google / google/osv-scanner

Matching license with exception

Open
#1,923 0 comments 0 reactions 0 assignees View on GitHub
backlog enhancement
Dominant language
Go
Stars
11k
Forks
792
Avg merge
2d 1h
Merged PRs (30d)
48

Description

How, if at all, exceptions in license conditions are matched?

Based on SPDX [license spec](https://spdx.github.io/spdx-spec/v3.0.1/annexes/spdx-license-expressions)

licnes can be specified as Apache-2.0 WITH LLVM-exception

how does list of allowed licences e.g. Apache-2.0

I am currently on osv-scanner version 2.0.2 and this is flagged as not allowed. Any plan to support this?

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.