aboutcode-org / aboutcode-org/scancode-toolkit

Improve PyPI package declared license detection

未關閉
#2,487 0 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
improve-license-detection license scan new feature package scan package-formats
主要語言
Python
星號
2.6k
分支
791
平均合併
1 天 12 小時
30 天內合併 PR
5

描述

The goal of this ticket is to improve PyPI package license detection across the board. While scancode-toolkit's PyPI package detection is pretty good, there a few repeat cases where license information is not properly gathered from PyPI package metadata. Usually this is because a `declared_license` value contains things we did not expect (like a URL) or is improperly formed.

Resolving this would likely require a mix of:
- adding new license detection rules to scancode,
- adding new and improved code to handle the specific patterns of license,
- creating new license mappings
- and possibly working with upstream maintainers to improve their license declarations.

The approach should be to start with a complete data set of all package manifests and find patterns of license issues and establish the baseline, possibly with classifiers and ML. The end results should be a significant improvement to the license detection quality for the PyPI packages.

This https://github.com/pypa/bandersnatch/ and the PyPI API may help collect a list of all declared licenses.

See also https://www.python.org/dev/peps/pep-0639/ and may be https://github.com/nexB/scancode-toolkit/issues/253 too

There are also other related ticket for other package types such as:
- https://github.com/nexB/scancode-toolkit/issues/2412 for RPM that has some detailed examples

And a project idea: https://github.com/nexB/aboutcode/wiki/Project-Ideas-Improve-PyPI-package-license-detection

貢獻指南

開啟貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。