Skip to content

Use manifest declarations in repository license results #60

Description

@andrew

Users coming from Licensee or ScanCode will expect a repository containing only a package manifest with a declared license to produce a useful license result. Licensee enables package detection in its CLI and includes the package matcher in the project licenses. ScanCode keeps the package declaration separate from file-level detections, then uses it in package and repository summaries.

Our manifest parser already extracts raw license values and license-file references, and ScanReport.Declared exposes normalized expressions in JSON. Those declarations do not affect Expressions, human output, summary counts, or reportExitCode. Common values such as this one can still appear as detected expressions because the ScanCode rule corpus independently matches the same bytes:

{
  "name": "example",
  "license": "MIT"
}

That makes manifest-only behavior depend on whether the text corpus happens to contain a matching metadata rule. It also leaves conflicts unresolved. For example, a podspec containing s.license = "BSD" currently produces BSD-2-Clause in declared and BSD-3-Clause in expressions. A Cabal declaration of GPL-3 produces GPL-3.0-or-later in declared, while file matching produces GPL-3.0-only plus an unknown license reference.

Use parsed manifest declarations as package-scoped license evidence in repository results. Keep their source and raw value distinct from license-text matches, include normalized declarations in human output and result status, and report whether declared and detected evidence agrees or conflicts. When a manifest names a license file, associate that reference with detections from the file when it is present.

This was reproduced on current main at b515d70 (v0.8.0-1-gb515d70). The existing declared support was added in #17.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions