 +4258,10 @@ PackageName: gopkg.in/square/go-jose.v2 SPDXID: SPDXRef-Package387 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (BSD-3-Clause AND Apache-2.0) +PackageLicenseConcluded: BSD-3-Clause AND Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: gopkg.in/src-d @@ -4272,7 +4272,7 @@ FilesAnalyzed: false PackageLicenseConcluded: Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: apache-2.0. Apache-2.0, no approval needed +PackageComment: Project: All CNCF Projects. Status: apache-2.0. Apache-2.0, no approval needed ##### Package: gopkg.in/tomb.v1 @@ -4283,7 +4283,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: jquery.scrollto @@ -4294,7 +4294,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: marked @@ -4302,10 +4302,10 @@ PackageName: marked SPDXID: SPDXRef-Package391 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (BSD-3-Clause AND MIT) +PackageLicenseConcluded: BSD-3-Clause AND MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: mime @@ -4316,7 +4316,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: minimist @@ -4327,7 +4327,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: node-static @@ -4338,7 +4338,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: optimist @@ -4349,7 +4349,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: ui-router for Angular @@ -4360,7 +4360,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: vbom.ml/util @@ -4371,7 +4371,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: wordwrap @@ -4382,7 +4382,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Scope: build-time dependency. Status: allowlisted. allowlisted +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. allowlisted ##### Package: VirtualBox Linux Guest Drivers Makefile @@ -4393,7 +4393,7 @@ FilesAnalyzed: false PackageLicenseConcluded: GPL-2.0-only PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-05-20 +PackageComment: Project: Kubernetes. Scope: Approved ONLY as an OPTIONl subdependency of Minikube (not approved for use on a standalone basis or as a required dependency). Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-05-20 ##### Package: Angular @@ -4404,7 +4404,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11 +PackageComment: Project: All CNCF Projects. Scope: No scope restrictions. Status: approved. contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11 ##### Package: Asciidoctor @@ -4415,7 +4415,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11 +PackageComment: Project: All CNCF Projects. Scope: No scope restrictions. Status: approved. contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11 ##### Package: Azure acr-docker-credential-helper @@ -4426,7 +4426,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11 +PackageComment: Project: Kubernetes. Scope: No scope restrictions. Status: approved. modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11 ##### Package: Backbone @@ -4437,7 +4437,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11 +PackageComment: Project: All CNCF Projects. Scope: No scope restrictions. Status: approved. contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11 ##### Package: bitbucket.org/bertimus9/systemstat @@ -4448,7 +4448,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11 +PackageComment: Project: Kubernetes. Scope: No scope restrictions. Status: approved. not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11 ##### Package: bitbucket.org/ww/goautoneg @@ -4459,7 +4459,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11 +PackageComment: Project: All CNCF Projects. Scope: No scope restrictions. Status: approved. not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11 ##### Package: bootstrap @@ -4467,10 +4467,10 @@ PackageName: bootstrap SPDXID: SPDXRef-Package406 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (CC-BY-3.0 AND MIT) +PackageLicenseConcluded: CC-BY-3.0 AND MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11 +PackageComment: Project: All CNCF Projects. Scope: No scope restrictions. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11 ##### Package: dialog-polyfill.css @@ -4481,7 +4481,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11 +PackageComment: Project: All CNCF Projects. Scope: No scope restrictions. Status: approved. contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11 ##### Package: font-awesome @@ -4489,10 +4489,10 @@ PackageName: font-awesome SPDXID: SPDXRef-Package408 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (CC-BY-3.0 AND MIT AND OFL-1.1) +PackageLicenseConcluded: CC-BY-3.0 AND MIT AND OFL-1.1 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11 +PackageComment: Project: All CNCF Projects. Scope: No scope restrictions. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11 ##### Package: Gingko @@ -4503,7 +4503,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11 +PackageComment: Project: All CNCF Projects. Scope: No scope restrictions. Status: approved. contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11 ##### Package: Azure/azure-pipeline-go @@ -4514,7 +4514,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11 +PackageComment: Project: Kubernetes. Scope: No scope restrictions. Status: approved. not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11 ##### Package: bungle/lua-resty-template @@ -4525,7 +4525,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11 +PackageComment: Project: Ingress-Nginx. Scope: No scope restrictions. Status: approved. modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11 ##### Package: c4milo/gotoolkit @@ -4536,7 +4536,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MPL-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11 +PackageComment: Project: All CNCF Projects. Scope: Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11 ##### Package: client9/misspell @@ -4544,10 +4544,10 @@ PackageName: client9/misspell SPDXID: SPDXRef-Package413 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (Unlicense AND BSD-3-Clause AND MIT) +PackageLicenseConcluded: Unlicense AND BSD-3-Clause AND MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11 +PackageComment: Project: All CNCF Projects. Scope: No scope restrictions. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11 ##### Package: d2g/dhcp4 @@ -4558,7 +4558,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11 +PackageComment: Project: Kubernetes. Scope: No scope restrictions. Status: approved. not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11 ##### Package: d2g/dhcp4client @@ -4569,7 +4569,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MPL-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11 +PackageComment: Project: Kubernetes. Scope: Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11 ##### Package: dgryski/go-onlinestats @@ -4577,10 +4577,10 @@ PackageName: dgryski/go-onlinestats SPDXID: SPDXRef-Package416 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (MIT AND LicenseRef-Public-domain-statement) +PackageLicenseConcluded: MIT AND LicenseRef-Public-domain-statement PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11 +PackageComment: Project: OpenTelemetry. Scope: No scope restrictions. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11 ##### Package: docker/go-units @@ -4588,10 +4588,10 @@ PackageName: docker/go-units SPDXID: SPDXRef-Package417 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (CC-BY-SA-4.0 AND CC-BY-4.0 AND Apache-2.0) +PackageLicenseConcluded: CC-BY-SA-4.0 AND CC-BY-4.0 AND Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11 +PackageComment: Project: All CNCF Projects. Scope: No scope restrictions. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11 ##### Package: docker/spdystream @@ -4599,10 +4599,10 @@ PackageName: docker/spdystream SPDXID: SPDXRef-Package418 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (CC-BY-SA-4.0 AND CC-BY-4.0 AND BSD-3-Clause AND Apache-2.0) +PackageLicenseConcluded: CC-BY-SA-4.0 AND CC-BY-4.0 AND BSD-3-Clause AND Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11 +PackageComment: Project: Kubernetes. Scope: No scope restrictions. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11 ##### Package: go-sql-driver/mysql @@ -4613,7 +4613,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MPL-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11 +PackageComment: Project: All CNCF Projects. Scope: Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11 ##### Package: gonum/graph @@ -4624,7 +4624,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11 +PackageComment: Project: All CNCF Projects. Scope: No scope restrictions. Status: approved. modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11 ##### Package: google/go-github @@ -4632,10 +4632,10 @@ PackageName: google/go-github SPDXID: SPDXRef-Package421 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (BSD-3-Clause AND CC-BY-3.0) +PackageLicenseConcluded: BSD-3-Clause AND CC-BY-3.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11 +PackageComment: Project: All CNCF Projects. Scope: No scope restrictions. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11 ##### Package: grpc-ecosystem/grpc-opentracing @@ -4643,10 +4643,10 @@ PackageName: grpc-ecosystem/grpc-opentracing SPDXID: SPDXRef-Package422 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (BSD-3-Clause AND LicenseRef-Google-Patents-Notice-GRPC) +PackageLicenseConcluded: BSD-3-Clause AND LicenseRef-Google-Patents-Notice-GRPC PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11 +PackageComment: Project: All CNCF Projects. Scope: No scope restrictions. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11 ##### Package: hashicorp/errwrap @@ -4657,7 +4657,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MPL-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11 +PackageComment: Project: All CNCF Projects. Scope: Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11 ##### Package: hashicorp/go-cleanhttp @@ -4668,7 +4668,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MPL-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11 +PackageComment: Project: All CNCF Projects. Scope: Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11 ##### Package: hashicorp/go-multierror @@ -4679,7 +4679,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MPL-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11 +PackageComment: Project: All CNCF Projects. Scope: Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11 ##### Package: hashicorp/golang-lru @@ -4690,7 +4690,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MPL-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11 +PackageComment: Project: All CNCF Projects. Scope: Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11 ##### Package: hashicorp/hcl @@ -4701,7 +4701,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MPL-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11 +PackageComment: Project: All CNCF Projects. Scope: Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11 ##### Package: hooklift/iso9660 @@ -4712,7 +4712,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MPL-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11 +PackageComment: Project: Kubernetes. Scope: Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11 ##### Package: howeyc/gopass @@ -4720,10 +4720,10 @@ PackageName: howeyc/gopass SPDXID: SPDXRef-Package429 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (ISC AND CDDL-1.0) +PackageLicenseConcluded: ISC AND CDDL-1.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11 +PackageComment: Project: Kubernetes. Scope: Allowed only if the dependency files are either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11 ##### Package: jbenet/go-context @@ -4734,7 +4734,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11 +PackageComment: Project: All CNCF Projects. Scope: No scope restrictions. Status: approved. not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11 ##### Package: JeffAshton/win_pdh @@ -4745,7 +4745,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11 +PackageComment: Project: Kubernetes. Scope: No scope restrictions. Status: approved. not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11 ##### Package: jmank88/nuts @@ -4756,7 +4756,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11 +PackageComment: Project: All CNCF Projects. Scope: No scope restrictions. Status: approved. not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11 ##### Package: johanneswuerbach/nfsexports @@ -4767,7 +4767,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11 +PackageComment: Project: Kubernetes. Scope: No scope restrictions. Status: approved. not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11 ##### Package: joshdk/go-junit @@ -4778,7 +4778,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11 +PackageComment: Project: All CNCF Projects. Scope: No scope restrictions. Status: approved. not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11 ##### Package: jteeuwen/go-bindata @@ -4789,7 +4789,7 @@ FilesAnalyzed: false PackageLicenseConcluded: CC0-1.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11 +PackageComment: Project: All CNCF Projects. Scope: No scope restrictions. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11 ##### Package: konsorten/go-windows-terminal-sequences @@ -4800,7 +4800,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11 +PackageComment: Project: All CNCF Projects. Scope: No scope restrictions. Status: approved. not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11 ##### Package: marstr/guid @@ -4811,7 +4811,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11 +PackageComment: Project: All CNCF Projects. Scope: No scope restrictions. Status: approved. not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11 ##### Package: mattn/go-sqlite3 @@ -4819,10 +4819,10 @@ PackageName: mattn/go-sqlite3 SPDXID: SPDXRef-Package438 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (MIT AND LicenseRef-Public-domain-statement) +PackageLicenseConcluded: MIT AND LicenseRef-Public-domain-statement PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11 +PackageComment: Project: All CNCF Projects. Scope: No scope restrictions. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11 ##### Package: multiarch/qemu-user-static @@ -4833,7 +4833,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11 +PackageComment: Project: All CNCF Projects. Scope: No scope restrictions. Status: approved. modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11 ##### Package: Nvveen/Gotty @@ -4844,7 +4844,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-2-Clause-FreeBSD PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11 +PackageComment: Project: All CNCF Projects. Scope: No scope restrictions. Status: approved. not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11 ##### Package: opencontainers/go-digest @@ -4852,10 +4852,10 @@ PackageName: opencontainers/go-digest SPDXID: SPDXRef-Package441 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (CC-BY-SA-4.0 AND CC-BY-4.0 AND Apache-2.0) +PackageLicenseConcluded: CC-BY-SA-4.0 AND CC-BY-4.0 AND Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11 +PackageComment: Project: All CNCF Projects. Scope: No scope restrictions. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11 ##### Package: opencontainers/runc @@ -4863,10 +4863,10 @@ PackageName: opencontainers/runc SPDXID: SPDXRef-Package442 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (LicenseRef-CC-unspecified AND Apache-2.0) +PackageLicenseConcluded: CC-BY-4.0 AND Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11 +PackageComment: Project: All CNCF Projects. Scope: No scope restrictions. