Skip to content

LGPL false positive (should be GPL) #4946

@armijnhemel

Description

@armijnhemel

Description

https://github.com/rpm-software-management/rpm/blob/master/scripts/vpkg-provides.sh#L7

has a clear GPL license text, but is recognized as LGPL with exception:

    {
      "path": "rpm/scripts/vpkg-provides.sh",
      "type": "file",
      "detected_license_expression": null,
      "detected_license_expression_spdx": null,
      "license_detections": [],
      "license_clues": [
        {
          "license_expression": "lgpl-2.0-plus WITH ocaml-lgpl-linking-exception",
          "license_expression_spdx": "LGPL-2.0-or-later WITH OCaml-LGPL-linking-exception",
          "from_file": "rpm/scripts/vpkg-provides.sh",
          "start_line": 7,
          "end_line": 7,
          "matcher": "3-seq",
          "score": 46.04,
          "matched_length": 13,
          "match_coverage": 54.17,
          "rule_relevance": 85,
          "rule_identifier": "lgpl-2.0-plus_with_ocaml-lgpl-linking-exception_1.RULE",
          "rule_url": "https://github.com/nexB/scancode-toolkit/tree/develop/src/licensedcode/data/rules/lgpl-2.0-plus_with_ocaml-lgpl-linking-exception_1.RULE"
        }
      ],
      "percentage_of_license_text": 0.88,
      "scan_errors": []
    },

I would suggest tightening the rule and adding some required phrases.

Metadata

Metadata

Labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions