aboutcode-org / aboutcode-org/scancode-toolkit

Improve license detection for wrong SPDX license identifiers

Open
#3,912 3 comments 0 reactions 1 assignee Claimed by @AyanSinhaMahapatra View on GitHub
improve-license-detection license scan
Dominant language
Python
Stars
2.6k
Forks
791
Avg merge
1d 12h
Merged PRs (30d)
5

Description

Consider the following text:
```
SPDX-License-Identifier: (GPL-2.0+ OR BSD)
```

Here `BSD` is not a valid license expression and even adding a rule is insufficient because the `SPDX-License-Identifier` based detection was moved before the hash license detection.

We should either:
1. do the hash license detection first so we can catch these with rules, and then do the SPDX identifier based detection
2. if we get unknown-spdx we consider license detection with rules
3. Also optionally consider license detection with required phrase rules if nothing works (would lose license expression info for this potentially)?

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.