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11 ##### Package: quobyte/api @@ -4877,7 +4877,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11 +PackageComment: Project: Kubernetes. Scope: No scope restrictions. Status: approved. not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11 ##### Package: rubiojr/go-vhd @@ -4888,7 +4888,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11 +PackageComment: Project: Kubernetes. Scope: No scope restrictions. Status: approved. not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11 ##### Package: sigma/go-inotify @@ -4896,10 +4896,10 @@ PackageName: sigma/go-inotify SPDXID: SPDXRef-Package445 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (LicenseRef-Google-Patents-Notice-Golang AND BSD-3-Clause) +PackageLicenseConcluded: LicenseRef-Google-Patents-Notice-Golang AND BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11 +PackageComment: Project: Kubernetes. Scope: No scope restrictions. Status: approved. not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11 ##### Package: spotinst/spotinst-sdk-go @@ -4907,10 +4907,10 @@ PackageName: spotinst/spotinst-sdk-go SPDXID: SPDXRef-Package446 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (BSD-3-Clause AND Apache-2.0 AND MIT) +PackageLicenseConcluded: BSD-3-Clause AND Apache-2.0 AND MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11 +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11 ##### Package: src-d/gcfg @@ -4921,7 +4921,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11 +PackageComment: Project: All CNCF Projects. Scope: No scope restrictions. Status: approved. not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11 ##### Package: tent/http-link-go @@ -4932,7 +4932,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11 +PackageComment: Project: All CNCF Projects. Scope: No scope restrictions. Status: approved. not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11 ##### Package: xanzy/ssh-agent @@ -4940,10 +4940,10 @@ PackageName: xanzy/ssh-agent SPDXID: SPDXRef-Package449 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (Apache-2.0 AND MIT) +PackageLicenseConcluded: Apache-2.0 AND MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11 +PackageComment: Project: OpenTelemetry. Scope: No scope restrictions. Status: approved. not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11 ##### Package: zchee/go-vmnet @@ -4951,10 +4951,10 @@ PackageName: zchee/go-vmnet SPDXID: SPDXRef-Package450 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (BSD-2-Clause AND BSD-3-Clause) +PackageLicenseConcluded: BSD-2-Clause AND BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11 +PackageComment: Project: Kubernetes & Minikube. Scope: No scope restrictions. Status: approved. not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11 ##### Package: go-srcimporter @@ -4965,7 +4965,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11 +PackageComment: Project: All CNCF Projects. Scope: No scope restrictions. Status: approved. modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11 ##### Package: go9p @@ -4976,7 +4976,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11 +PackageComment: Project: All CNCF Projects. Scope: No scope restrictions. Status: approved. modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11 ##### Package: godep @@ -4987,7 +4987,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11 +PackageComment: Project: All CNCF Projects. Scope: No scope restrictions. Status: approved. modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11 ##### Package: x/crypto @@ -4995,10 +4995,10 @@ PackageName: x/crypto SPDXID: SPDXRef-Package454 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (LicenseRef-Google-Patents-Notice-Golang AND BSD-3-Clause AND MIT AND LicenseRef-Public-domain-statement) +PackageLicenseConcluded: LicenseRef-Google-Patents-Notice-Golang AND BSD-3-Clause AND MIT AND LicenseRef-Public-domain-statement PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11 +PackageComment: Project: All CNCF Projects. Scope: No scope restrictions. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11 ##### Package: x/net @@ -5006,10 +5006,10 @@ PackageName: x/net SPDXID: SPDXRef-Package455 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (LicenseRef-Google-Patents-Notice-Golang AND BSD-2-Clause AND BSD-3-Clause AND CC-BY-3.0 AND (BSD-3-Clause OR LicenseRef-W3C-Test-Suite-License-1)) +PackageLicenseConcluded: LicenseRef-Google-Patents-Notice-Golang AND BSD-2-Clause AND BSD-3-Clause AND CC-BY-3.0 AND BSD-3-Clause OR LicenseRef-W3C-Test-Suite-License-1 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11 +PackageComment: Project: All CNCF Projects. Scope: No scope restrictions. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11 ##### Package: golang/expansion @@ -5017,10 +5017,10 @@ PackageName: golang/expansion SPDXID: SPDXRef-Package456 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (LicenseRef-Google-Patents-Notice-Golang AND BSD-3-Clause) +PackageLicenseConcluded: LicenseRef-Google-Patents-Notice-Golang AND BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11 +PackageComment: Project: All CNCF Projects. Scope: No scope restrictions. Status: approved. modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11 ##### Package: golang/go/types @@ -5028,10 +5028,10 @@ PackageName: golang/go/types SPDXID: SPDXRef-Package457 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (LicenseRef-Google-Patents-Notice-Golang AND BSD-3-Clause) +PackageLicenseConcluded: LicenseRef-Google-Patents-Notice-Golang AND BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11 +PackageComment: Project: All CNCF Projects. Scope: No scope restrictions. Status: approved. modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11 ##### Package: golang/internal/srcimporter @@ -5042,7 +5042,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11 +PackageComment: Project: All CNCF Projects. Scope: No scope restrictions. Status: approved. modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11 ##### Package: golang/json @@ -5053,7 +5053,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11 +PackageComment: Project: All CNCF Projects. Scope: No scope restrictions. Status: approved. modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11 ##### Package: golang/netutil @@ -5064,7 +5064,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11 +PackageComment: Project: All CNCF Projects. Scope: No scope restrictions. Status: approved. modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11 ##### Package: golang/reflect @@ -5072,10 +5072,10 @@ PackageName: golang/reflect SPDXID: SPDXRef-Package461 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (LicenseRef-Google-Patents-Notice-Golang AND BSD-3-Clause) +PackageLicenseConcluded: LicenseRef-Google-Patents-Notice-Golang AND BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11 +PackageComment: Project: All CNCF Projects. Scope: No scope restrictions. Status: approved. modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11 ##### Package: golang/template @@ -5083,10 +5083,10 @@ PackageName: golang/template SPDXID: SPDXRef-Package462 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (LicenseRef-Google-Patents-Notice-Golang AND BSD-3-Clause) +PackageLicenseConcluded: LicenseRef-Google-Patents-Notice-Golang AND BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11 +PackageComment: Project: All CNCF Projects. Scope: No scope restrictions. Status: approved. modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11 ##### Package: Google Protocol Buffers @@ -5097,7 +5097,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11 +PackageComment: Project: All CNCF Projects. Scope: No scope restrictions. Status: approved. contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11 ##### Package: google.golang.org/api @@ -5105,10 +5105,10 @@ PackageName: google.golang.org/api SPDXID: SPDXRef-Package464 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (BSD-3-Clause AND Apache-2.0 AND MIT) +PackageLicenseConcluded: BSD-3-Clause AND Apache-2.0 AND MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. not auto-allowlist because: No measure of stars / forks; approved by GB exception 2019-03-11 +PackageComment: Project: All CNCF Projects. Scope: See Allowlist Policy requirements. Status: allowlisted. not auto-allowlist because: No measure of stars / forks; approved by GB exception 2019-03-11 ##### Package: google.golang.org/appengine @@ -5116,10 +5116,10 @@ PackageName: google.golang.org/appengine SPDXID: SPDXRef-Package465 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (BSD-3-Clause AND Apache-2.0) +PackageLicenseConcluded: BSD-3-Clause AND Apache-2.0 PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. not auto-allowlist because: No measure of stars / forks; approved by GB exception 2019-03-11 +PackageComment: Project: Kubernetes. Scope: No scope restrictions. Status: approved. not auto-allowlist because: No measure of stars / forks; approved by GB exception 2019-03-11 ##### Package: google.golang.org/grpc @@ -5127,10 +5127,10 @@ PackageName: google.golang.org/grpc SPDXID: SPDXRef-Package466 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (BSD-3-Clause AND Apache-2.0 AND LicenseRef-Google-Patents-Notice-GRPC) +PackageLicenseConcluded: BSD-3-Clause AND Apache-2.0 AND LicenseRef-Google-Patents-Notice-GRPC PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11 +PackageComment: Project: All CNCF Projects. Scope: No scope restrictions. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11 ##### Package: gopkg.in/warnings.v0 @@ -5141,7 +5141,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-2-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11 +PackageComment: Project: All CNCF Projects. Scope: No scope restrictions. Status: approved. not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11 ##### Package: Handlebars @@ -5152,7 +5152,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11 +PackageComment: Project: All CNCF Projects. Scope: No scope restrictions. Status: approved. contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11 ##### Package: Highlight @@ -5163,7 +5163,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11 +PackageComment: Project: All CNCF Projects. Scope: No scope restrictions. Status: approved. contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11 ##### Package: highlight.js @@ -5171,10 +5171,10 @@ PackageName: highlight.js SPDXID: SPDXRef-Package470 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (BSD-3-Clause AND MIT AND CC0-1.0 AND LicenseRef-Public-domain-statement) +PackageLicenseConcluded: BSD-3-Clause AND MIT AND CC0-1.0 AND LicenseRef-Public-domain-statement PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11 +PackageComment: Project: All CNCF Projects. Scope: No scope restrictions. Status: approved. not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11 ##### Package: htpasswd @@ -5185,7 +5185,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. not auto-allowlist because: No measure of stars / forks; approved by GB exception 2019-03-11 +PackageComment: Project: All CNCF Projects. Scope: No scope restrictions. Status: approved. not auto-allowlist because: No measure of stars / forks; approved by GB exception 2019-03-11 ##### Package: jQuery @@ -5196,7 +5196,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11 +PackageComment: Project: All CNCF Projects. Scope: No scope restrictions. Status: approved. contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11 ##### Package: jQuery BBQ @@ -5204,10 +5204,10 @@ PackageName: jQuery BBQ SPDXID: SPDXRef-Package473 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (MIT OR GPL-2.0+) +PackageLicenseConcluded: MIT OR GPL-2.0+ PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11 +PackageComment: Project: All CNCF Projects. Scope: Any CNCF project using this dependency must elect to do so under the MIT License (rather than GPL-2.0) and declare such election in its documentation. Status: approved. contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11 ##### Package: jQuery hashchange event @@ -5215,10 +5215,10 @@ PackageName: jQuery hashchange event SPDXID: SPDXRef-Package474 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (GPL-2.0+ OR MIT) +PackageLicenseConcluded: GPL-2.0+ OR MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11 +PackageComment: Project: All CNCF Projects. Scope: Any CNCF project using this dependency must elect to do so under the MIT License (rather than GPL-2.0) and declare such election in its documentation. Status: approved. contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11 ##### Package: jQuery Slideto @@ -5229,7 +5229,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11 +PackageComment: Project: All CNCF Projects. Scope: No scope restrictions. Status: approved. contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11 ##### Package: jQuery Wiggle @@ -5240,7 +5240,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11 +PackageComment: Project: All CNCF Projects. Scope: No scope restrictions. Status: approved. contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11 ##### Package: moment.js @@ -5251,7 +5251,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11 +PackageComment: Project: All CNCF Projects. Scope: No scope restrictions. Status: approved. contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11 ##### Package: normalize.css @@ -5262,7 +5262,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11 +PackageComment: Project: All CNCF Projects. Scope: No scope restrictions. Status: approved. contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11 ##### Package: Octicons @@ -5273,7 +5273,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11 +PackageComment: Project: All CNCF Projects. Scope: No scope restrictions. Status: approved. contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11 ##### Package: parseUri @@ -5284,7 +5284,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11 +PackageComment: Project: All CNCF Projects. Scope: No scope restrictions. Status: approved. contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11 ##### Package: Pause @@ -5295,7 +5295,7 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. not auto-allowlist because: No measure of stars / forks; approved by GB exception 2019-03-11 +PackageComment: Project: Kubernetes. Scope: No scope restrictions. Status: approved. not auto-allowlist because: No measure of stars / forks; approved by GB exception 2019-03-11 ##### Package: Pure CSS @@ -5306,7 +5306,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11 +PackageComment: Project: All CNCF Projects. Scope: No scope restrictions. Status: approved. contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11 ##### Package: shred @@ -5317,7 +5317,7 @@ FilesAnalyzed: false PackageLicenseConcluded: ISC PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11 +PackageComment: Project: All CNCF Projects. Scope: No scope restrictions. Status: approved. contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11 ##### Package: sigs.k8s.io/yaml @@ -5325,10 +5325,10 @@ PackageName: sigs.k8s.io/yaml SPDXID: SPDXRef-Package484 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (BSD-3-Clause AND MIT) +PackageLicenseConcluded: BSD-3-Clause AND MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. fork of github.com/ghodss/yaml; not auto-allowlist because: Modified; approved by GB exception 2019-03-11 +PackageComment: Project: Kubernetes. Scope: Approved for Kubernetes only. Status: approved. fork of github.com/ghodss/yaml; not auto-allowlist because: Modified; approved by GB exception 2019-03-11 ##### Package: speter.net/go/exp @@ -5336,10 +5336,10 @@ PackageName: speter.net/go/exp SPDXID: SPDXRef-Package485 PackageDownloadLocation: NOASSERTION FilesAnalyzed: false -PackageLicenseConcluded: (BSD-2-Clause AND BSD-3-Clause) +PackageLicenseConcluded: BSD-2-Clause AND BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. not auto-allowlist because: No measure of stars / forks; approved by GB exception 2019-03-11 +PackageComment: Project: Oopentelemetry. Scope: No scope restrictions. Status: approved. not auto-allowlist because: No measure of stars / forks; approved by GB exception 2019-03-11 ##### Package: sprintf() for JavaScript @@ -5350,7 +5350,7 @@ FilesAnalyzed: false PackageLicenseConcluded: BSD-3-Clause PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11 +PackageComment: Project: All CNCF Projects. Scope: No scope restrictions. Status: approved. contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11 ##### Package: Underscore.js @@ -5361,4 +5361,4 @@ FilesAnalyzed: false PackageLicenseConcluded: MIT PackageLicenseDeclared: NOASSERTION PackageCopyrightText: NOASSERTION -PackageComment: Status: approved. contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11 +PackageComment: Project: All CNCF Projects. Scope: No scope restrictions. Status: approved. contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11 diff --git a/license-exceptions/exceptions.json b/license-exceptions/exceptions.json index d7ea5fb3..1fc1f9ba 100644 --- a/license-exceptions/exceptions.json +++ b/license-exceptions/exceptions.json @@ -1,6 +1,6 @@ { "version": "1.1.0", - "lastUpdated": "2026-02-04", + "lastUpdated": "2026-06-01", "blanketExceptions": [], "exceptions": [ { @@ -8,9 +8,9 @@ "package": "eclipse-ee4j/expressly", "license": "EPL-2.0 OR GPL-2.0-only WITH Classpath-exception-2.0", "project": "Keycloak", - "approvedDate": "2026-02-05", + "approvedDate": "2025-01-12", "status": "approved", - "scope": "required upstream dependency, dynamically linked, unmodified", + "scope": "Approved for dynamic linking only (static linking not permitted); furthermore, the dependency must be used in unmodified form", "results": "https://github.com/cncf/foundation/issues/1177", "comment": "Default implementation of Jakarta Expression Language 6.0, transitive dependency for Hibernate Validator" }, @@ -19,9 +19,9 @@ "package": "libpathrs", "license": "MPL-2.0 OR LGPL-3.0-or-later", "project": "All CNCF Projects", - "approvedDate": "2026-02-05", + "approvedDate": "2025-01-12", "status": "approved", - "scope": "vendored component, build-time dependency, or install-time dependency; statically or dynamically linked", + "scope": "Any CNCF project using libpathrs as a statically linked dependency MUST elect to do so under MPL-2.0 (rather than LGPL-3.0) and declare such election in its documentation. Furthermore, to minimize compliance burdens for CNCF projects and downstream users, it is strongly recommended that projects using libpathrs as a dynamically linked dependency also elect to do so under MPL-2.0 (rather than LGPL-3.0). Furthermore, libpathrs must be maintained either (a) in a distinct directory or module clearly separated from CNCF project code, or (b) retrieved at build/installation time from a third-party repository.", "results": "https://github.com/cncf/foundation/issues/1154", "comment": "Blanket exception: Projects using libpathrs statically linked MUST elect MPL-2.0 and document this. Provides secure path resolution APIs." }, @@ -30,9 +30,9 @@ "package": "go-pathrs", "license": "MPL-2.0", "project": "All CNCF Projects", - "approvedDate": "2026-02-05", + "approvedDate": "2025-01-12", "status": "approved", - "scope": "vendored component, build-time dependency, or install-time dependency; statically or dynamically linked", + "scope": "Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository", "results": "https://github.com/cncf/foundation/issues/1154", "comment": "Blanket exception: Go bindings for libpathrs. Provides secure path resolution APIs." }, @@ -43,18 +43,18 @@ "project": "All CNCF Projects", "approvedDate": "2025-11-21", "status": "approved", - "scope": "vendored component, build-time dependency, or install-time dependency; statically or dynamically linked", + "scope": "Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository", "results": "https://github.com/cncf/foundation/issues/1154", "comment": "Blanket exception: Provides secure path resolution APIs on Linux. Used by Kubernetes, containerd, Podman, buildah, cri-o, nerdctl." }, { "id": "exc-2025-11-21-002", "package": "Liquibase", - "license": "FSL (Functional Source License)", + "license": "FSL Functional Source License", "project": "Keycloak", "approvedDate": "2025-11-21", "status": "denied", - "scope": "incorporated code, dynamically linked", + "scope": "Not Applicable (Denied)", "results": "https://github.com/cncf/foundation/issues/1147", "comment": "Denied: FSL is not an open source license. GB does not approve exceptions for non-OSS licenses." }, @@ -65,7 +65,7 @@ "project": "oscal-compass", "approvedDate": "2025-10-17", "status": "approved", - "scope": "build-time dependency, dynamically linked", + "scope": "Approved only for dynamic linking (static linking is not approved)", "results": "https://github.com/cncf/foundation/issues/1108", "comment": "Pure-Python SSHv2 protocol implementation, used for fetching files" }, @@ -76,7 +76,7 @@ "project": "oscal-compass", "approvedDate": "2025-10-17", "status": "approved", - "scope": "install-time dependency, dynamically linked", + "scope": "Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository", "results": "https://github.com/cncf/foundation/issues/1091", "comment": "Dependency for requests library" }, @@ -87,7 +87,7 @@ "project": "oscal-compass", "approvedDate": "2025-10-17", "status": "approved", - "scope": "build-time dependency, separate process", + "scope": "Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository", "results": "https://github.com/cncf/foundation/issues/1090", "comment": "Dependency for black, mkdocs, mypy" }, @@ -98,7 +98,7 @@ "project": "Kubernetes", "approvedDate": "2025-10-17", "status": "approved", - "scope": "vendored component, build-time dependency, statically linked", + "scope": "No scope restrictions", "results": "https://github.com/cncf/foundation/issues/1074", "comment": "Provides secure path construction functions. Superseded by blanket exception in issue #1154." }, @@ -109,7 +109,7 @@ "project": "Crossplane", "approvedDate": "2024-10-23", "status": "approved", - "scope": "build-time dependency, modified fork", + "scope": "Allowed only if the modified fork is stored in a seperate designated folder separate from the project's own code", "results": "https://github.com/cncf/foundation/issues/818", "comment": "Fork maintained for Crossplane providers, changes contributed upstream" }, @@ -120,7 +120,7 @@ "project": "Crossplane", "approvedDate": "2024-10-23", "status": "approved", - "scope": "build-time dependency, modified fork", + "scope": "Allowed only if the modified fork is stored in a seperate designated folder separate from the project's own code", "results": "https://github.com/cncf/foundation/issues/818", "comment": "Fork maintained for Crossplane providers, changes contributed upstream" }, @@ -131,7 +131,7 @@ "project": "Crossplane", "approvedDate": "2024-10-23", "status": "approved", - "scope": "build-time dependency, modified fork", + "scope": "Allowed only if the modified fork is stored in a seperate designated folder separate from the project's own code", "results": "https://github.com/cncf/foundation/issues/818", "comment": "Fork maintained for Crossplane providers, changes contributed upstream" }, @@ -142,7 +142,7 @@ "project": "Connect", "approvedDate": "2024-10-23", "status": "approved", - "scope": "build-time dependency, unmodified", + "scope": "Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository", "results": "https://github.com/cncf/foundation/issues/823", "comment": "Required for HTTP/2 + TLS with HTTP trailers on iOS. Also used by gRPC Swift." }, @@ -153,7 +153,7 @@ "project": "Crossplane", "approvedDate": "2024-10-23", "status": "approved", - "scope": "build-time dependency, unmodified, linked at build time", + "scope": "Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository", "results": "https://github.com/cncf/foundation/issues/787", "comment": "Various hashicorp terraform dependencies for Upjet: hcl, terraform-json, terraform-plugin-framework, terraform-plugin-go, terraform-plugin-sdk, go-plugin, go-uuid, go-version, logutils, terraform-plugin-log, terraform-registry-address, terraform-svchost, yamux" }, @@ -164,7 +164,7 @@ "project": "containerd", "approvedDate": "2024-10-23", "status": "approved", - "scope": "kernel headers included via #include, no inline functions compiled in", + "scope": "Approved only for ue by containerd as described in the exception request", "results": "https://github.com/cncf/foundation/issues/174", "comment": "Used by containerd/btrfs for btrfs-related ioctl syscalls. Headers from linux/btrfs.h and linux/btrfs_tree.h." }, @@ -173,9 +173,9 @@ "package": "github.com/hashicorp/go-set/v2", "license": "MPL-2.0", "project": "OpenFGA", - "approvedDate": "2024-10-22", + "approvedDate": "2024-10-23", "status": "approved", - "scope": "build-time dependency, linked at build time", + "scope": "Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository", "results": "https://github.com/cncf/foundation/issues/830", "comment": "Unmodified code" }, @@ -184,9 +184,9 @@ "package": "Keycloak Java dependencies", "license": "0BSD, CDDL-1.1, EPL-1.0, EPL-2.0, GPL-2.0-only, GPL-2.0-with-classpath-exception, LGPL-2.1, LGPL-2.1-only, MIT-0, MPL-2.0, UPL-1.0", "project": "Keycloak", - "approvedDate": "2024-10-22", + "approvedDate": "2024-10-23", "status": "approved", - "scope": "transitive dependencies from Quarkus framework, unmodified", + "scope": "Approved for use by Keycloak only in unmodified form", "results": "https://github.com/cncf/foundation/issues/817", "comment": "Multiple Java dependencies including: tslib, h2, mysql-connector-j, jakarta.* APIs, parsson, graalvm SDK, hibernate-*, mariadb-java-client, nashorn-core, reactive-streams" }, @@ -197,7 +197,7 @@ "project": "kubernetes/kops", "approvedDate": "2024-07-16", "status": "approved", - "scope": "build-time dependency, unmodified", + "scope": "Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository", "results": "https://github.com/cncf/foundation/issues/741", "comment": "Main component of Gossip DNS feature for peer-to-peer network K8s API address propagation" }, @@ -208,7 +208,7 @@ "project": "Falco", "approvedDate": "2024-02-27", "status": "approved", - "scope": "kernel module, dual-licensed", + "scope": "Approved for use by Falco only", "results": "https://github.com/cncf/foundation/issues/645", "comment": "Falco's kernel module is dual-licensed GPL-2.0-only OR MIT" }, @@ -219,18 +219,19 @@ "project": "All CNCF Projects", "approvedDate": "2023-08-31", "status": "approved", - "scope": "in-kernel eBPF programs only", + "scope": "Exception applies only to code that runs inside the kernel (not to any code running in the user-space)", "results": "https://github.com/cncf/foundation/blob/main/license-exceptions/README.md#gpl-exceptions-for-in-kernel-ebpf-programs", "comment": "Blanket exception: GPL-2.0 licensed code is permitted for in-kernel eBPF programs only, as this is required by the Linux kernel BPF subsystem." }, { "id": "exc-2023-08-31-001", - "package": "github.com/docker/go-metrics", + "package": "github.com/docker/go-metrics documentation", "license": "CC-BY-SA 4.0", "approvedDate": "2023-08-31", "status": "approved", - "scope": "runtime dependency, statically linked", - "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-08-31" + "scope": "Approval applies only to use of documentation in unmodified form", + "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-08-31", + "project": "Cilium" }, { "id": "exc-2023-08-31-002", @@ -238,7 +239,6 @@ "license": "MPL-2.0", "approvedDate": "2023-08-31", "status": "approved", - "scope": "runtime dependency, dynamically linked", "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-08-31", "results": "https://github.com/cncf/foundation/issues/400", "project": "Cilium" @@ -249,8 +249,9 @@ "license": "MPL-2.0", "approvedDate": "2023-08-31", "status": "approved", - "scope": "build dependency", - "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-08-31" + "scope": "Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository", + "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-08-31", + "project": "Kubernetes" }, { "id": "exc-2023-08-31-004", @@ -258,7 +259,9 @@ "license": "MPL-2.0", "approvedDate": "2023-08-31", "status": "approved", - "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-08-31" + "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-08-31", + "project": "All CNCF Projects", + "scope": "Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository" }, { "id": "exc-2023-06-27-001", @@ -268,7 +271,7 @@ "status": "approved", "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27", "results": "https://github.com/cncf/foundation/issues/400", - "scope": "build-time dependency, unmodified", + "scope": "Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository", "project": "Cilium" }, { @@ -279,7 +282,7 @@ "status": "approved", "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27", "results": "https://github.com/cncf/foundation/issues/400", - "scope": "build-time dependency, unmodified", + "scope": "Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository", "project": "Cilium" }, { @@ -290,7 +293,7 @@ "status": "approved", "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27", "results": "https://github.com/cncf/foundation/issues/400", - "scope": "build-time dependency, unmodified", + "scope": "Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository", "project": "Cilium" }, { @@ -301,7 +304,8 @@ "status": "approved", "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27", "results": "https://github.com/cncf/foundation/issues/300", - "scope": "build-time dependency, unmodified" + "scope": "Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository", + "project": "All CNCF Projects" }, { "id": "exc-2023-06-27-005", @@ -311,7 +315,7 @@ "status": "approved", "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27", "results": "https://github.com/cncf/foundation/issues/400", - "scope": "build-time dependency, unmodified", + "scope": "Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository", "project": "Cilium" }, { @@ -320,7 +324,9 @@ "license": "MPL-2.0", "approvedDate": "2023-06-27", "status": "approved", - "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27" + "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27", + "project": "All CNCF Projects", + "scope": "Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository" }, { "id": "exc-2023-06-27-007", @@ -328,7 +334,9 @@ "license": "MPL-2.0", "approvedDate": "2023-06-27", "status": "approved", - "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27" + "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27", + "project": "All CNCF Projects", + "scope": "Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository" }, { "id": "exc-2023-06-27-008", @@ -336,7 +344,9 @@ "license": "MPL-2.0", "approvedDate": "2023-06-27", "status": "approved", - "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27" + "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27", + "project": "All CNCF Projects", + "scope": "Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository" }, { "id": "exc-2023-06-27-009", @@ -346,7 +356,7 @@ "status": "approved", "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27", "results": "https://github.com/cncf/foundation/issues/400", - "scope": "build-time dependency, unmodified", + "scope": "Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository", "project": "Cilium" }, { @@ -357,7 +367,8 @@ "status": "approved", "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27", "results": "https://github.com/cncf/foundation/issues/485", - "scope": "build-time dependency, unmodified" + "scope": "Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository", + "project": "All