aboutcode-org / aboutcode-org/scancode-toolkit

ScanCode conflates `gpl-2.0` with `gpl-2.0-plus` in `license_detections`

Open
#3,713 0 comments 0 reactions 0 assignees View on GitHub
bug
Dominant language
Python
Stars
2.6k
Forks
791
Avg merge
1d 12h
Merged PRs (30d)
5

Description

### Description

To my understanding, the `license_expression` field in the JSON output is supposed to contain all distinct licenses listed under `reference_matches`. However, in my case there are

"reference_matches": [
// ...
"license_expression": "public-domain AND gpl-2.0-plus AND gpl-3.0-plus",
"license_expression": "lgpl-2.1 AND gpl-2.0 AND gpl-3.0",

but

"license_detections": [
// ...
"license_expression": "public-domain AND lgpl-2.1-plus AND gpl-2.0-plus AND (public-domain AND gpl-2.0-plus AND gpl-3.0-plus) AND (other-permissive AND other-copyleft) AND public-domain-disclaimer AND lgpl-2.1",

So the `gpl-2.0` and `gpl-3.0` license keys are missing. My guess it that they somehow get conflated into the also existing `gpl-2.0-plus` and `gpl-3.0-plus` license keys.

### How To Reproduce

Using ScanCode 32.1.0, run a scan on the files mentioned at https://github.com/nexB/scancode-toolkit/issues/3648.

### System configuration

* What OS are you running on? Fedora Linux 30
* What version of scancode-toolkit was used to generate the scan file? 32.1.0
* What installation method was used to install/run scancode? pip

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.