aboutcode-org / aboutcode-org/scancode-toolkit

False positive `gpl-1.0-plus` license reported for `node-forge`

Đang mở
#3,722 2 bình luận 1 reaction 0 người được giao Xem trên GitHub
bug
Ngôn ngữ chính
Python
Star
2.6k
Fork
791
Merge trung bình
1 ngày 12 giờ
Pull request đã merge (30 ngày)
5

Mô tả

### Description

When running the current version of `scancode-toolkit` on https://www.npmjs.com/package/node-forge, it will report a declared license expression in the summary of `(bsd-new AND gpl-2.0 AND gpl-1.0-plus) AND (bsd-new AND gpl-2.0)`. The inclusion of `gpl-1.0-plus` here is wrong.

I believe this is due to a lax text matching in the `gpl-1.0-plus_351.RULE`. The `LICENSE` file of `node-forge` includes a preamble by the package author explaining the licenses:

> ...
> If the GPL suits your project better you are also free to use Forge under
that license.
> …

From the ScanCode result, it appears that it's simply matching on "the GPL" in the above sentence which triggers this license detection:

```json
{
"score": 85,
"start_line": 8,
"end_line": 8,
"matched_length": 2,
"match_coverage": 100,
"matcher": "2-aho",
"license_expression": "gpl-1.0-plus",
"rule_identifier": "gpl-1.0-plus_351.RULE",
"rule_relevance": 85,
"rule_url": "https://github.com/nexB/scancode-toolkit/tree/develop/src/licensedcode/data/rules/gpl-1.0-plus_351.RULE",
"matched_text": "the GPL"
}
```

Perhaps the required matched text needs to be expanded?

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Đánh giá

Issue này chưa được đánh giá.

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.