Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

SCTK detects gpl-1.0-plus with insufficient evidence #3914

Open
DennisClark opened this issue Sep 10, 2024 · 1 comment
Open

SCTK detects gpl-1.0-plus with insufficient evidence #3914

DennisClark opened this issue Sep 10, 2024 · 1 comment
Assignees
Labels

Comments

@DennisClark
Copy link
Member

In a recent scan of the Package available at https://github.com/facebook/sapling/archive/refs/tags/0.2.20240718-145624+f4e9df48.tar.gz multiple detections of gpl-1.0-plus were reported with insufficient evidence for that. Here is an example as presented in DejaCode:

sapling-0.2.20240718-145624-f4e9df48/eden/scm/contrib/chg/chg.c
Detected: gpl-1.0-plus

 * This software may be used and distributed according to the terms of the
 * GNU General Public License version 2 or any later version.

Detected: gpl-2.0-plus

 * GNU General Public License version 2 or any later version.

The scan results also report a Declared license of gpl-1.0-plus AND gpl-2.0-plus AND mit for which I am unable to find any supporting evidence of anything other than gpl-2.0-plus.

I continue to be of the opinion, btw, that SCTK over-reports gpl-1.0-plus whenever the version of a reference to the GPL license is not entirely clear, and that gpl-1.0-plus only contributes distracting noise. The default should be gpl-2.0-plus. But that is not the main issue here, which is that the text clearly indicates version 2 or any later version.

sapling-0.2.20240718-145624-f4e9df48.tar.gz_scan.zip

@AyanSinhaMahapatra
Copy link
Member

Thanks for the report @DennisClark , I will verify that this (and all other open issues like this) are automatically resolved by #3254

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

3 participants