aboutcode-org / aboutcode-org/scancode-toolkit
Improve license detection for wrong SPDX license identifiers
- Dominant language
- Python
- Stars
- 2.6k
- Forks
- 791
- Avg merge
- 1d 12h
- Merged PRs (30d)
- 5
Description
Consider the following text:
```
SPDX-License-Identifier: (GPL-2.0+ OR BSD)
```
Here `BSD` is not a valid license expression and even adding a rule is insufficient because the `SPDX-License-Identifier` based detection was moved before the hash license detection.
We should either:
1. do the hash license detection first so we can catch these with rules, and then do the SPDX identifier based detection
2. if we get unknown-spdx we consider license detection with rules
3. Also optionally consider license detection with required phrase rules if nothing works (would lose license expression info for this potentially)?
Contributor guide
Assessment
This issue has not been assessed yet.