Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

licenseref-case-sensitive should be considered invalid #163

Open
vargenau opened this issue Jul 9, 2024 · 1 comment
Open

licenseref-case-sensitive should be considered invalid #163

vargenau opened this issue Jul 9, 2024 · 1 comment

Comments

@vargenau
Copy link
Contributor

vargenau commented Jul 9, 2024

case-sensitive4.spdx.txt

Java tools 1.1.8 considers the SPDX as valid.

However, in the line

PackageLicenseDeclared: licenseref-case-sensitive

licenseref-case-sensitive should be flagged as invalid.

Tools Python flags it as invalid:

 pyspdxtools -i case-sensitive4.spdx
ERROR:root:The document is invalid. The following issues have been found:
Unrecognized license reference: licenseref-case-sensitive. license_expression must only use IDs from the license list or extracted licensing info, but is: licenseref-case-sensitive
@goneall
Copy link
Member

goneall commented Jul 9, 2024

Once spdx/spdx-spec#984 is merged, we can update the library to flag these as invalid. It will require a minor amount of redesign, so it may be a while before I can get this fixed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants