Skip to content

False positive detection on unknown-license-reference_332.RULE #3379

Description

@DennisClark

A recent scan of CHANGELOG.md in package which-2.0.2.tgz returned a detection of unknown-license-reference with a score of 80 on the unknown-license-reference_332.RULE which is based on this rule text: {{License 1.0}}

The problem is that the actual text in the CHANGELOG.md file, starting at line 135, is this:

## v1.0.6

* isc license

## 1.0.5

* Awful typo

Since standard license detection behavior is to ignore punctuation, one can see why this would happen, but it is definitely a false positive detection, although I am afraid I do not have (yet) a good suggestion for an approach to fix this problem. Basically the unknown license should not have been detected and reported at all.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

buglicense-reviewA license detection issue that needs review

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions