You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
There are discrepancies between FSF's canonical GPL-1.0 and GPL-2.0 texts and their associated SPDX templates that cause matching to fail in downstream software that performs matching.
Specifically:
The canonical GPL-1.0 text no longer includes a physical address on line 6, and has added a URL in that location instead. Neither of these changes are taken into account in either the GPL-1.0-only or GPL-1.0-or-later SPDX templates.
Similarly, the canonical GPL-2.0 text now has a URL on line 6. While the GPL-2.0-only and GPL-2.0-or-later SPDX templates correctly handle the (now optional) physical address, neither of them handle the (presumably optional) URL that is now included in the canonical text.
Note: if the SPDX project has contacts over at the FSF it may be worth asking them if it might be possible to notify the SPDX project whenever they make changes of any kind to their license texts (even/especially "legally inconsequential" ones). Previous issues (including #2430, #2204, #1995, #1973, #1972) suggest that the FSF are quite liberal about making such changes and thereby inadvertently breaking SPDX license matching randomly.
The text was updated successfully, but these errors were encountered:
The LGPL-3.0-* SPDX templates appear to be aligned with the FSF's canonical LGPL-3.0 text, however. This issue also isn't relevant for the AGPL, since there's only a single version of that published by the FSF (AGPL-3.0).
good catch! And since the copyright notice in this (somewhat rare case) is on the license itself, this is not a situation where for matching purposes it might be ignored as part of the copyright notice.
the good news is that this can easily be accommodated with the alt tag.
+1 to merging the address vs URL change. Perhaps "The GNU Volunteer Coordinators gvc@gnu.org can assist you if you would like to help developing GNU software." would be a decent place to pose your query on notice re breaking changes.
There are discrepancies between FSF's canonical
GPL-1.0
andGPL-2.0
texts and their associated SPDX templates that cause matching to fail in downstream software that performs matching.Specifically:
GPL-1.0
text no longer includes a physical address on line 6, and has added a URL in that location instead. Neither of these changes are taken into account in either theGPL-1.0-only
orGPL-1.0-or-later
SPDX templates.GPL-2.0
text now has a URL on line 6. While theGPL-2.0-only
andGPL-2.0-or-later
SPDX templates correctly handle the (now optional) physical address, neither of them handle the (presumably optional) URL that is now included in the canonical text.Note: if the SPDX project has contacts over at the FSF it may be worth asking them if it might be possible to notify the SPDX project whenever they make changes of any kind to their license texts (even/especially "legally inconsequential" ones). Previous issues (including #2430, #2204, #1995, #1973, #1972) suggest that the FSF are quite liberal about making such changes and thereby inadvertently breaking SPDX license matching randomly.
The text was updated successfully, but these errors were encountered: