aboutcode-org / aboutcode-org/scancode-toolkit

False positive detection with apache-1.1_37_1.RULE

Open
#3,366 2 comments 0 reactions 1 assignee Claimed by @AyanSinhaMahapatra View on GitHub
bug license-review
Dominant language
Python
Stars
2.6k
Forks
791
Avg merge
1d 12h
Merged PRs (30d)
5

Description

A recent scan of about.html in project org.osgi.service.cdi-1.0.0.jar detected apache-1.1 with a score of 73.68 using apache-1.1_37_1.RULE. The about.html file is very clearly a declaration of the apache-2.0 license (also detected, correctly). I believe that the problem is probably caused by the lack of requiring specific text in the RULE. Here is the relevant text in apache-1.1_37_1.RULE:

`Apache Software License 1.1 (available at http://www.apache.org/licenses/LICENSE`

I think that the problem could be resolved by requiring a match on `1.1` or perhaps even `Apache Software License 1.1` which would avoid the false positive on the following matched text in the about.html file:

"matched_text":"available at http://www.apache.org/licenses/LICENSE-"

There is nothing about apache-1.1 in the actual matched text.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.