Skip to content

Incorrect detection of the tmate license in fastapi #3652

Description

@DennisClark

A recent scan of fastapi-0.109.2.tar.gz from https://github.com/tiangolo/fastapi/archive/refs/tags/0.109.2.tar.gz resulted in the correct detection of declared_license_expression of mit but the other_license_expressions show 7 detections for tmate and since that license is copyleft the license_clarity_score shows conflicting_license_categories as true.

But I don't think that tmate code is actually in this project. The reported tmate detections are simply text indicating that a tmate service, provided by github, can be enabled when building the project. For example:

description: 'Run the build with tmate debugging enabled (https://github.com/marketplace/actions/debugging-with-tmate)'

So I think that there is a false positive detection of tmate resulting in fastapi getting a -20 value for conflicting_license_categories when that is not accurate.

Scan results attached.
fastapi-0.109.2.tar.gz_scan.zip

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions