aboutcode-org / aboutcode-org/scancode-toolkit

False positive detection of warranty-disclaimer AND mit-taylor-variant AND mit-old-style-no-advert

Offen
#3,357 0 Kommentare 0 Reaktionen 1 zugewiesene Person Beansprucht von @AyanSinhaMahapatra Auf GitHub ansehen
bug license-review
Vorherrschende Sprache
Python
Sterne
2.6k
Forks
791
Ø Merge
1 T. 12 Std.
Gemergte PRs (30 T.)
5

Beschreibung

See related issue #3356

A recent scan of the file index.xsb in poi-ooxml-lite-5.2.2.jar returned a detected license expression of
`warranty-disclaimer AND mit-taylor-variant AND mit-old-style-no-advert`
even though the score and match coverage of each detected license was very low (all under 20). The triggered rules included:
warranty-disclaimer_73.RULE
mit-taylor-variant_3.RULE
warranty-disclaimer_31.RULE
mit-old-style-no-advert_25.RULE

None of the matches were sufficient to detect those licenses.
Here is the text from index.xsb

Permission to copy, display and distribute the contents of this document (the
"Specification"), in any medium for any purpose without fee or royalty is
hereby granted, provided that you include the following notice on ALL copies of
the Specification, or portions thereof, that you make:
Copyright (c) Microsoft Corporation. All rights reserved. Permission to copy,
display and distribute this document is available at:
http://msdn.microsoft.com/library/en-us/odcXMLRef/html/odcXMLRefLegalNotice.asp?frame=true.
No right to create modifications or derivatives of this Specification is
granted herein. There is a separate patent license available to parties
interested in implementing software programs that can read and write files that
conform to the Specification. This patent license is available at this
location: http://www.microsoft.com/mscorp/ip/format/xmlpatentlicense.asp.
THE SPECIFICATION IS PROVIDED "AS IS" AND MICROSOFT MAKES NO REPRESENTATIONS OR
WARRANTIES, EXPRESS OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, WARRANTIES OF
MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, NON-INFRINGEMENT, OR TITLE;
THAT THE CONTENTS OF THE SPECIFICATION ARE SUITABLE FOR ANY PURPOSE; NOR THAT
THE IMPLEMENTATION OF SUCH CONTENTS WILL NOT INFRINGE ANY THIRD PARTY PATENTS,
COPYRIGHTS, TRADEMARKS OR OTHER RIGHTS. MICROSOFT WILL NOT BE LIABLE FOR ANY
DIRECT, INDIRECT, SPECIAL, INCIDENTAL OR CONSEQUENTIAL DAMAGES ARISING OUT OF
OR RELATING TO ANY USE OR DISTRIBUTION OF THE SPECIFICATION.
The name and trademarks of Microsoft may NOT be used in any manner, including
advertising or publicity pertaining to the Specification or its contents
without specific, written prior permission. Title to copyright in the
Specification will at all times remain with Microsoft. No other rights are
granted by implication, estoppel or otherwise.

This should probably be a new Microsoft license (again see #3356) but there should also be some refinement of the SCTK code or the rules or both to prevent false positive detection without better matches.

Also refer to https://mvnrepository.com/artifact/org.apache.poi/poi-ooxml-lite/5.2.2

Beitragsleitfaden

Beitragsleitfaden öffnen

Bewertung

Dieses Issue wurde noch nicht bewertet.

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.