aboutcode-org / aboutcode-org/dejacode

BUG: LicenseRef should not be used with License Exceptions

未关闭
#318 8 条评论 0 个 reaction 已指派 2 人 已指派给 @hesa 在 GitHub 查看
bug design needed HighPriority integration
主要语言
Python
星标
50
派生
27
平均合并
4 小时 51 分钟
30 天内合并 PR
11

描述

The SPDX team has specified that a non-SPDX-license-list text which is an exception should be identified with a name that starts with `AdditionRef` rather than `LicenseRef`.

So, from the SPDX perspective, this is wrong:
`some-license-key WITH LicenseRef-something-exception`
but this is right:
`some-license-key WITH AdditionRef-something-exception`

There are multiple Active license exceptions in DejaCode with SPDX key starting with "LicenseRef".
Updating them would of course have an impact on the LicenseDB and various ScanCode tools, so such an update is a big deal and would require a fair amount of work and communication/documentation.

I have created a new Query and Report in DejaCode (nexB dataspace) called License Exceptions with "LicenseRef". I am also attaching the .xlsx output from the report to this issue.

The resolution of this conflict requires some discussion.

Note that our current workaround to this problem, which is simply to construct an expression like this using the AND operator

`some-license-key AND LicenseRef-something-exception`

rather than using the operator WITH , gets us through the SPDX validator, but is not really a good long-term sustainable solution, since it avoids compliance with the latest SPDX standard.

贡献指南

打开贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。