aboutcode-org / aboutcode-org/scancode-toolkit

Debian copyright files license declaration inconsistency

Offen
#2,568 0 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
license scan package scan package-formats
Vorherrschende Sprache
Python
Sterne
2.6k
Forks
791
Ø Merge
1 T. 12 Std.
Gemergte PRs (30 T.)
5

Beschreibung

Often debian copyright files are not updated and has inconsistencies where the license declared in the copyright file is different from the license present in the files itself.

This creates wrong licensing information when reporting the license based on parsing the debian copyright file only, and scanning the files would be the only way where correct license is detected.

An example (also #2555 ):

For the debian copyright file for `util-linux` package:

https://metadata.ftp-master.debian.org/changelogs//main/u/util-linux/util-linux_2.36.1-7_copyright

1. The copyright file has a License paragraph with `License: BSD-2-clause` at line 402,
with a license paragraph which is not the license text for `BSD-2-clause`
(https://spdx.org/licenses/BSD-2-Clause.html), but only the 2 clauses
(mentioning the disclaimer) without the disclaimer.

2. The files refer to the license `License: BSD-2-clause` in the Files Paragraph, are:
- `text-utils/pg.c`
- `login-utils/last-deprecated.c`
- `login-utils/login.c`

But, they have different licenses in them, which is not consistent to what is reported
in the copyright file.

The license text in the file `text-utils/pg.c` is BSD-3-clause.

The license text in the file `login-utils/login.c` is https://scancode-licensedb.aboutcode.org/bsla.html.

The file `login-utils/last-deprecated.c` is not present anywhere, and the `login-utils/last.c`
has a `gpl-2.0-plus` license text.

There are also other bugs reported for this package with inconsistencies: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=987944.

Beitragsleitfaden

Beitragsleitfaden öffnen

Bewertung

Dieses Issue wurde noch nicht bewertet.

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.