Skip to content

properly handle top-level, key files Licenses vs. other files - [was Scan of eudev-3.2.5.tar.gz returns ambiguous license results] #1290

Description

@DennisClark

A recent scan of eudev-3.2.5.tar.gz using download url https://github.com/gentoo/eudev/archive/v3.2.5.tar.gz returned the following license results:

lgpl-2.1-plus 78
gpl-2.0-plus 34
lgpl-2.0-plus 3
gpl-2.0 2
public-domain 2
cc0-1.0 1
fsf-unlimited 1
lgpl-2.1 1
mit 1

If you were simply to look at the numbers, it seems that the overall project license is lgpl-2.1-plus; however, this package is acutally an excellent example of where providing the Declared License would be extremely helpful. The project has a COPYING license text for GPL 2.0 at the top level, but the file headers are quite mixed (certainly NOT Clearly Defined). Anyway, the applicable license for the whole project is GPL 2.0 and not LGPL 2.1. This is a good case for identifying a declared license at the project level.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions