aboutcode-org / aboutcode-org/scancode-toolkit

Improve Maven package (POM) declared license detection

オープン
#2,490 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る
license scan new feature package scan package-formats
主要言語
Python
スター
2.6k
フォーク
791
平均マージ
1日 12時間
マージ済み PR(30日)
5

説明

The goal of this ticket is to improve maven package license detection across the board. While scancode-toolkit's maven package detection basics are OK, there a few repeat cases where license information is not properly gathered from maven package metadata (e.g. the POM mostly, though we could also consider gradle definition and a few more). Usually this is because a `declared_license` value found in the pom.xml contains things we did not expect (like a URL) or is vague. There is no encoding standard in Maven to document the license, therefore there are many variations.

Resolving this would likely require a mix of:
- adding new license detection rules to scancode,
- adding new and improved code to handle the specific patterns of license,
- creating new license mappings
- and possibly working with upstream maintainers to improve their license declarations.

The approach should be to start with a complete data set of all package manifests (pom.xml) and find patterns of license issues and establish the baseline, possibly helped by heuristics, classifiers and ML if needed. The end results should be a significant improvement to the license detection quality for the maven packages.

One possibility could be to fetch many POMS with bigquery: https://opensource.googleblog.com/2017/03/operation-rosehub.html
Or just fetch them from maven central

See also https://github.com/nexB/scancode-toolkit/issues/1525

There are also other related ticket for other package types such as:
- https://github.com/nexB/scancode-toolkit/issues/2412 for RPM that has some detailed examples
- https://github.com/nexB/scancode-toolkit/issues/2487 for PyPI
- https://github.com/nexB/scancode-toolkit/issues/2487 for npm

コントリビューションガイド

コントリビューションガイドを開く

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。