aboutcode-org / aboutcode-org/scancode-toolkit

Missing License/Question : MIT-0 not detected and OR license expression misinterpreted as AND

Offen
#4,574 6 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
bug
Vorherrschende Sprache
Python
Sterne
2.6k
Forks
791
Ø Merge
1 T. 12 Std.
Gemergte PRs (30 T.)
5

Beschreibung

### Description

When scanning [constant_time_eq v0.3.1](https://github.com/cesarb/constant_time_eq/tree/0.3.1), I observed the following issues:

1. **MIT-0 not detected**
- In `Cargo.toml`, the declared license expression is:
```
license = "CC0-1.0 OR MIT-0 OR Apache-2.0"
```
- However, only `CC0-1.0` and `Apache-2.0` are detected.
- `MIT-0` is missing from the scan result.

2. **OR misinterpreted as AND**
- The above license expression (`CC0-1.0 OR MIT-0 OR Apache-2.0`) is reported as `CC0-1.0 AND Apache-2.0`.
- This changes the intended meaning from a license choice (OR) to a license conjunction (AND).

### How To Reproduce

git clone --branch 0.3.1 https://github.com/cesarb/constant_time_eq.git
cd constant_time_eq
scancode -cli --json-pp - > result.json constant_time_eq

### System configuration

OS: macOS 15.6.1 (x86_64)
ScanCode Toolkit version: 32.4.1
Installation method: pip

### Questions

In addition to the bug report, I would like to confirm two points about how license expressions are represented in the scan output:

1. Multiple detections per file
- If files[].license_detections[].matches[].license_expression contains multiple entries for a single file, are they always combined into files[].license_detections[].matches[].detected_license_expression with an AND operator?
- Or can they sometimes be combined differently (e.g., OR)?
2. Difference between fields
What is the exact difference between:
- files[].license_detections[].matches[].detected_license_expression
- files[].license_detections[].matches[].detected_license_expression_spdx
- When should each be used?

Beitragsleitfaden

Beitragsleitfaden öffnen

Bewertung

Dieses Issue wurde noch nicht bewertet.

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.