SQ12401
Detected presence of license families that were marked to issue a warning.
priority | CI/CD status | severity | effort | SAFE level | SAFE assessment |
---|---|---|---|---|---|
pass | medium | high | None | licenses: warning Reason: restricted license inclusions |
About the issueโ
Software license is a legal instrument that governs the use and distribution of software source code and its binary representation. Software publishers have the freedom to choose any commonly used or purposefully written license to publish their work under. Software licenses are categorized into license families, or license groups, that impose a similar set of restrictions on software use. While some license families are universally accepted, as they are permissive, others may be intentionally declared as undesirable through the organization policy. This issue is reported for components or their dependencies with license families that were explicitly marked to issue a warning.
How to resolve the issueโ
- Confirm that the software package references a component or a dependency with an unwanted license family.
- Consider replacing the software component with an alternative that offers a license compatible with organization policy.
Incidence statisticsโ
ReversingLabs periodically collects and analyzes the contents of popular software package repositories for threat research purposes. Analysis results are used to calculate incidence statistics for issues (policy violations) that Spectra Assure can detect in software packages.
This section is updated when new data becomes available.
Total amount of packages analyzed
- RubyGems: 183K
- Nuget: 644K
- PyPi: 628K
- NPM: 3.72M