Scan Report
Created by ORT, the OSS Review Toolkit, version cc543c9380-dirty on 2023-03-28T03:05:10.522199107Z.

Project

Scanned revision 10edfdaa7740c426a055799ad245c3ee059b1553 of Git repository https://github.com/adoptium/blog.adoptium.net.git

Index

Rule Violation Summary (0 errors, 0 warnings, 2 hints to resolve)

# Rule Package License Message
1 PROJECT_LICENSE_CHECK NPM::blog:1.0.0 DETECTED: LicenseRef-scancode-commercial-license

License LicenseRef-scancode-commercial-license of project 'NPM::blog:1.0.0' is unclassified.

How to fix

Classify LicenseRef-scancode-commercial-license as either approved or restricted.

2 PROJECT_LICENSE_CHECK NPM::blog:1.0.0 DETECTED: NOASSERTION

License NOASSERTION of project 'NPM::blog:1.0.0' is unclassified.

How to fix

Classify NOASSERTION as either approved or restricted.

Issue Summary (1 errors, 0 warnings, 0 hints to resolve)

Issues from excluded components are not shown in this summary.

Packages

# Package Analyzer Issues Scanner Issues
1 NPM::blog:1.0.0 NPM::blog:1.0.0
  • 2023-03-28T03:04:29.230374831Z [ERROR]: NPM - code ERESOLVE
    ERESOLVE could not resolve
    While resolving: radium@0.26.2
    Found: react@18.2.0
    node_modules/react
    react@"18.2.0" from the root project
    peer react@">=16.3" from @fortawesome/react-fontawesome@0.2.0
    node_modules/@fortawesome/react-fontawesome
    @fortawesome/react-fontawesome@"0.2.0" from the root project
    15 more (@gatsbyjs/reach-router, @mdx-js/react, gatsby, ...)
    Could not resolve dependency:
    peer react@"^16.8.0 || ^17.0.0" from radium@0.26.2
    node_modules/radium
    radium@"0.26.2" from the root project
    Conflicting peer dependency: react@17.0.2
    node_modules/react
    peer react@"^16.8.0 || ^17.0.0" from radium@0.26.2
    node_modules/radium
    radium@"0.26.2" from the root project
    Fix the upstream dependency conflict, or retry
    this command with --force, or --legacy-peer-deps
    to accept an incorrect (and potentially broken) dependency resolution.
    See /home/ort/.npm/eresolve-report.txt for a full report.

NPM::blog:1.0.0 (package.json)

VCS Information

Type Git
URL https://github.com/adoptium/blog.adoptium.net.git
Path
Revision 10edfdaa7740c426a055799ad245c3ee059b1553

Packages

# Package Scopes Licenses Analyzer Issues Scanner Issues
1 NPM::blog:1.0.0 Declared Licenses:
Detected Licenses (from VCS):
Apache-2.0 (exemplary link to the first of 2 locations)
EPL-1.0 (link to the location)
EPL-2.0 (link to the location)
LicenseRef-scancode-commercial-license (link to the location)
MIT (exemplary link to the first of 6 locations)
NOASSERTION (exemplary link to the first of 4 locations)
Effective License:
Apache-2.0 AND EPL-1.0 AND EPL-2.0 AND LicenseRef-scancode-commercial-license AND MIT AND NOASSERTION
  • 2023-03-28T03:04:29.230374831Z [ERROR]: NPM - code ERESOLVE
    ERESOLVE could not resolve
    While resolving: radium@0.26.2
    Found: react@18.2.0
    node_modules/react
    react@"18.2.0" from the root project
    peer react@">=16.3" from @fortawesome/react-fontawesome@0.2.0
    node_modules/@fortawesome/react-fontawesome
    @fortawesome/react-fontawesome@"0.2.0" from the root project
    15 more (@gatsbyjs/reach-router, @mdx-js/react, gatsby, ...)
    Could not resolve dependency:
    peer react@"^16.8.0 || ^17.0.0" from radium@0.26.2
    node_modules/radium
    radium@"0.26.2" from the root project
    Conflicting peer dependency: react@17.0.2
    node_modules/react
    peer react@"^16.8.0 || ^17.0.0" from radium@0.26.2
    node_modules/radium
    radium@"0.26.2" from the root project
    Fix the upstream dependency conflict, or retry
    this command with --force, or --legacy-peer-deps
    to accept an incorrect (and potentially broken) dependency resolution.
    See /home/ort/.npm/eresolve-report.txt for a full report.

    Repository Configuration

    
    ---
    excludes:
      paths:
      - pattern: "**/META-INF/DEPENDENCIES"
        reason: "BUILD_TOOL_OF"
        comment: "Licenses contained in this directory reflect content analysed elsewhere."
      - pattern: "**/META-INF/NOTICE*"
        reason: "BUILD_TOOL_OF"
        comment: "Licenses contained in this directory reflect content analysed elsewhere."
      - pattern: "**/*.svg"
        reason: "BUILD_TOOL_OF"
        comment: "SVG files do not contain any license information."
      - pattern: "package-lock.json"
        reason: "BUILD_TOOL_OF"
        comment: "Does not contain any license information."