aboutcode-org / aboutcode-org/scancode-toolkit

Override license detection by checksum

Offen
#1,281 6 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
enhancement license scan policy
Vorherrschende Sprache
Python
Sterne
2.6k
Forks
791
Ø Merge
1 T. 12 Std.
Gemergte PRs (30 T.)
5

Beschreibung

While scanning some repositories, notably SignalR, we routinely come across files identified with an unknown license. Typically, this is because the file both mentions a license, and makes a reference to an external license file, where the latter is then matched as unknown. See for instance `unknown_19.RULE` for a popular one in SignalR.

In conjunction with defining a policy with `--license-policy`, this is not ideal: you hardly want to claim neither yay nor nay about unknown licenses, without looking at the files in question individually.

What I've ended up doing is that I adapted our wrapper around ScanCode with a post-process step:

1. For any file with an `unknown` license match, check in `whitelist.txt`, which for each line contains a sha1:license tuple.
2. If the file's sha1 matches a sha1 in the whitelist, override ScanCodes unknown with the identified license.
3. Any files still matched as `unknown`, output this as part of the report in the same format for manual identification and addition to `whitelist.txt`.

This could probably be improved quite a bit if done in ScanCode, but it would move ScanCode further in the direction of being a compliance toolkit, rather than a scanner, so it might be that it wouldn't fit the roadmap.

Beitragsleitfaden

Beitragsleitfaden öffnen

Bewertung

Dieses Issue wurde noch nicht bewertet.

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.