fix(spdx): Use the official SPDX license list instead of the ScanCode license DB for license texts - #12184
fix(spdx): Use the official SPDX license list instead of the ScanCode license DB for license texts#12184tsteenbe wants to merge 2 commits into
Conversation
fd7cabd to
262f2bc
Compare
Use the official SPDX license list instead of the ScanCode license DB. This avoids issues in the ScanCode data, such as: 1. copyright variables in license texts [2] 2. missing 3rd clause in [3] 3. use of non-standard texts [4] vs [5]. [1]: https://spdx.org/licenses. [2]: https://github.com/oss-review-toolkit/ort/blob/main/utils/spdx/src/main/resources/licenses/AAL#L8 [3]: https://github.com/oss-review-toolkit/ort/blob/main/utils/spdx/src/main/resources/licenses/BSD-4-Clause-UC#L13 [4]: https://scancode-licensedb.aboutcode.org/bsd-new.yml [5]: https://github.com/spdx/license-list-data/blob/main/text/BSD-3-Clause.txt Signed-off-by: Thomas Steenbergen <opensource@steenbe.nl>
Regenerate license list to use license texts from spdx.org
instead of scancode-licensedb.aboutcode.org.
This was done by running
./gradlew --no-configuration-cache generateSpdxEnums
Signed-off-by: Thomas Steenbergen <opensource@steenbe.nl>
262f2bc to
60618a7
Compare
|
Still running into issue regenerating Oppossum test assests, not sure what I am doing wrong but runs forever... |
| } | ||
|
|
||
| /** | ||
| * Wrap [line] at whitespace boundaries so no resulting line exceeds [maxLineLength] characters. A single word longer than |
sschuberth
left a comment
There was a problem hiding this comment.
I believe this needs further discussion.
| fun getLicenseUrl(info: LicenseInfo): URI? | ||
| } | ||
| // The SPDX license list version, fetched lazily so it is only queried when a generation task runs. | ||
| val spdxLicenseListVersion: String by lazy { |
There was a problem hiding this comment.
This changes the logic back to before b282327 by always fetching the latest / current version, instead of being able to specify the version to use (e.g. when deliberately sticking to an older version because a newer version has issues) via the spdxLicenseListVersion property in gradle.properties, which is now unused.
| obligated to do so. If you do not wish to provide this exception without | ||
| modification, you must delete this exception statement from your version and | ||
| license this file solely under the GPL without exception. | ||
| This Program is free software; you can redistribute it and/or modify it under the terms of the GNU General Public |
There was a problem hiding this comment.
To me, this is not really a "fix" commit as it was a deliberate decision from long ago (see b1e4387) to not use license text from SPDX due to miscellaneous formatting issues, and placeholders being present. While there might be some text where SPDX provides better texts, in the past for the majority of licenses using the ScanCode LicenseDB texts was the better choice.
So I believe we need to discuss this change with the core team / TSC.
Actually, I was wondering whether we still need to embed license texts at all. Ideally, user could just configure the LicenseFactProvider of their choice to retrieve texts on the fly at runtime only.
There was a problem hiding this comment.
Another option is to bundle both, scancode and SPDX license list texts.
This way the user can easily control the order in config.yml and place his preference.
Fetching license texts on the fly from some outside ORT location might be a source of flakyness which may not always be desired.
There was a problem hiding this comment.
might be a source of flakyness which may not always be desired.
Could be, but I believe we'd be able to reduce any potential impact by proper caching.
Bundling the resources has the disadvantage that providing a newer version of the data also requires an ORT release.
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #12184 +/- ##
=========================================
Coverage 58.66% 58.66%
Complexity 1835 1835
=========================================
Files 361 361
Lines 13603 13603
Branches 1408 1408
=========================================
Hits 7980 7980
Misses 5117 5117
Partials 506 506
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
Scancode license DB has several issues that were flagged by Lisa Käde (legal counsel) , a colleague of Till Jaeger, see for details the first commit.