aboutcode-org / aboutcode-org/scancode-toolkit

False positive `gpl-1.0-plus` license reported for `node-forge`

Open
#3,722 2 comments 1 reaction 0 assignees View on GitHub
bug
Dominant language
Python
Stars
2.6k
Forks
791
Avg merge
1d 12h
Merged PRs (30d)
5

Description

### Description

When running the current version of `scancode-toolkit` on https://www.npmjs.com/package/node-forge, it will report a declared license expression in the summary of `(bsd-new AND gpl-2.0 AND gpl-1.0-plus) AND (bsd-new AND gpl-2.0)`. The inclusion of `gpl-1.0-plus` here is wrong.

I believe this is due to a lax text matching in the `gpl-1.0-plus_351.RULE`. The `LICENSE` file of `node-forge` includes a preamble by the package author explaining the licenses:

> ...
> If the GPL suits your project better you are also free to use Forge under
that license.
> …

From the ScanCode result, it appears that it's simply matching on "the GPL" in the above sentence which triggers this license detection:

```json
{
"score": 85,
"start_line": 8,
"end_line": 8,
"matched_length": 2,
"match_coverage": 100,
"matcher": "2-aho",
"license_expression": "gpl-1.0-plus",
"rule_identifier": "gpl-1.0-plus_351.RULE",
"rule_relevance": 85,
"rule_url": "https://github.com/nexB/scancode-toolkit/tree/develop/src/licensedcode/data/rules/gpl-1.0-plus_351.RULE",
"matched_text": "the GPL"
}
```

Perhaps the required matched text needs to be expanded?

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.