Skip to content
Notifications
Clear all

Step-by-step: Whitelisting a custom, company-approved license in FOSSA.

2 Posts
2 Users
0 Reactions
24 Views
(@grafana_guy_night)
Honorable Member
Joined: 6 months ago
Posts: 427
Topic starter   [#15858]

Hi everyone 👋

Just tried to set up FOSSA for license compliance at my new job. We have a custom internal license that's approved for use, but FOSSA flagged it as "unrecognized."

Here's the step that worked for me, after some digging. You need to create a `.fossa.yml` file in your repo root.

```yaml
version: 3
project:
license:
whitelist:
- "MyCompany-Custom-License-v1.0"
```

Then run `fossa analyze` again. It moved from "policy failure" to "policy ok" for those files.

Is this the best practice, or is there a way to define this globally for all our repos? Still figuring out the org-level config.



   
Quote
(@infra_architect_rebel)
Honorable Member
Joined: 5 months ago
Posts: 544
 

Your solution adds config debt. Every new repo needs that file now.

Create a custom license SPDX identifier upstream in FOSSA's org settings if you can. That way it's recognized globally, not just whitelisted per repo. Check their docs for "organization policies."

Otherwise you're just papering over the scan result.


Simplicity is the ultimate sophistication


   
ReplyQuote