aboutcode-org / aboutcode-org/scancode-toolkit

False positive `gpl-1.0-plus` license reported for `node-forge`

Aperta
#3,722 2 commenti 1 reazione 0 assegnatari Vedi su GitHub
bug
Lingua principale
Python
Stelle
2.6k
Fork
791
Merge medio
1g 12h
PR unite (30g)
5

Descrizione

### Description

When running the current version of `scancode-toolkit` on https://www.npmjs.com/package/node-forge, it will report a declared license expression in the summary of `(bsd-new AND gpl-2.0 AND gpl-1.0-plus) AND (bsd-new AND gpl-2.0)`. The inclusion of `gpl-1.0-plus` here is wrong.

I believe this is due to a lax text matching in the `gpl-1.0-plus_351.RULE`. The `LICENSE` file of `node-forge` includes a preamble by the package author explaining the licenses:

> ...
> If the GPL suits your project better you are also free to use Forge under
that license.
> …

From the ScanCode result, it appears that it's simply matching on "the GPL" in the above sentence which triggers this license detection:

```json
{
"score": 85,
"start_line": 8,
"end_line": 8,
"matched_length": 2,
"match_coverage": 100,
"matcher": "2-aho",
"license_expression": "gpl-1.0-plus",
"rule_identifier": "gpl-1.0-plus_351.RULE",
"rule_relevance": 85,
"rule_url": "https://github.com/nexB/scancode-toolkit/tree/develop/src/licensedcode/data/rules/gpl-1.0-plus_351.RULE",
"matched_text": "the GPL"
}
```

Perhaps the required matched text needs to be expanded?

Guida per i contributori

Apri la guida per i contributori

Valutazione

Questa issue non è ancora stata valutata.

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.