Hi Kotrappa,

 

In general, if there is a match to an SPDX standard license, it is a best 
practice to use the standard license ID.  If there is any uncertainty if the 
text matches the SPDX standard license, a licenseRef should be generated and 
the found text for the license be included in the extracted license info.

 

I'm not sure if using the extracted license text for an SPDX standard license 
violates the spec since all of the information is present.

 

I only maintain the SPDX tools libraries, not the FOSSOLOGY tools, so I'll pass 
along your comments to Matt Germonprez at UNO.

 

Matt: If you agree with the above, it may make for a good student project to 
match against the standard licenses.  In the SPDX Tools, there is some Java 
code which uses the legal team's matching guidelines to identify matches.  Once 
SPDX 2.0 is released, we I'll update the library to match against license 
headers as well.  If you have a student interested, I can point them in the 
direction of the existing code.

 

Gary

 

From: [email protected] [mailto:[email protected]] 
Sent: Friday, May 30, 2014 5:31 AM
To: [email protected]; [email protected]
Cc: [email protected]; [email protected]
Subject: [SPDX] Standard Licenses like GPL, LGPL, BSD, ISC are shown in 
extracted License Info list.

 

Hello Gary,

 

To understand spdx results, we tried to scan rsync package available in below 
link 

 

http://rsync.samba.org/ - please download  rsync-3.1.1pre2.tar.gz 
<http://rsync.samba.org/ftp/rsync/src-previews/rsync-3.1.1pre2.tar.gz> 

 

we scanned on public fossology+SPDX web server -  
<https://fossologyspdx.ist.unomaha.edu/> https://fossologyspdx.ist.unomaha.edu 
and then generated spdx results for it.

 

The extracted License info  in below link shows standard open source license 
list available in spdx.org, i.e GPL, LGPL, BSD etc are shown in 
extractedLicense info.

 

https://fossologyspdx.ist.unomaha.edu/?mod=spdx_extdLicInfoEdit_list 
<https://fossologyspdx.ist.unomaha.edu/?mod=spdx_extdLicInfoEdit_list&spdxId=80&packageInfoPk=80>
 &spdxId=80&packageInfoPk=80

 

 

But I think as per spdx spec 1.2, extracted license info should represent 
licenses which are NOT in spdx license list.

 

Please let us know if there any mismatch in understanding or tool having issues.

 

 

Regards

Kotrappa.

 

 

 

 

The information contained in this electronic message and any attachments to 
this message are intended for the exclusive use of the addressee(s) and may 
contain proprietary, confidential or privileged information. If you are not the 
intended recipient, you should not disseminate, distribute or copy this e-mail. 
Please notify the sender immediately and destroy all copies of this message and 
any attachments.

WARNING: Computer viruses can be transmitted via email. The recipient should 
check this email and any attachments for the presence of viruses. The company 
accepts no liability for any damage caused by any virus transmitted by this 
email.

www.wipro.com

_______________________________________________
Spdx-tech mailing list
[email protected]
https://lists.spdx.org/mailman/listinfo/spdx-tech

Reply via email to