aboutcode-org / aboutcode-org/scancode-licensedb

CryptoSwift license incorrectly identified as Zlib

未關閉
#61 1 則留言 1 個 reaction 已指派 2 人 已被 @AyanSinhaMahapatra 認領 在 GitHub 檢視
主要語言
Makefile
星號
67
分支
15
PR 合併指標
30 天內沒有已合併 PR

描述

# CryptoSwift license incorrectly identified as Zlib

The CONTRIBUTING and LICENSE files of CryptoSwift are incorrectly
identified as Zlib license.

CryptoSwift: https://github.com/krzyzanowskim/CryptoSwift
* LICENSE file: https://github.com/krzyzanowskim/CryptoSwift/blob/main/LICENSE
* CONTRIBUTING file: https://github.com/krzyzanowskim/CryptoSwift/blob/main/CONTRIBUTING.md

Zlib: https://www.zlib.net/
* license: https://www.zlib.net/zlib_license.html

## Major difference

### Zlib text

```
If you use this software in a product, an acknowledgment in the
product documentation would be appreciated but is not required.
```

### CryptoSwift text

```
If you use this software in a product, an acknowledgment in the product documentation is required.
```

### The difference

Zlib says: `appreciated but is not required`
CryptoSwift: `is required`

This is quite a difference for users when complying with the license terms.

### Additional notes

* The CryptoSwift license needs an identifier

* Unfortunately the LICENSE and CONTRIBUTING files have slightly different texts.

# Reproducing

## CONTRIBUTING file

### Scanning the CONTRIBUTING file

```
mkdir contributing-file
cd contributing-file
curl -LJ https://raw.githubusercontent.com/krzyzanowskim/CryptoSwift/refs/heads/main/CONTRIBUTING.md | grep "^//" > CONTRIBUTING.md
cd ..
scancode -clipe \
--license-text --license-text-diagnostics \
--classify --license-clarity-score --summary \
-n $(cat /proc/cpuinfo | grep processor | wc -l) \
--json-pp contributing-file.json contributing-file
```

### Extracting the detected license

```
$ cat contributing-file.json | jq .files[].detected_license_expression_spdx
null
"Zlib"
```

### LICENSE file

### Scanning the LICENSE file

```
mkdir license-file
cd license-file
curl -LJO https://raw.githubusercontent.com/krzyzanowskim/CryptoSwift/refs/heads/main/LICENSE
cd ..
scancode -clipe \
--license-text --license-text-diagnostics \
--classify --license-clarity-score --summary \
-n $(cat /proc/cpuinfo | grep processor | wc -l) \
--json-pp license-file.json license-file
```

### Extracting the detected license

```
$ cat license-file.json | jq .files[].detected_license_expression_spdx
null
"Zlib"
```

# Versions etc

* scancode-toolkit 32.3.0
* Ubuntu 24.04.1 LTS
* Python 3.12.3

貢獻指南

這個儲存庫沒有索引到貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。