aboutcode-org / aboutcode-org/scancode-toolkit

False positive: LGPL-2.1 file detected as "LGPL-3.0-only AND GPL-1.0-or-later"

Open
#4,992 8 comments 0 reactions 0 assignees View on GitHub
bug
Dominant language
Python
Stars
2.6k
Forks
791
Avg merge
1d 12h
Merged PRs (30d)
5

Description

### Description

Scanning `src/yp_order.c` from `libnsl` v2.0.1 reports `LGPL-3.0-only AND GPL-1.0-or-later`.
and "identifier": "lgpl_3_0_and_gpl_1_0_plus-d1207106-f72f-146f-6eb1-6008c11de4ee",

The file header states that the file is under GNU Lesser General Public License in version 2.1

Source file:
https://github.com/thkukuk/libnsl/blob/v2.0.1/src/yp_order.c

Expected license detection: `LGPL-2.1-only`

Actual license detection: `LGPL-3.0-only AND GPL-1.0-or-later`

This appears to be a false positive caused by the license text mentioning "GNU Lesser General Public License" and later "GNU General Public License" in the warranty/copy notice text, even though the version stated in the header is LGPL version 2.1.

### How To Reproduce

```bash
wget https://github.com/thkukuk/libnsl/archive/refs/tags/v2.0.1.zip
unzip v2.0.1.zip
scancode --license --json-pp result.json libnsl-2.0.1/src/yp_order.c
```

### System configuration

OS: macOS 26.3.1 (x86_64)
ScanCode Toolkit version: 32.5.0
Installation method: pip

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.