apache / apache/logging-log4j2

Small licensing and copyright documentation inconsistencies

Open
#3,644 0 comments 1 reaction 0 assignees View on GitHub
waiting-for-maintainer
Dominant language
Java
Stars
3.6k
Forks
1.7k
Avg merge
21h 30m
Merged PRs (30d)
27

Description

## Description

While chatting with @ppkarwasz I ran a scancode scan of https://repo1.maven.org/maven2/org/apache/logging/log4j/log4j-core/2.24.3/log4j-core-2.24.3-sources.jar using the latest https://github.com/aboutcode-org/scancode.io

Here are some notes:

- Overall the scan clarity in the latest scancode.io looks fine to me:

![Image](https://github.com/user-attachments/assets/6ba18437-66c8-4aae-a059-c7991630a4e1)

There are a few small oddities:

- A sample copyright there is not useful IMHO:
https://github.com/apache/logging-log4j2/blob/7acbc486854cd9b62184883ef9ee5973e1ef1b8b/log4j-core/src/main/java/org/apache/logging/log4j/core/tools/picocli/CommandLine.java#L1508
- the META-INF/DEPENDENCIES file comes with good intentions, but is not useful and eventually misleading as not all these deps may be installed. I would advise against including such data that is likely wrong. (and will be detected by ScanCode but will lead to busy work for reviewing this)
- if you intend for your NOTICE file to include all copyrights, it is incomplete as it is missing https://github.com/apache/logging-log4j2/blob/7acbc486854cd9b62184883ef9ee5973e1ef1b8b/log4j-core/src/main/java/org/apache/logging/log4j/core/util/CronExpression.java#L21
- this license header may be not the original one https://github.com/apache/logging-log4j2/blob/7acbc486854cd9b62184883ef9ee5973e1ef1b8b/log4j-core/src/main/java/org/apache/logging/log4j/core/util/CronExpression.java ... back in ~ 2015, this was likely like this https://github.com/quartz-scheduler/quartz/blob/40b70e3ab49ecc0b53f4d719e6e81392469fd5f6/quartz-core/src/main/java/org/quartz/CronExpression.java ... I would likely restore the original one. And same ... if you really intend your NOTICE to be comprehensive, this is missing there.
- Your NOTICE file dates are likely outdated. I would remove dates or remove the NOTICE
- The author and copyright info from Tim Fennel was stripped from its original at https://github.com/apache/logging-log4j2/blob/3e6bb87f728a9da48d33cecf9dd02dd09bc1a330/log4j2-core/src/main/java/org/apache/logging/log4j/core/config/plugins/ResolverUtil.java and the license notice changed. I would restore it.

Contributor guide

No contributing guide indexed for this repository

Research direction

Review the referenced CommandLine.java, CronExpression.java, and ResolverUtil.java files together with META-INF/DEPENDENCIES and NOTICE. Compare the current source and notices with the linked historical versions, then verify the resulting licensing and copyright information against a ScanCode scan. Done means the inconsistencies identified in the issue are resolved or explicitly clarified.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
documentation
Issue type
Documentation
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.