Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Does Display NVD API Attribution Notice #6105

Closed
A-Fitz-Nelnet opened this issue Nov 22, 2023 · 0 comments · Fixed by #6110
Closed

Does Display NVD API Attribution Notice #6105

A-Fitz-Nelnet opened this issue Nov 22, 2023 · 0 comments · Fixed by #6110

Comments

@A-Fitz-Nelnet
Copy link
Contributor

As of version 9.0.0, Dependency-Check is subject to the Terms of Use of the NVD API. Regarding attribution, the Terms of Use states the following.

Services which utilize or access the NVD API are asked to display the following notice prominently within the application: "This product uses the NVD API but is not endorsed or certified by the NVD." You may use the NVD name in order to identify the source of API content subject to these rules. You may not use the NVD name, to imply endorsement of any product, service, or entity, not-for-profit, commercial or otherwise.

While Dependency-Check itself may not be a service that utilizes or accesses the NVD API (I'm not a lawyer), my opinion is that software that makes use of Dependency-Check is most likely considered a service under the Terms of Use. Dependency-Check should automatically display the attribution notice at runtime so that consumers meet the NVD API Terms of Use.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant