NVIDIA / NVIDIA/cuda-python

[BUG]: `check_spdx.py` can miss stale copyright years outside staged-file workflows

Open
#2,273 2 comments 1 reaction 1 assignee View on GitHub

@juenglin is already working on this.

Since Jul 16, 2026.

P1
Dominant language
Cython
Stars
3.4k
Forks
329
Avg merge
1d 23h
Merged PRs (30d)
116

Description

toolshed/check_spdx.py currently updates stale copyright years only when a file has a staged diff:

def is_staged(filepath):
    process = subprocess.run(
        ["git", "diff", "--staged", "--", filepath],
        capture_output=True,
        text=True,
    )
    return process.stdout.strip() != ""

and:

if not is_staged(filepath) or int(end_year) >= int(CURRENT_YEAR):
    return True, blob

This means the hook behaves differently depending on how it is invoked.

In the normal local git commit path, a modified file is staged when pre-commit runs, so check_spdx.py --fix can update a stale year such as 2025 to 2025-2026.

However, if the same file is already committed and then checked by pre-commit run --all-files, the file is no longer staged. In that mode, check_spdx.py accepts the stale year even though the file may have been modified in 2026. CI-style all-files validation has the same blind spot.

Concrete example of the blind spot:

  1. Start with a file containing:

    SPDX-FileCopyrightText: Copyright (c) 2025 NVIDIA CORPORATION & AFFILIATES. All rights reserved.
    
  2. Modify that file in 2026.

  3. Create a commit without first running pre-commit.

  4. Run:

    pre-commit run --all-files
    

Desired result:

The check should fail, or --fix should update the modified file to include the current year.

Actual result:

The check can pass because the file has no staged diff at the time check_spdx.py runs.

This makes the copyright-year rule non-deterministic: it may or may not be enforced in typical local workflows, and is not enforced in common validation workflows.

Possible fix directions:

  • Separate "validate SPDX syntax/license fields" from "update years for changed files".
  • Add an explicit mode or option for year enforcement, for example:
    • staged files, for local pre-commit convenience;
    • files changed against a base ref, for CI/PR validation;
    • all files, only if intentionally desired.
  • In CI, prefer checking changed files against the PR base or merge base instead of relying on git diff --staged.
  • Make the hook fail in validation mode when a changed file has an outdated copyright year, instead of silently accepting it because it is not staged.

The important part is that "was this file changed in the commit/PR being validated?" should not be inferred solely from the current staged index state.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.