CNCF Projects" }, { "id": "exc-2023-06-27-011", @@ -367,7 +378,7 @@ "status": "approved", "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27", "results": "https://github.com/cncf/foundation/issues/526", - "scope": "build-time dependency, unmodified", + "scope": "Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository", "project": "Notary" }, { @@ -376,7 +387,9 @@ "license": "MPL-2.0", "approvedDate": "2023-06-27", "status": "approved", - "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27" + "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27", + "project": "All CNCF Projects", + "scope": "Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository" }, { "id": "exc-2023-06-27-013", @@ -384,7 +397,9 @@ "license": "MPL-2.0", "approvedDate": "2023-06-27", "status": "approved", - "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27" + "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27", + "project": "All CNCF Projects", + "scope": "Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository" }, { "id": "exc-2023-06-27-014", @@ -392,7 +407,9 @@ "license": "MPL-2.0", "approvedDate": "2023-06-27", "status": "approved", - "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27" + "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27", + "project": "All CNCF Projects", + "scope": "Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository" }, { "id": "exc-2023-06-27-015", @@ -402,7 +419,8 @@ "status": "approved", "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27", "results": "https://github.com/cncf/foundation/issues/300", - "scope": "build-time dependency, unmodified" + "scope": "Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository", + "project": "All CNCF Projects" }, { "id": "exc-2023-06-27-016", @@ -410,7 +428,9 @@ "license": "MPL-2.0", "approvedDate": "2023-06-27", "status": "approved", - "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27" + "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27", + "project": "All CNCF Projects", + "scope": "Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository" }, { "id": "exc-2023-06-27-017", @@ -418,7 +438,9 @@ "license": "MPL-2.0", "approvedDate": "2023-06-27", "status": "approved", - "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27" + "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27", + "project": "All CNCF Projects", + "scope": "Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository" }, { "id": "exc-2023-06-27-018", @@ -426,7 +448,9 @@ "license": "MPL-2.0", "approvedDate": "2023-06-27", "status": "approved", - "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27" + "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27", + "project": "All CNCF Projects", + "scope": "Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository" }, { "id": "exc-2023-06-27-019", @@ -434,7 +458,9 @@ "license": "MPL-2.0", "approvedDate": "2023-06-27", "status": "approved", - "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27" + "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27", + "project": "All CNCF Projects", + "scope": "Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository" }, { "id": "exc-2023-06-27-020", @@ -444,7 +470,8 @@ "status": "approved", "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27", "results": "https://github.com/cncf/foundation/issues/297", - "scope": "build-time dependency, unmodified" + "scope": "Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository", + "project": "All CNCF Projects" }, { "id": "exc-2023-06-27-021", @@ -452,7 +479,9 @@ "license": "MPL-2.0", "approvedDate": "2023-06-27", "status": "approved", - "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27" + "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27", + "project": "All CNCF Projects", + "scope": "Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository" }, { "id": "exc-2023-06-27-022", @@ -460,7 +489,9 @@ "license": "MPL-2.0", "approvedDate": "2023-06-27", "status": "approved", - "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27" + "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27", + "project": "All CNCF Projects", + "scope": "Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository" }, { "id": "exc-2023-06-27-023", @@ -470,7 +501,8 @@ "status": "approved", "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27", "results": "https://github.com/cncf/foundation/issues/485", - "scope": "build-time dependency, unmodified" + "scope": "Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository", + "project": "All CNCF Projects" }, { "id": "exc-2023-06-27-024", @@ -480,7 +512,8 @@ "status": "approved", "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27", "results": "https://github.com/cncf/foundation/issues/400", - "scope": "build-time dependency, unmodified" + "scope": "Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository", + "project": "All CNCF Projects" }, { "id": "exc-2023-06-27-025", @@ -490,7 +523,7 @@ "status": "approved", "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2023-06-27", "results": "https://github.com/cncf/foundation/issues/526", - "scope": "build-time dependency, unmodified", + "scope": "Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository", "project": "Notary" }, { @@ -500,7 +533,8 @@ "approvedDate": "2022-04-12", "status": "approved", "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2022-04-12", - "scope": "build-time dependency, unmodified" + "scope": "Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository", + "project": "All CNCF Projects" }, { "id": "exc-2022-04-12-002", @@ -510,7 +544,8 @@ "status": "approved", "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2022-04-12", "results": "https://github.com/cncf/foundation/issues/297", - "scope": "build-time dependency, unmodified" + "scope": "Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository", + "project": "All CNCF Projects" }, { "id": "exc-2022-04-12-003", @@ -520,7 +555,7 @@ "status": "approved", "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2022-04-12", "results": "https://github.com/cncf/foundation/issues/297", - "scope": "build-time dependency, unmodified", + "scope": "Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository", "project": "Dapr" }, { @@ -531,7 +566,7 @@ "status": "approved", "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2022-04-12", "results": "https://github.com/cncf/foundation/issues/297", - "scope": "build-time dependency, unmodified", + "scope": "Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository", "project": "Dapr" }, { @@ -541,7 +576,8 @@ "approvedDate": "2022-04-12", "status": "approved", "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2022-04-12", - "scope": "build-time dependency, unmodified" + "scope": "No scope restrictions", + "project": "All CNCF Projects" }, { "id": "exc-2022-04-12-006", @@ -551,7 +587,8 @@ "status": "approved", "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2022-04-12", "results": "https://github.com/cncf/foundation/issues/297", - "scope": "build-time dependency, unmodified" + "scope": "Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository", + "project": "All CNCF Projects" }, { "id": "exc-2022-04-12-007", @@ -560,7 +597,8 @@ "approvedDate": "2022-04-12", "status": "approved", "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2022-04-12", - "scope": "build-time dependency, unmodified" + "scope": "Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository", + "project": "All CNCF Projects" }, { "id": "exc-2022-04-12-008", @@ -570,7 +608,7 @@ "status": "approved", "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2022-04-12", "results": "https://github.com/cncf/foundation/issues/297", - "scope": "build-time dependency, unmodified", + "scope": "Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository", "project": "Dapr" }, { @@ -581,7 +619,7 @@ "status": "approved", "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2022-04-12", "results": "https://github.com/cncf/foundation/issues/297", - "scope": "build-time dependency, unmodified", + "scope": "Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository", "project": "Dapr" }, { @@ -591,7 +629,8 @@ "approvedDate": "2022-04-12", "status": "approved", "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2022-04-12", - "scope": "build-time dependency, unmodified" + "scope": "No scope restrictions", + "project": "All CNCF Projects" }, { "id": "exc-2022-04-12-011", @@ -601,7 +640,8 @@ "status": "approved", "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2022-04-12", "results": "https://github.com/cncf/foundation/issues/172", - "scope": "build-time dependency, unmodified" + "scope": "Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository", + "project": "All CNCF Projects" }, { "id": "exc-2021-07-19-001", @@ -611,7 +651,8 @@ "status": "approved", "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2021-07-19", "results": "https://github.com/cncf/foundation/issues/138", - "scope": "build-time dependency, unmodified" + "scope": "Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository", + "project": "All CNCF Projects" }, { "id": "exc-2021-07-19-002", @@ -621,7 +662,8 @@ "status": "approved", "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2021-07-19", "results": "https://github.com/cncf/foundation/issues/138", - "scope": "build-time dependency, unmodified" + "scope": "Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-001", @@ -630,7 +672,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-002", @@ -639,7 +682,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-003", @@ -648,7 +691,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-004", @@ -657,7 +700,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-005", @@ -666,16 +710,18 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-006", "package": "ejs", - "license": "(Apache-2.0 AND MIT)", + "license": "Apache-2.0 AND MIT", "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-007", @@ -684,7 +730,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "Kubernetes" }, { "id": "exc-2019-11-01-008", @@ -693,7 +739,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-009", @@ -702,7 +749,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-010", @@ -711,7 +759,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-011", @@ -720,7 +768,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-012", @@ -729,7 +777,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-013", @@ -738,7 +787,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-014", @@ -747,7 +797,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-015", @@ -756,7 +807,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-016", @@ -765,16 +817,17 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "Kubernetes" }, { "id": "exc-2019-11-01-017", "package": "github.com/aws/aws-sdk-go", - "license": "((MIT OR GPL-3.0) AND BSD-3-Clause AND Apache-2.0 AND MIT)", + "license": "(MIT OR GPL-3.0) AND BSD-3-Clause AND Apache-2.0 AND MIT", "approvedDate": "2019-11-01", - "status": "allowlisted", + "status": "approved", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "Allowed as long as the CNCF project imports this SDK through standard dependency management rather than modifying the core SDK code", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-018", @@ -783,7 +836,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-019", @@ -792,7 +845,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-020", @@ -801,7 +855,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-021", @@ -810,7 +865,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-022", @@ -819,7 +874,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-023", @@ -828,7 +883,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-024", @@ -837,7 +892,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-025", @@ -846,7 +902,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-026", @@ -855,7 +912,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "Kubernetes" }, { "id": "exc-2019-11-01-027", @@ -864,7 +921,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-028", @@ -873,7 +931,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-029", @@ -882,25 +941,28 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-030", "package": "github.com/cloudflare/cfssl", - "license": "(BSD-2-Clause AND BSD-3-Clause AND ISC)", + "license": "BSD-2-Clause AND BSD-3-Clause AND ISC", "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-031", "package": "github.com/cloudfoundry-incubator/candiedyaml", - "license": "(Apache-2.0 AND MIT)", + "license": "Apache-2.0 AND MIT", "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-032", @@ -909,7 +971,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "Kubernetes" }, { "id": "exc-2019-11-01-033", @@ -918,7 +980,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-034", @@ -927,7 +989,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "Kubernetes" }, { "id": "exc-2019-11-01-035", @@ -936,7 +998,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-036", @@ -945,16 +1007,16 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-037", "package": "github.com/containerd/containerd", - "license": "(CC-BY-4.0 AND Apache-2.0)", + "license": "CC-BY-4.0 AND Apache-2.0", "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-038", @@ -963,7 +1025,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-039", @@ -972,7 +1034,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-040", @@ -981,7 +1043,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-041", @@ -990,16 +1052,18 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-042", "package": "github.com/coreos/etcd", - "license": "(BSD-3-Clause AND Apache-2.0)", + "license": "BSD-3-Clause AND Apache-2.0", "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-043", @@ -1008,7 +1072,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-044", @@ -1017,7 +1081,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-045", @@ -1026,7 +1090,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-046", @@ -1035,7 +1099,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-047", @@ -1044,7 +1108,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-048", @@ -1053,7 +1117,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-049", @@ -1062,7 +1126,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-050", @@ -1071,7 +1136,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-051", @@ -1080,7 +1146,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-052", @@ -1089,16 +1156,18 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-053", "package": "github.com/daviddengcn/go-colortext", - "license": "(BSD-3-Clause AND MIT)", + "license": "BSD-3-Clause AND MIT", "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-054", @@ -1107,7 +1176,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-055", @@ -1116,7 +1186,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-056", @@ -1125,7 +1196,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "Kubernetes" }, { "id": "exc-2019-11-01-057", @@ -1134,34 +1205,38 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-058", "package": "github.com/digitalocean/godo", - "license": "(BSD-3-Clause AND MIT)", + "license": "BSD-3-Clause AND MIT", "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-059", "package": "github.com/djherbis/atime", - "license": "(BSD-3-Clause AND MIT)", + "license": "BSD-3-Clause AND MIT", "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-060", "package": "github.com/docker/cli", - "license": "(Apache-2.0 AND MIT)", + "license": "Apache-2.0 AND MIT", "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-061", @@ -1170,25 +1245,27 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-062", "package": "github.com/docker/docker", - "license": "(Apache-2.0 AND MIT)", + "license": "Apache-2.0 AND MIT", "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-063", "package": "github.com/docker/engine-api", - "license": "(BSD-3-Clause AND Apache-2.0)", + "license": "BSD-3-Clause AND Apache-2.0", "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-064", @@ -1197,7 +1274,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-065", @@ -1206,7 +1283,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-066", @@ -1215,7 +1292,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-067", @@ -1224,7 +1301,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-068", @@ -1233,7 +1310,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-069", @@ -1242,7 +1319,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-070", @@ -1251,7 +1329,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-071", @@ -1260,7 +1339,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-072", @@ -1269,7 +1349,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-073", @@ -1278,7 +1359,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-074", @@ -1287,7 +1369,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-075", @@ -1296,7 +1379,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-076", @@ -1305,7 +1389,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-077", @@ -1314,16 +1399,18 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-078", "package": "github.com/emirpasic/gods", - "license": "(BSD-2-Clause AND ISC)", + "license": "BSD-2-Clause AND ISC", "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-079", @@ -1332,7 +1419,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "Kubernetes" }, { "id": "exc-2019-11-01-080", @@ -1341,7 +1428,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-081", @@ -1350,7 +1438,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-082", @@ -1359,7 +1448,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-083", @@ -1368,7 +1458,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-084", @@ -1377,7 +1468,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-085", @@ -1386,7 +1477,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-086", @@ -1395,25 +1487,28 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-087", "package": "github.com/fsouza/go-dockerclient", - "license": "(BSD-2-Clause AND Apache-2.0)", + "license": "BSD-2-Clause AND Apache-2.0", "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-088", "package": "github.com/fullsailor/pkcs7", - "license": "(BSD-3-Clause AND MIT)", + "license": "BSD-3-Clause AND MIT", "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-089", @@ -1422,25 +1517,28 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-090", "package": "github.com/ghodss/yaml", - "license": "(BSD-3-Clause AND MIT)", + "license": "BSD-3-Clause AND MIT", "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-091", "package": "github.com/globalsign/mgo", - "license": "(BSD-2-Clause AND BSD-3-Clause)", + "license": "BSD-2-Clause AND BSD-3-Clause", "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-092", @@ -1449,7 +1547,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-093", @@ -1458,7 +1556,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-094", @@ -1467,7 +1565,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-095", @@ -1476,7 +1574,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-096", @@ -1485,7 +1583,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-097", @@ -1494,7 +1592,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-098", @@ -1503,16 +1601,17 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-099", "package": "github.com/go-openapi/spec", - "license": "(CC-BY-4.0 AND Apache-2.0 AND MIT)", + "license": "CC-BY-4.0 AND Apache-2.0 AND MIT", "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-100", @@ -1521,16 +1620,17 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-101", "package": "github.com/go-openapi/swag", - "license": "(Apache-2.0 AND MIT)", + "license": "Apache-2.0 AND MIT", "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-102", @@ -1539,7 +1639,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-103", @@ -1548,16 +1648,18 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-104", "package": "github.com/go-yaml/yaml", - "license": "(Apache-2.0 AND MIT)", + "license": "Apache-2.0 AND MIT", "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-105", @@ -1566,7 +1668,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-106", @@ -1575,25 +1678,28 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-107", "package": "github.com/gogo/protobuf", - "license": "(BSD-2-Clause AND BSD-3-Clause)", + "license": "BSD-2-Clause AND BSD-3-Clause", "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-108", "package": "github.com/golang/dep", - "license": "(LicenseRef-Google-Patents-Notice-Golang AND BSD-3-Clause)", + "license": "LicenseRef-Google-Patents-Notice-Golang AND BSD-3-Clause", "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-109", @@ -1602,7 +1708,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-110", @@ -1611,7 +1717,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-111", @@ -1620,7 +1726,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-112", @@ -1629,7 +1736,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-113", @@ -1638,7 +1745,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-114", @@ -1647,7 +1755,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-115", @@ -1656,7 +1765,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-116", @@ -1665,16 +1774,17 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-117", "package": "github.com/google/certificate-transparency-go", - "license": "(BSD-3-Clause AND Apache-2.0)", + "license": "BSD-3-Clause AND Apache-2.0", "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-118", @@ -1683,7 +1793,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-119", @@ -1692,7 +1802,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-120", @@ -1701,7 +1812,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-121", @@ -1710,7 +1821,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-122", @@ -1719,7 +1830,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-123", @@ -1728,16 +1840,18 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-124", "package": "github.com/googleapis/gnostic", - "license": "(BSD-3-Clause AND Apache-2.0 AND MIT)", + "license": "BSD-3-Clause AND Apache-2.0 AND MIT", "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-125", @@ -1746,7 +1860,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "Kubernetes" }, { "id": "exc-2019-11-01-126", @@ -1755,7 +1869,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-127", @@ -1764,7 +1878,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-128", @@ -1773,7 +1888,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-129", @@ -1782,7 +1898,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-130", @@ -1791,16 +1908,18 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-131", "package": "github.com/gorilla/websocket", - "license": "(BSD-2-Clause AND MIT)", + "license": "BSD-2-Clause AND MIT", "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-132", @@ -1809,7 +1928,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-133", @@ -1818,7 +1938,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-134", @@ -1827,16 +1947,17 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-135", "package": "github.com/grpc-ecosystem/grpc-gateway", - "license": "(BSD-3-Clause AND Apache-2.0)", + "license": "BSD-3-Clause AND Apache-2.0", "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-136", @@ -1845,16 +1966,17 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "Kubernetes" }, { "id": "exc-2019-11-01-137", "package": "github.com/heketi/heketi REST API", - "license": "(Apache-2.0 OR LGPL-3.0-or-later)", + "license": "Apache-2.0 OR LGPL-3.0-or-later", "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "scope": "Approval is limited to the REST API client libraries and does not extend to the Heketi server or other components.", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-138", @@ -1863,7 +1985,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-139", @@ -1872,7 +1995,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-140", @@ -1881,7 +2005,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-141", @@ -1890,7 +2015,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-142", @@ -1899,7 +2024,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-143", @@ -1908,7 +2034,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-144", @@ -1917,7 +2043,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-145", @@ -1926,7 +2053,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-146", @@ -1935,7 +2063,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-147", @@ -1944,7 +2072,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-148", @@ -1953,7 +2082,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-149", @@ -1962,7 +2092,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-150", @@ -1971,7 +2102,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-151", @@ -1980,7 +2111,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-152", @@ -1989,7 +2121,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-153", @@ -1998,7 +2131,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-154", @@ -2007,7 +2141,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-155", @@ -2016,7 +2151,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-156", @@ -2025,7 +2161,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-157", @@ -2034,7 +2171,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "Knative" }, { "id": "exc-2019-11-01-158", @@ -2043,7 +2180,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-159", @@ -2052,7 +2190,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-160", @@ -2061,7 +2200,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-161", @@ -2070,7 +2210,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-162", @@ -2079,7 +2220,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "Kubernetes" }, { "id": "exc-2019-11-01-163", @@ -2088,7 +2229,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "Kubernetes" }, { "id": "exc-2019-11-01-164", @@ -2097,7 +2238,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "Kubernetes" }, { "id": "exc-2019-11-01-165", @@ -2106,7 +2247,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "Kubernetes" }, { "id": "exc-2019-11-01-166", @@ -2115,7 +2256,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-167", @@ -2124,7 +2265,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-168", @@ -2133,7 +2275,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "Kubernetes" }, { "id": "exc-2019-11-01-169", @@ -2142,7 +2284,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-170", @@ -2151,7 +2294,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-171", @@ -2160,7 +2304,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "Kubernetes" }, { "id": "exc-2019-11-01-172", @@ -2169,16 +2313,18 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-173", "package": "github.com/magiconair/properties", - "license": "(BSD-2-Clause AND BSD-3-Clause)", + "license": "BSD-2-Clause AND BSD-3-Clause", "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-174", @@ -2187,7 +2333,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-175", @@ -2196,7 +2343,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-176", @@ -2205,7 +2353,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-177", @@ -2214,7 +2363,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-178", @@ -2223,7 +2373,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-179", @@ -2232,7 +2383,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-180", @@ -2241,7 +2393,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-181", @@ -2250,7 +2403,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-182", @@ -2259,25 +2413,28 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-183", "package": "github.com/mattn/go-zglob", - "license": "(BSD-3-Clause AND MIT)", + "license": "BSD-3-Clause AND MIT", "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-184", "package": "github.com/matttproud/golang_protobuf_extensions", - "license": "(BSD-3-Clause AND Apache-2.0)", + "license": "BSD-3-Clause AND Apache-2.0", "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-185", @@ -2286,7 +2443,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "Kubernetes" }, { "id": "exc-2019-11-01-186", @@ -2295,25 +2452,27 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-187", "package": "github.com/Microsoft/go-winio", - "license": "(BSD-3-Clause AND MIT)", + "license": "BSD-3-Clause AND MIT", "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-188", "package": "github.com/Microsoft/hcsshim", - "license": "(BSD-3-Clause AND MIT)", + "license": "BSD-3-Clause AND MIT", "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-189", @@ -2322,7 +2481,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-190", @@ -2331,7 +2490,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-191", @@ -2340,7 +2500,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "Kubernetes" }, { "id": "exc-2019-11-01-192", @@ -2349,7 +2509,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "Kubernetes" }, { "id": "exc-2019-11-01-193", @@ -2358,7 +2518,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-194", @@ -2367,7 +2528,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-195", @@ -2376,7 +2538,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-196", @@ -2385,7 +2548,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-197", @@ -2394,7 +2558,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-198", @@ -2403,7 +2568,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "Kubernetes" }, { "id": "exc-2019-11-01-199", @@ -2412,7 +2577,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-200", @@ -2421,7 +2586,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-201", @@ -2430,7 +2595,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-202", @@ -2439,7 +2605,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-203", @@ -2448,7 +2615,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-204", @@ -2457,7 +2624,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-205", @@ -2466,16 +2634,18 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-206", "package": "github.com/ncabatoff/process-exporter", - "license": "(Apache-2.0 AND MIT)", + "license": "Apache-2.0 AND MIT", "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-207", @@ -2484,7 +2654,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-208", @@ -2493,7 +2664,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-209", @@ -2502,7 +2673,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-210", @@ -2511,7 +2682,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-211", @@ -2520,7 +2692,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-212", @@ -2529,7 +2702,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-213", @@ -2538,7 +2712,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-214", @@ -2547,7 +2721,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-215", @@ -2556,7 +2730,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-216", @@ -2565,7 +2739,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "Kubernetes" }, { "id": "exc-2019-11-01-217", @@ -2574,7 +2748,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-218", @@ -2583,7 +2758,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-219", @@ -2592,7 +2768,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-220", @@ -2601,7 +2778,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "Kubernetes" }, { "id": "exc-2019-11-01-221", @@ -2610,7 +2787,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-222", @@ -2619,7 +2797,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-223", @@ -2628,7 +2807,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-224", @@ -2637,7 +2817,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-225", @@ -2646,7 +2827,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-226", @@ -2655,7 +2837,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-227", @@ -2664,7 +2847,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-228", @@ -2673,7 +2857,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-229", @@ -2682,7 +2867,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-230", @@ -2691,7 +2877,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-231", @@ -2700,7 +2887,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-232", @@ -2709,34 +2897,38 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-233", "package": "github.com/pquerna/cachecontrol", - "license": "(BSD-3-Clause AND Apache-2.0)", + "license": "BSD-3-Clause AND Apache-2.0", "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-234", "package": "github.com/pquerna/ffjson", - "license": "(BSD-3-Clause AND Apache-2.0 AND ISC)", + "license": "BSD-3-Clause AND Apache-2.0 AND ISC", "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-235", "package": "github.com/prometheus/client_golang", - "license": "(BSD-3-Clause AND Apache-2.0 AND MIT)", + "license": "BSD-3-Clause AND Apache-2.0 AND MIT", "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-236", @@ -2745,16 +2937,17 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-237", "package": "github.com/prometheus/common", - "license": "(BSD-3-Clause AND Apache-2.0)", + "license": "BSD-3-Clause AND Apache-2.0", "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-238", @@ -2763,7 +2956,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-239", @@ -2772,7 +2965,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-240", @@ -2781,7 +2975,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-241", @@ -2790,7 +2985,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "Kubernetes" }, { "id": "exc-2019-11-01-242", @@ -2799,7 +2994,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "Kubernetes" }, { "id": "exc-2019-11-01-243", @@ -2808,7 +3003,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-244", @@ -2817,7 +3012,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-245", @@ -2826,7 +3022,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-246", @@ -2835,7 +3032,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-247", @@ -2844,7 +3042,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-248", @@ -2853,7 +3052,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-249", @@ -2862,7 +3062,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-250", @@ -2871,7 +3072,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-251", @@ -2880,16 +3081,18 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-252", "package": "github.com/scalingdata/gcfg", - "license": "(BSD-2-Clause AND BSD-3-Clause)", + "license": "BSD-2-Clause AND BSD-3-Clause", "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-253", @@ -2898,7 +3101,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-254", @@ -2907,7 +3111,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-255", @@ -2916,7 +3121,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-256", @@ -2925,7 +3131,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-257", @@ -2934,7 +3141,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-258", @@ -2943,7 +3151,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-259", @@ -2952,7 +3161,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-260", @@ -2961,25 +3171,28 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-261", "package": "github.com/sirupsen/logrus", - "license": "(BSD-2-Clause AND BSD-3-Clause AND MIT)", + "license": "BSD-2-Clause AND BSD-3-Clause AND MIT", "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-262", "package": "github.com/skynetservices/skydns", - "license": "(Apache-2.0 AND MIT)", + "license": "Apache-2.0 AND MIT", "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-263", @@ -2988,7 +3201,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-264", @@ -2997,7 +3211,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-265", @@ -3006,7 +3220,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-266", @@ -3015,16 +3229,18 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-267", "package": "github.com/spf13/cobra", - "license": "(Apache-2.0 AND MIT)", + "license": "Apache-2.0 AND MIT", "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-268", @@ -3033,7 +3249,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-269", @@ -3042,7 +3259,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-270", @@ -3051,16 +3269,18 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-271", "package": "github.com/storageos/go-api", - "license": "(BSD-2-Clause AND MIT)", + "license": "BSD-2-Clause AND MIT", "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-272", @@ -3069,7 +3289,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-273", @@ -3078,7 +3299,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-274", @@ -3087,7 +3309,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-275", @@ -3096,7 +3319,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-276", @@ -3105,7 +3329,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-277", @@ -3114,7 +3339,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-278", @@ -3123,7 +3348,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-279", @@ -3132,7 +3357,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-280", @@ -3141,7 +3367,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-281", @@ -3150,7 +3377,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-282", @@ -3159,7 +3387,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-283", @@ -3168,7 +3396,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-284", @@ -3177,7 +3406,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-285", @@ -3186,25 +3415,27 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-286", "package": "github.com/vmware/govmomi", - "license": "(BSD-3-Clause AND Apache-2.0)", + "license": "BSD-3-Clause AND Apache-2.0", "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-287", "package": "github.com/vmware/photon-controller-go-sdk", - "license": "(BSD-3-Clause AND Apache-2.0)", + "license": "BSD-3-Clause AND Apache-2.0", "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-288", @@ -3213,7 +3444,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-289", @@ -3222,7 +3453,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "Kubernetes" }, { "id": "exc-2019-11-01-290", @@ -3231,7 +3462,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-291", @@ -3240,16 +3471,17 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-292", "package": "github.com/xeipuuv/gojsonschema", - "license": "(Apache-2.0 AND MIT)", + "license": "Apache-2.0 AND MIT", "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-293", @@ -3258,7 +3490,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-294", @@ -3267,7 +3500,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-295", @@ -3276,7 +3510,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-296", @@ -3285,7 +3520,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-297", @@ -3294,7 +3529,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-298", @@ -3303,7 +3539,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-299", @@ -3312,7 +3549,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-300", @@ -3321,25 +3559,27 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-301", "package": "golang.org/x/build", - "license": "(LicenseRef-Google-Patents-Notice-Golang AND BSD-3-Clause)", + "license": "LicenseRef-Google-Patents-Notice-Golang AND BSD-3-Clause", "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-302", "package": "golang.org/x/exp", - "license": "(LicenseRef-Google-Patents-Notice-Golang AND BSD-3-Clause)", + "license": "LicenseRef-Google-Patents-Notice-Golang AND BSD-3-Clause", "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-303", @@ -3348,7 +3588,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-304", @@ -3357,52 +3598,58 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-305", "package": "golang.org/x/sync", - "license": "(LicenseRef-Google-Patents-Notice-Golang AND BSD-3-Clause)", + "license": "LicenseRef-Google-Patents-Notice-Golang AND BSD-3-Clause", "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-306", "package": "golang.org/x/sys", - "license": "(LicenseRef-Google-Patents-Notice-Golang AND BSD-2-Clause AND BSD-3-Clause)", + "license": "LicenseRef-Google-Patents-Notice-Golang AND BSD-2-Clause AND BSD-3-Clause", "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-307", "package": "golang.org/x/text", - "license": "(LicenseRef-Google-Patents-Notice-Golang AND BSD-3-Clause)", + "license": "LicenseRef-Google-Patents-Notice-Golang AND BSD-3-Clause", "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-308", "package": "golang.org/x/time", - "license": "(LicenseRef-Google-Patents-Notice-Golang AND BSD-3-Clause)", + "license": "LicenseRef-Google-Patents-Notice-Golang AND BSD-3-Clause", "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-309", "package": "golang.org/x/tools", - "license": "(LicenseRef-Google-Patents-Notice-Golang AND BSD-3-Clause AND Apache-2.0 AND MIT)", + "license": "LicenseRef-Google-Patents-Notice-Golang AND BSD-3-Clause AND Apache-2.0 AND MIT", "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-310", @@ -3411,16 +3658,18 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-311", "package": "gonum.org/v1/gonum", - "license": "((BSD-3-Clause OR CC0-1.0) AND BSD-3-Clause)", + "license": "BSD-3-Clause OR CC0-1.0 AND BSD-3-Clause", "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-312", @@ -3429,7 +3678,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-313", @@ -3438,16 +3687,17 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-314", "package": "gopkg.in/check.v1", - "license": "(BSD-2-Clause AND BSD-3-Clause)", + "license": "BSD-2-Clause AND BSD-3-Clause", "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-315", @@ -3456,7 +3706,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-316", @@ -3465,7 +3716,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-317", @@ -3474,7 +3726,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-318", @@ -3483,7 +3736,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-319", @@ -3492,7 +3746,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-320", @@ -3501,7 +3756,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-321", @@ -3510,25 +3766,28 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-322", "package": "gopkg.in/olivere/elastic.v3", - "license": "(BSD-3-Clause AND MIT)", + "license": "BSD-3-Clause AND MIT", "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-323", "package": "gopkg.in/olivere/elastic.v5", - "license": "(BSD-3-Clause AND MIT)", + "license": "BSD-3-Clause AND MIT", "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-324", @@ -3537,16 +3796,18 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-325", "package": "gopkg.in/square/go-jose.v2", - "license": "(BSD-3-Clause AND Apache-2.0)", + "license": "BSD-3-Clause AND Apache-2.0", "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-326", @@ -3555,7 +3816,7 @@ "approvedDate": "2019-11-01", "status": "apache-2.0", "comment": "Apache-2.0, no approval needed", - "scope": "build-time dependency" + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-327", @@ -3564,7 +3825,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-328", @@ -3573,16 +3835,18 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-329", "package": "marked", - "license": "(BSD-3-Clause AND MIT)", + "license": "BSD-3-Clause AND MIT", "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-330", @@ -3591,7 +3855,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-331", @@ -3600,7 +3865,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-332", @@ -3609,7 +3875,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-333", @@ -3618,7 +3885,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-334", @@ -3627,7 +3895,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-335", @@ -3636,7 +3905,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-11-01-336", @@ -3645,7 +3915,8 @@ "approvedDate": "2019-11-01", "status": "allowlisted", "comment": "allowlisted", - "scope": "build-time dependency" + "scope": "See Allowlist Policy requirements", + "project": "All CNCF Projects" }, { "id": "exc-2019-05-20-001", @@ -3653,7 +3924,9 @@ "license": "GPL-2.0-only", "approvedDate": "2019-05-20", "status": "approved", - "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-05-20" + "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-05-20", + "project": "Kubernetes", + "scope": "Approved ONLY as an OPTIONl subdependency of Minikube (not approved for use on a standalone basis or as a required dependency)" }, { "id": "exc-2019-03-11-001", @@ -3661,7 +3934,9 @@ "license": "MIT", "approvedDate": "2019-03-11", "status": "approved", - "comment": "contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11" + "comment": "contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11", + "project": "All CNCF Projects", + "scope": "No scope restrictions" }, { "id": "exc-2019-03-11-002", @@ -3669,7 +3944,9 @@ "license": "MIT", "approvedDate": "2019-03-11", "status": "approved", - "comment": "contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11" + "comment": "contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11", + "project": "All CNCF Projects", + "scope": "No scope restrictions" }, { "id": "exc-2019-03-11-003", @@ -3677,7 +3954,9 @@ "license": "MIT", "approvedDate": "2019-03-11", "status": "approved", - "comment": "modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11" + "comment": "modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11", + "project": "Kubernetes", + "scope": "No scope restrictions" }, { "id": "exc-2019-03-11-004", @@ -3685,7 +3964,9 @@ "license": "MIT", "approvedDate": "2019-03-11", "status": "approved", - "comment": "contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11" + "comment": "contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11", + "project": "All CNCF Projects", + "scope": "No scope restrictions" }, { "id": "exc-2019-03-11-005", @@ -3693,7 +3974,9 @@ "license": "MIT", "approvedDate": "2019-03-11", "status": "approved", - "comment": "not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11" + "comment": "not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11", + "project": "Kubernetes", + "scope": "No scope restrictions" }, { "id": "exc-2019-03-11-006", @@ -3701,15 +3984,19 @@ "license": "BSD-3-Clause", "approvedDate": "2019-03-11", "status": "approved", - "comment": "not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11" + "comment": "not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11", + "project": "All CNCF Projects", + "scope": "No scope restrictions" }, { "id": "exc-2019-03-11-007", "package": "bootstrap", - "license": "(CC-BY-3.0 AND MIT)", + "license": "CC-BY-3.0 AND MIT", "approvedDate": "2019-03-11", "status": "approved", - "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11" + "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11", + "project": "All CNCF Projects", + "scope": "No scope restrictions" }, { "id": "exc-2019-03-11-008", @@ -3717,15 +4004,19 @@ "license": "BSD-3-Clause", "approvedDate": "2019-03-11", "status": "approved", - "comment": "contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11" + "comment": "contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11", + "project": "All CNCF Projects", + "scope": "No scope restrictions" }, { "id": "exc-2019-03-11-009", "package": "font-awesome", - "license": "(CC-BY-3.0 AND MIT AND OFL-1.1)", + "license": "CC-BY-3.0 AND MIT AND OFL-1.1", "approvedDate": "2019-03-11", "status": "approved", - "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11" + "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11", + "project": "All