Working with SW licenses is tricky. E.g., This is an MIT license that has added one additional word, "NOT". That makes it a non-MIT license (although GH thinks something else). Makes it non-free, non-foss. And it is tough to spot such subtle change. https://github.com/jamietsadler/itx_nabla/blob/1ff180dfd80c50a063c398866bcd42196be96e58/LICENSE#L3 #SBOM #license
=> More informations about this toot | More toots from mirek@rodina-sucha.cz
@mirek interesting way of crafting a new license. Do trivy and/or askalono detect this as a non-MIT license or do they also get tricked?
=> More informations about this toot | More toots from fale@fale.io
@fale @mirek
$ askalono identify ~/tmp/badLICENSE
License: MIT (original text)
Score: 0.991
=> More informations about this toot | More toots from hroncok@floss.social
@hroncok @fale @mirek yeah the scoring algorithm in askalono is way off sometimes ... with new SPDX license data, it also identifies Apache-2.0 as "Pixar" (which is why I didn't update the embedded data in a while 😐)
=> More informations about this toot | More toots from decathorpe@mastodon.social
@mirek also looks like that project might be breaking the MIT licence of the original cookie cutter template there?
=> More informations about this toot | More toots from bkhl@social.sdfeu.org This content has been proxied by September (ba2dc).Proxy Information
text/gemini