aboutcode-org / aboutcode-org/scancode-toolkit

Use full medata of PyPI packages for license detection

Đang mở
#3,919 0 bình luận 0 reaction 0 người được giao Xem trên GitHub
Ngôn ngữ chính
Python
Star
2.6k
Fork
791
Merge trung bình
1 ngày 12 giờ
Pull request đã merge (30 ngày)
5

Mô tả

For instance https://files.pythonhosted.org/packages/c9/5e/dc6acaf46d78979d6b03458b7a1618a68e152a6776fce95daac5e0f0301b/psycopg2-2.9.9.tar.gz has an ambiguous license in its manifest, but it has a proper license file in it PKG-INFO. We should report the correct referenced license:
Extracted license statement is reported as lgpl-2.0-plus

```
license: LGPL with exceptions
classifiers:
- 'License :: OSI Approved :: GNU Library or Lesser General Public License (LGPL)'
```
The LICENSE file referenced in the PKG-INFO has this instead `lgpl-3.0-plus WITH openssl-exception-lgpl-3.0-plus AND zlib`

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Đánh giá

Issue này chưa được đánh giá.

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.