Users coming from Licensee or ScanCode will expect a repository containing only a package manifest with a declared license to produce a useful license result. Licensee enables package detection in its CLI and includes the package matcher in the project licenses. ScanCode keeps the package declaration separate from file-level detections, then uses it in package and repository summaries.
Our manifest parser already extracts raw license values and license-file references, and ScanReport.Declared exposes normalized expressions in JSON. Those declarations do not affect Expressions, human output, summary counts, or reportExitCode. Common values such as this one can still appear as detected expressions because the ScanCode rule corpus independently matches the same bytes:
{
"name": "example",
"license": "MIT"
}
That makes manifest-only behavior depend on whether the text corpus happens to contain a matching metadata rule. It also leaves conflicts unresolved. For example, a podspec containing s.license = "BSD" currently produces BSD-2-Clause in declared and BSD-3-Clause in expressions. A Cabal declaration of GPL-3 produces GPL-3.0-or-later in declared, while file matching produces GPL-3.0-only plus an unknown license reference.
Use parsed manifest declarations as package-scoped license evidence in repository results. Keep their source and raw value distinct from license-text matches, include normalized declarations in human output and result status, and report whether declared and detected evidence agrees or conflicts. When a manifest names a license file, associate that reference with detections from the file when it is present.
This was reproduced on current main at b515d70 (v0.8.0-1-gb515d70). The existing declared support was added in #17.
Users coming from Licensee or ScanCode will expect a repository containing only a package manifest with a declared license to produce a useful license result. Licensee enables package detection in its CLI and includes the package matcher in the project licenses. ScanCode keeps the package declaration separate from file-level detections, then uses it in package and repository summaries.
Our manifest parser already extracts raw license values and license-file references, and
ScanReport.Declaredexposes normalized expressions in JSON. Those declarations do not affectExpressions, human output, summary counts, orreportExitCode. Common values such as this one can still appear as detected expressions because the ScanCode rule corpus independently matches the same bytes:{ "name": "example", "license": "MIT" }That makes manifest-only behavior depend on whether the text corpus happens to contain a matching metadata rule. It also leaves conflicts unresolved. For example, a podspec containing
s.license = "BSD"currently producesBSD-2-ClauseindeclaredandBSD-3-Clauseinexpressions. A Cabal declaration ofGPL-3producesGPL-3.0-or-laterindeclared, while file matching producesGPL-3.0-onlyplus an unknown license reference.Use parsed manifest declarations as package-scoped license evidence in repository results. Keep their source and raw value distinct from license-text matches, include normalized declarations in human output and result status, and report whether declared and detected evidence agrees or conflicts. When a manifest names a license file, associate that reference with detections from the file when it is present.
This was reproduced on current
mainatb515d70(v0.8.0-1-gb515d70). The existingdeclaredsupport was added in #17.