Skip to content
This repository was archived by the owner on May 1, 2024. It is now read-only.
Discussion options

You must be logged in to vote

It isn't a requirement that packages published to the registry have a license as such it would seem like overstepping to block publishing based on the license of a package matching the SPDX string in packge.json.

It might be worth surfacing metadata about this on the package landing page... e.g. we use the SPDX string to surface license information, we could also surface if that license data matches the included LICENSE. With that said, this is very error prone and could result in false negatives. I manage a package that is licensed with the spdx string LGPL-3.0-or-later, but a popular tool for checking licenses can't accurately assess the license file and marks my pacakge as a risk becau…

Replies: 2 comments

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Answer selected by MylesBorins
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
CLI
Labels
None yet
3 participants