CNCF Projects", + "scope": "No scope restrictions" }, { "id": "exc-2019-03-11-010", @@ -3733,7 +4024,9 @@ "license": "MIT", "approvedDate": "2019-03-11", "status": "approved", - "comment": "contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11" + "comment": "contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11", + "project": "All CNCF Projects", + "scope": "No scope restrictions" }, { "id": "exc-2019-03-11-011", @@ -3741,7 +4034,9 @@ "license": "MIT", "approvedDate": "2019-03-11", "status": "approved", - "comment": "not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11" + "comment": "not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11", + "project": "Kubernetes", + "scope": "No scope restrictions" }, { "id": "exc-2019-03-11-012", @@ -3749,7 +4044,9 @@ "license": "BSD-3-Clause", "approvedDate": "2019-03-11", "status": "approved", - "comment": "modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11" + "comment": "modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11", + "project": "Ingress-Nginx", + "scope": "No scope restrictions" }, { "id": "exc-2019-03-11-013", @@ -3757,15 +4054,19 @@ "license": "MPL-2.0", "approvedDate": "2019-03-11", "status": "approved", - "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11" + "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11", + "project": "All CNCF Projects", + "scope": "Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository" }, { "id": "exc-2019-03-11-014", "package": "github.com/client9/misspell", - "license": "(Unlicense AND BSD-3-Clause AND MIT)", + "license": "Unlicense AND BSD-3-Clause AND MIT", "approvedDate": "2019-03-11", "status": "approved", - "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11" + "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11", + "project": "All CNCF Projects", + "scope": "No scope restrictions" }, { "id": "exc-2019-03-11-015", @@ -3773,7 +4074,9 @@ "license": "BSD-3-Clause", "approvedDate": "2019-03-11", "status": "approved", - "comment": "not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11" + "comment": "not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11", + "project": "Kubernetes", + "scope": "No scope restrictions" }, { "id": "exc-2019-03-11-016", @@ -3781,31 +4084,39 @@ "license": "MPL-2.0", "approvedDate": "2019-03-11", "status": "approved", - "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11" + "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11", + "project": "Kubernetes", + "scope": "Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository" }, { "id": "exc-2019-03-11-017", "package": "github.com/dgryski/go-onlinestats", - "license": "(MIT AND LicenseRef-Public-domain-statement)", + "license": "MIT AND LicenseRef-Public-domain-statement", "approvedDate": "2019-03-11", "status": "approved", - "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11" + "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11", + "project": "OpenTelemetry", + "scope": "No scope restrictions" }, { "id": "exc-2019-03-11-018", "package": "github.com/docker/go-units", - "license": "(CC-BY-SA-4.0 AND CC-BY-4.0 AND Apache-2.0)", + "license": "CC-BY-SA-4.0 AND CC-BY-4.0 AND Apache-2.0", "approvedDate": "2019-03-11", "status": "approved", - "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11" + "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11", + "project": "All CNCF Projects", + "scope": "No scope restrictions" }, { "id": "exc-2019-03-11-019", "package": "github.com/docker/spdystream", - "license": "(CC-BY-SA-4.0 AND CC-BY-4.0 AND BSD-3-Clause AND Apache-2.0)", + "license": "CC-BY-SA-4.0 AND CC-BY-4.0 AND BSD-3-Clause AND Apache-2.0", "approvedDate": "2019-03-11", "status": "approved", - "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11" + "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11", + "project": "Kubernetes", + "scope": "No scope restrictions" }, { "id": "exc-2019-03-11-020", @@ -3813,7 +4124,9 @@ "license": "MPL-2.0", "approvedDate": "2019-03-11", "status": "approved", - "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11" + "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11", + "project": "All CNCF Projects", + "scope": "Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository" }, { "id": "exc-2019-03-11-021", @@ -3821,23 +4134,29 @@ "license": "BSD-3-Clause", "approvedDate": "2019-03-11", "status": "approved", - "comment": "modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11" + "comment": "modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11", + "project": "All CNCF Projects", + "scope": "No scope restrictions" }, { "id": "exc-2019-03-11-022", "package": "github.com/google/go-github", - "license": "(BSD-3-Clause AND CC-BY-3.0)", + "license": "BSD-3-Clause AND CC-BY-3.0", "approvedDate": "2019-03-11", "status": "approved", - "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11" + "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11", + "project": "All CNCF Projects", + "scope": "No scope restrictions" }, { "id": "exc-2019-03-11-023", "package": "github.com/grpc-ecosystem/grpc-opentracing", - "license": "(BSD-3-Clause AND LicenseRef-Google-Patents-Notice-GRPC)", + "license": "BSD-3-Clause AND LicenseRef-Google-Patents-Notice-GRPC", "approvedDate": "2019-03-11", "status": "approved", - "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11" + "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11", + "project": "All CNCF Projects", + "scope": "No scope restrictions" }, { "id": "exc-2019-03-11-024", @@ -3845,7 +4164,9 @@ "license": "MPL-2.0", "approvedDate": "2019-03-11", "status": "approved", - "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11" + "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11", + "project": "All CNCF Projects", + "scope": "Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository" }, { "id": "exc-2019-03-11-025", @@ -3853,7 +4174,9 @@ "license": "MPL-2.0", "approvedDate": "2019-03-11", "status": "approved", - "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11" + "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11", + "project": "All CNCF Projects", + "scope": "Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository" }, { "id": "exc-2019-03-11-026", @@ -3861,7 +4184,9 @@ "license": "MPL-2.0", "approvedDate": "2019-03-11", "status": "approved", - "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11" + "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11", + "project": "All CNCF Projects", + "scope": "Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository" }, { "id": "exc-2019-03-11-027", @@ -3869,7 +4194,9 @@ "license": "MPL-2.0", "approvedDate": "2019-03-11", "status": "approved", - "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11" + "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11", + "project": "All CNCF Projects", + "scope": "Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository" }, { "id": "exc-2019-03-11-028", @@ -3877,7 +4204,9 @@ "license": "MPL-2.0", "approvedDate": "2019-03-11", "status": "approved", - "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11" + "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11", + "project": "All CNCF Projects", + "scope": "Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository" }, { "id": "exc-2019-03-11-029", @@ -3885,15 +4214,19 @@ "license": "MPL-2.0", "approvedDate": "2019-03-11", "status": "approved", - "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11" + "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11", + "project": "Kubernetes", + "scope": "Allowed only if the dependency is either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository" }, { "id": "exc-2019-03-11-030", "package": "github.com/howeyc/gopass", - "license": "(ISC AND CDDL-1.0)", + "license": "ISC AND CDDL-1.0", "approvedDate": "2019-03-11", "status": "approved", - "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11" + "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11", + "project": "Kubernetes", + "scope": "Allowed only if the dependency files are either (a) stored unmodified in a designated third-party folder, or (b) not stored in the CNCF project repository and instead retrieved at installation or build time from the upstream third party repository or package repository" }, { "id": "exc-2019-03-11-031", @@ -3901,7 +4234,9 @@ "license": "MIT", "approvedDate": "2019-03-11", "status": "approved", - "comment": "not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11" + "comment": "not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11", + "project": "All CNCF Projects", + "scope": "No scope restrictions" }, { "id": "exc-2019-03-11-032", @@ -3909,7 +4244,9 @@ "license": "BSD-3-Clause", "approvedDate": "2019-03-11", "status": "approved", - "comment": "not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11" + "comment": "not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11", + "project": "Kubernetes", + "scope": "No scope restrictions" }, { "id": "exc-2019-03-11-033", @@ -3917,7 +4254,9 @@ "license": "MIT", "approvedDate": "2019-03-11", "status": "approved", - "comment": "not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11" + "comment": "not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11", + "project": "All CNCF Projects", + "scope": "No scope restrictions" }, { "id": "exc-2019-03-11-034", @@ -3925,7 +4264,9 @@ "license": "MIT", "approvedDate": "2019-03-11", "status": "approved", - "comment": "not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11" + "comment": "not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11", + "project": "Kubernetes", + "scope": "No scope restrictions" }, { "id": "exc-2019-03-11-035", @@ -3933,7 +4274,9 @@ "license": "MIT", "approvedDate": "2019-03-11", "status": "approved", - "comment": "not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11" + "comment": "not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11", + "project": "All CNCF Projects", + "scope": "No scope restrictions" }, { "id": "exc-2019-03-11-036", @@ -3941,7 +4284,9 @@ "license": "CC0-1.0", "approvedDate": "2019-03-11", "status": "approved", - "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11" + "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11", + "project": "All CNCF Projects", + "scope": "No scope restrictions" }, { "id": "exc-2019-03-11-037", @@ -3949,7 +4294,9 @@ "license": "MIT", "approvedDate": "2019-03-11", "status": "approved", - "comment": "not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11" + "comment": "not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11", + "project": "All CNCF Projects", + "scope": "No scope restrictions" }, { "id": "exc-2019-03-11-038", @@ -3957,15 +4304,19 @@ "license": "MIT", "approvedDate": "2019-03-11", "status": "approved", - "comment": "not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11" + "comment": "not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11", + "project": "All CNCF Projects", + "scope": "No scope restrictions" }, { "id": "exc-2019-03-11-039", "package": "github.com/mattn/go-sqlite3", - "license": "(MIT AND LicenseRef-Public-domain-statement)", + "license": "MIT AND LicenseRef-Public-domain-statement", "approvedDate": "2019-03-11", "status": "approved", - "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11" + "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11", + "project": "All CNCF Projects", + "scope": "No scope restrictions" }, { "id": "exc-2019-03-11-040", @@ -3973,7 +4324,9 @@ "license": "MIT", "approvedDate": "2019-03-11", "status": "approved", - "comment": "modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11" + "comment": "modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11", + "project": "All CNCF Projects", + "scope": "No scope restrictions" }, { "id": "exc-2019-03-11-041", @@ -3981,23 +4334,29 @@ "license": "BSD-2-Clause-FreeBSD", "approvedDate": "2019-03-11", "status": "approved", - "comment": "not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11" + "comment": "not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11", + "project": "All CNCF Projects", + "scope": "No scope restrictions" }, { "id": "exc-2019-03-11-042", "package": "github.com/opencontainers/go-digest", - "license": "(CC-BY-SA-4.0 AND CC-BY-4.0 AND Apache-2.0)", + "license": "CC-BY-SA-4.0 AND CC-BY-4.0 AND Apache-2.0", "approvedDate": "2019-03-11", "status": "approved", - "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11" + "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11", + "project": "All CNCF Projects", + "scope": "No scope restrictions" }, { "id": "exc-2019-03-11-043", "package": "github.com/opencontainers/runc", - "license": "(LicenseRef-CC-unspecified AND Apache-2.0)", + "license": "CC-BY-4.0 AND Apache-2.0", "approvedDate": "2019-03-11", "status": "approved", - "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11" + "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11", + "project": "All CNCF Projects", + "scope": "No scope restrictions" }, { "id": "exc-2019-03-11-044", @@ -4005,7 +4364,9 @@ "license": "BSD-3-Clause", "approvedDate": "2019-03-11", "status": "approved", - "comment": "not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11" + "comment": "not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11", + "project": "Kubernetes", + "scope": "No scope restrictions" }, { "id": "exc-2019-03-11-045", @@ -4013,23 +4374,29 @@ "license": "MIT", "approvedDate": "2019-03-11", "status": "approved", - "comment": "not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11" + "comment": "not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11", + "project": "Kubernetes", + "scope": "No scope restrictions" }, { "id": "exc-2019-03-11-046", "package": "github.com/sigma/go-inotify", - "license": "(LicenseRef-Google-Patents-Notice-Golang AND BSD-3-Clause)", + "license": "LicenseRef-Google-Patents-Notice-Golang AND BSD-3-Clause", "approvedDate": "2019-03-11", "status": "approved", - "comment": "not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11" + "comment": "not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11", + "project": "Kubernetes", + "scope": "No scope restrictions" }, { "id": "exc-2019-03-11-047", "package": "github.com/spotinst/spotinst-sdk-go", - "license": "(BSD-3-Clause AND Apache-2.0 AND MIT)", + "license": "BSD-3-Clause AND Apache-2.0 AND MIT", "approvedDate": "2019-03-11", - "status": "approved", - "comment": "not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11" + "status": "allowlisted", + "comment": "not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11", + "project": "All CNCF Projects", + "scope": "See Allowlist Policy requirements" }, { "id": "exc-2019-03-11-048", @@ -4037,7 +4404,9 @@ "license": "BSD-3-Clause", "approvedDate": "2019-03-11", "status": "approved", - "comment": "not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11" + "comment": "not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11", + "project": "All CNCF Projects", + "scope": "No scope restrictions" }, { "id": "exc-2019-03-11-049", @@ -4045,23 +4414,29 @@ "license": "BSD-3-Clause", "approvedDate": "2019-03-11", "status": "approved", - "comment": "not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11" + "comment": "not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11", + "project": "All CNCF Projects", + "scope": "No scope restrictions" }, { "id": "exc-2019-03-11-050", "package": "github.com/xanzy/ssh-agent", - "license": "(Apache-2.0 AND MIT)", + "license": "Apache-2.0 AND MIT", "approvedDate": "2019-03-11", "status": "approved", - "comment": "not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11" + "comment": "not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11", + "project": "OpenTelemetry", + "scope": "No scope restrictions" }, { "id": "exc-2019-03-11-051", "package": "github.com/zchee/go-vmnet", - "license": "(BSD-2-Clause