Skip to content

fix(spdx): Use the official SPDX license list instead of the ScanCode license DB for license texts - #12184

Open
tsteenbe wants to merge 2 commits into
mainfrom
fix-generate-spdx-enums-gradle-task-to-use-spdx-json
Open

tsteenbe wants to merge 2 commits into
mainfrom
fix-generate-spdx-enums-gradle-task-to-use-spdx-json

Conversation

@tsteenbe

@tsteenbe tsteenbe commented Jul 22, 2026 •

Copy link
Copy Markdown
Member

Scancode license DB has several issues that were flagged by Lisa Käde (legal counsel) , a colleague of Till Jaeger, see for details the first commit.

@tsteenbe
tsteenbe requested a review from a team as a code owner July 22, 2026 05:42
@tsteenbe tsteenbe changed the title Fix generate spdx enums gradle task to use spdx json Jul 22, 2026
@tsteenbe
tsteenbe force-pushed the fix-generate-spdx-enums-gradle-task-to-use-spdx-json branch from fd7cabd to 262f2bc Compare July 22, 2026 05:54
tsteenbe added 2 commits July 22, 2026 08:14
Use the official SPDX license list instead of the ScanCode license DB.
This avoids issues in the ScanCode data, such as:
1. copyright variables in license texts [2]
2. missing 3rd clause in [3]
3. use of non-standard texts [4] vs [5].

[1]: https://spdx.org/licenses.
[2]: https://github.com/oss-review-toolkit/ort/blob/main/utils/spdx/src/main/resources/licenses/AAL#L8
[3]: https://github.com/oss-review-toolkit/ort/blob/main/utils/spdx/src/main/resources/licenses/BSD-4-Clause-UC#L13
[4]: https://scancode-licensedb.aboutcode.org/bsd-new.yml
[5]: https://github.com/spdx/license-list-data/blob/main/text/BSD-3-Clause.txt

Signed-off-by: Thomas Steenbergen <opensource@steenbe.nl>
Regenerate license list to use license texts from spdx.org
instead of scancode-licensedb.aboutcode.org.

This was done by running

    ./gradlew --no-configuration-cache generateSpdxEnums

Signed-off-by: Thomas Steenbergen <opensource@steenbe.nl>
@tsteenbe
tsteenbe force-pushed the fix-generate-spdx-enums-gradle-task-to-use-spdx-json branch from 262f2bc to 60618a7 Compare July 22, 2026 06:14
@tsteenbe

Copy link
Copy Markdown
Member Author

Still running into issue regenerating Oppossum test assests, not sure what I am doing wrong but runs forever...

@tsteenbe tsteenbe changed the title fix(spdx): Use the official SPDX license list instead of the ScanCode license DB to obtain license texts for SPDX ids Jul 22, 2026
}

/**
* Wrap [line] at whitespace boundaries so no resulting line exceeds [maxLineLength] characters. A single word longer than

@sschuberth sschuberth left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I believe this needs further discussion.

fun getLicenseUrl(info: LicenseInfo): URI?
}
// The SPDX license list version, fetched lazily so it is only queried when a generation task runs.
val spdxLicenseListVersion: String by lazy {

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This changes the logic back to before b282327 by always fetching the latest / current version, instead of being able to specify the version to use (e.g. when deliberately sticking to an older version because a newer version has issues) via the spdxLicenseListVersion property in gradle.properties, which is now unused.

obligated to do so. If you do not wish to provide this exception without
modification, you must delete this exception statement from your version and
license this file solely under the GPL without exception.
This Program is free software; you can redistribute it and/or modify it under the terms of the GNU General Public

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

To me, this is not really a "fix" commit as it was a deliberate decision from long ago (see b1e4387) to not use license text from SPDX due to miscellaneous formatting issues, and placeholders being present. While there might be some text where SPDX provides better texts, in the past for the majority of licenses using the ScanCode LicenseDB texts was the better choice.

So I believe we need to discuss this change with the core team / TSC.

Actually, I was wondering whether we still need to embed license texts at all. Ideally, user could just configure the LicenseFactProvider of their choice to retrieve texts on the fly at runtime only.

@fviernau fviernau Jul 22, 2026 •

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Another option is to bundle both, scancode and SPDX license list texts.
This way the user can easily control the order in config.yml and place his preference.

Fetching license texts on the fly from some outside ORT location might be a source of flakyness which may not always be desired.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

might be a source of flakyness which may not always be desired.

Could be, but I believe we'd be able to reduce any potential impact by proper caching.

Bundling the resources has the disadvantage that providing a newer version of the data also requires an ORT release.

@codecov

codecov Bot commented Jul 22, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 58.66%. Comparing base (4e7f3a6) to head (60618a7).
⚠️ Report is 378 commits behind head on main.

Additional details and impacted files
@@            Coverage Diff            @@
##               main   #12184   +/-   ##
=========================================
  Coverage     58.66%   58.66%           
  Complexity     1835     1835           
=========================================
  Files           361      361           
  Lines         13603    13603           
  Branches       1408     1408           
=========================================
  Hits           7980     7980           
  Misses         5117     5117           
  Partials        506      506           
Flag Coverage Δ
funTest-external-tools 14.60% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

4 participants