aboutcode-org / aboutcode-org/scancode-toolkit

Override license detection by checksum

Abierto
#1,281 6 comentarios 0 reacciones 0 asignados Ver en GitHub
enhancement license scan policy
Lenguaje dominante
Python
Estrellas
2.6k
Forks
791
Merge medio
1 d 12 h
PR fusionados (30 d)
5

Descripción

While scanning some repositories, notably SignalR, we routinely come across files identified with an unknown license. Typically, this is because the file both mentions a license, and makes a reference to an external license file, where the latter is then matched as unknown. See for instance `unknown_19.RULE` for a popular one in SignalR.

In conjunction with defining a policy with `--license-policy`, this is not ideal: you hardly want to claim neither yay nor nay about unknown licenses, without looking at the files in question individually.

What I've ended up doing is that I adapted our wrapper around ScanCode with a post-process step:

1. For any file with an `unknown` license match, check in `whitelist.txt`, which for each line contains a sha1:license tuple.
2. If the file's sha1 matches a sha1 in the whitelist, override ScanCodes unknown with the identified license.
3. Any files still matched as `unknown`, output this as part of the report in the same format for manual identification and addition to `whitelist.txt`.

This could probably be improved quite a bit if done in ScanCode, but it would move ScanCode further in the direction of being a compliance toolkit, rather than a scanner, so it might be that it wouldn't fit the roadmap.

Guía de contribución

Abrir la guía de contribución

Evaluación

Este issue todavía no se ha evaluado.

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.