AND BSD-3-Clause)", + "license": "BSD-2-Clause AND BSD-3-Clause", "approvedDate": "2019-03-11", "status": "approved", - "comment": "not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11" + "comment": "not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11", + "project": "Kubernetes & Minikube", + "scope": "No scope restrictions" }, { "id": "exc-2019-03-11-052", @@ -4069,7 +4444,9 @@ "license": "BSD-3-Clause", "approvedDate": "2019-03-11", "status": "approved", - "comment": "modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11" + "comment": "modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11", + "project": "All CNCF Projects", + "scope": "No scope restrictions" }, { "id": "exc-2019-03-11-053", @@ -4077,7 +4454,9 @@ "license": "BSD-3-Clause", "approvedDate": "2019-03-11", "status": "approved", - "comment": "modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11" + "comment": "modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11", + "project": "All CNCF Projects", + "scope": "No scope restrictions" }, { "id": "exc-2019-03-11-054", @@ -4085,39 +4464,49 @@ "license": "BSD-3-Clause", "approvedDate": "2019-03-11", "status": "approved", - "comment": "modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11" + "comment": "modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11", + "project": "All CNCF Projects", + "scope": "No scope restrictions" }, { "id": "exc-2019-03-11-055", "package": "golang.org/x/crypto", - "license": "(LicenseRef-Google-Patents-Notice-Golang AND BSD-3-Clause AND MIT AND LicenseRef-Public-domain-statement)", + "license": "LicenseRef-Google-Patents-Notice-Golang AND BSD-3-Clause AND MIT AND LicenseRef-Public-domain-statement", "approvedDate": "2019-03-11", "status": "approved", - "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11" + "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11", + "project": "All CNCF Projects", + "scope": "No scope restrictions" }, { "id": "exc-2019-03-11-056", "package": "golang.org/x/net", - "license": "(LicenseRef-Google-Patents-Notice-Golang AND BSD-2-Clause AND BSD-3-Clause AND CC-BY-3.0 AND (BSD-3-Clause OR LicenseRef-W3C-Test-Suite-License-1))", + "license": "LicenseRef-Google-Patents-Notice-Golang AND BSD-2-Clause AND BSD-3-Clause AND CC-BY-3.0 AND BSD-3-Clause OR LicenseRef-W3C-Test-Suite-License-1", "approvedDate": "2019-03-11", "status": "approved", - "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11" + "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11", + "project": "All CNCF Projects", + "scope": "No scope restrictions" }, { "id": "exc-2019-03-11-057", "package": "golang/expansion", - "license": "(LicenseRef-Google-Patents-Notice-Golang AND BSD-3-Clause)", + "license": "LicenseRef-Google-Patents-Notice-Golang AND BSD-3-Clause", "approvedDate": "2019-03-11", "status": "approved", - "comment": "modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11" + "comment": "modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11", + "project": "All CNCF Projects", + "scope": "No scope restrictions" }, { "id": "exc-2019-03-11-058", "package": "golang/go/types", - "license": "(LicenseRef-Google-Patents-Notice-Golang AND BSD-3-Clause)", + "license": "LicenseRef-Google-Patents-Notice-Golang AND BSD-3-Clause", "approvedDate": "2019-03-11", "status": "approved", - "comment": "modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11" + "comment": "modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11", + "project": "All CNCF Projects", + "scope": "No scope restrictions" }, { "id": "exc-2019-03-11-059", @@ -4125,7 +4514,9 @@ "license": "BSD-3-Clause", "approvedDate": "2019-03-11", "status": "approved", - "comment": "modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11" + "comment": "modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11", + "project": "All CNCF Projects", + "scope": "No scope restrictions" }, { "id": "exc-2019-03-11-060", @@ -4133,7 +4524,9 @@ "license": "BSD-3-Clause", "approvedDate": "2019-03-11", "status": "approved", - "comment": "modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11" + "comment": "modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11", + "project": "All CNCF Projects", + "scope": "No scope restrictions" }, { "id": "exc-2019-03-11-061", @@ -4141,23 +4534,29 @@ "license": "BSD-3-Clause", "approvedDate": "2019-03-11", "status": "approved", - "comment": "modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11" + "comment": "modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11", + "project": "All CNCF Projects", + "scope": "No scope restrictions" }, { "id": "exc-2019-03-11-062", "package": "golang/reflect", - "license": "(LicenseRef-Google-Patents-Notice-Golang AND BSD-3-Clause)", + "license": "LicenseRef-Google-Patents-Notice-Golang AND BSD-3-Clause", "approvedDate": "2019-03-11", "status": "approved", - "comment": "modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11" + "comment": "modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11", + "project": "All CNCF Projects", + "scope": "No scope restrictions" }, { "id": "exc-2019-03-11-063", "package": "golang/template", - "license": "(LicenseRef-Google-Patents-Notice-Golang AND BSD-3-Clause)", + "license": "LicenseRef-Google-Patents-Notice-Golang AND BSD-3-Clause", "approvedDate": "2019-03-11", "status": "approved", - "comment": "modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11" + "comment": "modified from upstream; not auto-allowlist because: Modified; approved by GB exception 2019-03-11", + "project": "All CNCF Projects", + "scope": "No scope restrictions" }, { "id": "exc-2019-03-11-064", @@ -4165,31 +4564,39 @@ "license": "BSD-3-Clause", "approvedDate": "2019-03-11", "status": "approved", - "comment": "contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11" + "comment": "contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11", + "project": "All CNCF Projects", + "scope": "No scope restrictions" }, { "id": "exc-2019-03-11-065", "package": "google.golang.org/api", - "license": "(BSD-3-Clause AND Apache-2.0 AND MIT)", + "license": "BSD-3-Clause AND Apache-2.0 AND MIT", "approvedDate": "2019-03-11", - "status": "approved", - "comment": "not auto-allowlist because: No measure of stars / forks; approved by GB exception 2019-03-11" + "status": "allowlisted", + "comment": "not auto-allowlist because: No measure of stars / forks; approved by GB exception 2019-03-11", + "project": "All CNCF Projects", + "scope": "See Allowlist Policy requirements" }, { "id": "exc-2019-03-11-066", "package": "google.golang.org/appengine", - "license": "(BSD-3-Clause AND Apache-2.0)", + "license": "BSD-3-Clause AND Apache-2.0", "approvedDate": "2019-03-11", "status": "approved", - "comment": "not auto-allowlist because: No measure of stars / forks; approved by GB exception 2019-03-11" + "comment": "not auto-allowlist because: No measure of stars / forks; approved by GB exception 2019-03-11", + "project": "Kubernetes", + "scope": "No scope restrictions" }, { "id": "exc-2019-03-11-067", "package": "google.golang.org/grpc", - "license": "(BSD-3-Clause AND Apache-2.0 AND LicenseRef-Google-Patents-Notice-GRPC)", + "license": "BSD-3-Clause AND Apache-2.0 AND LicenseRef-Google-Patents-Notice-GRPC", "approvedDate": "2019-03-11", "status": "approved", - "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11" + "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11", + "project": "All CNCF Projects", + "scope": "No scope restrictions" }, { "id": "exc-2019-03-11-068", @@ -4197,7 +4604,9 @@ "license": "BSD-2-Clause", "approvedDate": "2019-03-11", "status": "approved", - "comment": "not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11" + "comment": "not auto-allowlist because: Insufficient stars / forks; approved by GB exception 2019-03-11", + "project": "All CNCF Projects", + "scope": "No scope restrictions" }, { "id": "exc-2019-03-11-069", @@ -4205,7 +4614,9 @@ "license": "MIT", "approvedDate": "2019-03-11", "status": "approved", - "comment": "contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11" + "comment": "contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11", + "project": "All CNCF Projects", + "scope": "No scope restrictions" }, { "id": "exc-2019-03-11-070", @@ -4213,15 +4624,19 @@ "license": "BSD-3-Clause", "approvedDate": "2019-03-11", "status": "approved", - "comment": "contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11" + "comment": "contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11", + "project": "All CNCF Projects", + "scope": "No scope restrictions" }, { "id": "exc-2019-03-11-071", "package": "highlight.js", - "license": "(BSD-3-Clause AND MIT AND CC0-1.0 AND LicenseRef-Public-domain-statement)", + "license": "BSD-3-Clause AND MIT AND CC0-1.0 AND LicenseRef-Public-domain-statement", "approvedDate": "2019-03-11", "status": "approved", - "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11" + "comment": "not auto-allowlist because: Non-allowlist license(s); approved by GB exception 2019-03-11", + "project": "All CNCF Projects", + "scope": "No scope restrictions" }, { "id": "exc-2019-03-11-072", @@ -4229,7 +4644,9 @@ "license": "BSD-3-Clause", "approvedDate": "2019-03-11", "status": "approved", - "comment": "not auto-allowlist because: No measure of stars / forks; approved by GB exception 2019-03-11" + "comment": "not auto-allowlist because: No measure of stars / forks; approved by GB exception 2019-03-11", + "project": "All CNCF Projects", + "scope": "No scope restrictions" }, { "id": "exc-2019-03-11-073", @@ -4237,23 +4654,29 @@ "license": "MIT", "approvedDate": "2019-03-11", "status": "approved", - "comment": "contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11" + "comment": "contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11", + "project": "All CNCF Projects", + "scope": "No scope restrictions" }, { "id": "exc-2019-03-11-074", "package": "jQuery BBQ", - "license": "(MIT OR GPL-2.0+)", + "license": "MIT OR GPL-2.0+", "approvedDate": "2019-03-11", "status": "approved", - "comment": "contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11" + "comment": "contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11", + "project": "All CNCF Projects", + "scope": "Any CNCF project using this dependency must elect to do so under the MIT License (rather than GPL-2.0) and declare such election in its documentation" }, { "id": "exc-2019-03-11-075", "package": "jQuery hashchange event", - "license": "(GPL-2.0+ OR MIT)", + "license": "GPL-2.0+ OR MIT", "approvedDate": "2019-03-11", "status": "approved", - "comment": "contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11" + "comment": "contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11", + "project": "All CNCF Projects", + "scope": "Any CNCF project using this dependency must elect to do so under the MIT License (rather than GPL-2.0) and declare such election in its documentation" }, { "id": "exc-2019-03-11-076", @@ -4261,7 +4684,9 @@ "license": "MIT", "approvedDate": "2019-03-11", "status": "approved", - "comment": "contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11" + "comment": "contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11", + "project": "All CNCF Projects", + "scope": "No scope restrictions" }, { "id": "exc-2019-03-11-077", @@ -4269,7 +4694,9 @@ "license": "MIT", "approvedDate": "2019-03-11", "status": "approved", - "comment": "contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11" + "comment": "contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11", + "project": "All CNCF Projects", + "scope": "No scope restrictions" }, { "id": "exc-2019-03-11-078", @@ -4277,7 +4704,9 @@ "license": "MIT", "approvedDate": "2019-03-11", "status": "approved", - "comment": "contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11" + "comment": "contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11", + "project": "All CNCF Projects", + "scope": "No scope restrictions" }, { "id": "exc-2019-03-11-079", @@ -4285,7 +4714,9 @@ "license": "MIT", "approvedDate": "2019-03-11", "status": "approved", - "comment": "contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11" + "comment": "contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11", + "project": "All CNCF Projects", + "scope": "No scope restrictions" }, { "id": "exc-2019-03-11-080", @@ -4293,7 +4724,9 @@ "license": "MIT", "approvedDate": "2019-03-11", "status": "approved", - "comment": "contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11" + "comment": "contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11", + "project": "All CNCF Projects", + "scope": "No scope restrictions" }, { "id": "exc-2019-03-11-081", @@ -4301,7 +4734,9 @@ "license": "MIT", "approvedDate": "2019-03-11", "status": "approved", - "comment": "contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11" + "comment": "contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11", + "project": "All CNCF Projects", + "scope": "No scope restrictions" }, { "id": "exc-2019-03-11-082", @@ -4309,7 +4744,9 @@ "license": "MIT", "approvedDate": "2019-03-11", "status": "approved", - "comment": "not auto-allowlist because: No measure of stars / forks; approved by GB exception 2019-03-11" + "comment": "not auto-allowlist because: No measure of stars / forks; approved by GB exception 2019-03-11", + "project": "Kubernetes", + "scope": "No scope restrictions" }, { "id": "exc-2019-03-11-083", @@ -4317,7 +4754,9 @@ "license": "BSD-3-Clause", "approvedDate": "2019-03-11", "status": "approved", - "comment": "contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11" + "comment": "contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11", + "project": "All CNCF Projects", + "scope": "No scope restrictions" }, { "id": "exc-2019-03-11-084", @@ -4325,23 +4764,29 @@ "license": "ISC", "approvedDate": "2019-03-11", "status": "approved", - "comment": "contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11" + "comment": "contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11", + "project": "All CNCF Projects", + "scope": "No scope restrictions" }, { "id": "exc-2019-03-11-085", "package": "sigs.k8s.io/yaml", - "license": "(BSD-3-Clause AND MIT)", + "license": "BSD-3-Clause AND MIT", "approvedDate": "2019-03-11", "status": "approved", - "comment": "fork of github.com/ghodss/yaml; not auto-allowlist because: Modified; approved by GB exception 2019-03-11" + "comment": "fork of github.com/ghodss/yaml; not auto-allowlist because: Modified; approved by GB exception 2019-03-11", + "project": "Kubernetes", + "scope": "Approved for Kubernetes only" }, { "id": "exc-2019-03-11-086", "package": "speter.net/go/exp", - "license": "(BSD-2-Clause AND BSD-3-Clause)", + "license": "BSD-2-Clause AND BSD-3-Clause", "approvedDate": "2019-03-11", "status": "approved", - "comment": "not auto-allowlist because: No measure of stars / forks; approved by GB exception 2019-03-11" + "comment": "not auto-allowlist because: No measure of stars / forks; approved by GB exception 2019-03-11", + "project": "Oopentelemetry", + "scope": "No scope restrictions" }, { "id": "exc-2019-03-11-087", @@ -4349,7 +4794,9 @@ "license": "BSD-3-Clause", "approvedDate": "2019-03-11", "status": "approved", - "comment": "contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11" + "comment": "contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11", + "project": "All CNCF Projects", + "scope": "No scope restrictions" }, { "id": "exc-2019-03-11-088", @@ -4357,7 +4804,9 @@ "license": "MIT", "approvedDate": "2019-03-11", "status": "approved", - "comment": "contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11" + "comment": "contained directly in repo; not auto-allowlist because: Not isolated; approved by GB exception 2019-03-11", + "project": "All CNCF Projects", + "scope": "No scope restrictions" } ] -} \ No newline at end of file +}