Scan Report
Created by ORT, the OSS Review Toolkit, version cc543c9380-dirty on 2023-04-05T14:35:20.932994521Z.

Project

Scanned revision f2fe4f7c4acaa01cd086dd6a6a758353344a675d of Git repository https://github.com/jakartaee/validation-spec.git

Index

Rule Violation Summary (1 errors, 0 warnings, 2 hints to resolve)

# Rule Package License Message
1 OSADL_PROJECT_LICENSE_COMPATIBILITY Maven:junit:junit:4.12 CONCLUDED: EPL-1.0

The outbound license Apache-2.0 of project 'Maven:org.beanvalidation:spec-examples:1.0-SNAPSHOT' is incompatible with the inbound license EPL-1.0 of its dependency 'Maven:junit:junit:4.12'. Software under a copyleft license such as the EPL-1.0 license normally cannot be redistributed under a non-copyleft license such as the Apache-2.0 license, except if it were explicitly permitted in the licenses.

How to fix

Remove the dependency on 'Maven:junit:junit:4.12' or put 'Maven:org.beanvalidation:spec-examples:1.0-SNAPSHOT' under a different license.

2 PROJECT_LICENSE_CHECK Unmanaged::validation-spec:f2fe4f7c4acaa01cd086dd6a6a758353344a675d DETECTED: LicenseRef-scancode-efsl-1.0

License LicenseRef-scancode-efsl-1.0 of project 'Unmanaged::validation-spec:f2fe4f7c4acaa01cd086dd6a6a758353344a675d' is unclassified.

How to fix

Classify LicenseRef-scancode-efsl-1.0 as either approved or restricted.

3 PROJECT_LICENSE_CHECK Unmanaged::validation-spec:f2fe4f7c4acaa01cd086dd6a6a758353344a675d DETECTED: NOASSERTION

License NOASSERTION of project 'Unmanaged::validation-spec:f2fe4f7c4acaa01cd086dd6a6a758353344a675d' is unclassified.

How to fix

Classify NOASSERTION as either approved or restricted.

Issue Summary (1 errors, 0 warnings, 0 hints to resolve)

Issues from excluded components are not shown in this summary.

Packages

# Package Analyzer Issues Scanner Issues
1 Maven:jakarta.validation:jakarta.validation-api:3.0.0-SNAPSHOT Maven:org.beanvalidation:spec-examples:1.0-SNAPSHOT
  • 2023-04-05T14:34:36.581977102Z [ERROR]: Maven - Could not get package information for dependency 'jakarta.validation:jakarta.validation-api:3.0.0-SNAPSHOT': ProjectBuildingException: Error resolving project artifact: Could not find artifact jakarta.validation:jakarta.validation-api:pom:3.0.0-SNAPSHOT in central (https://repo.maven.apache.org/maven2) for project jakarta.validation:jakarta.validation-api:pom:3.0.0-SNAPSHOT
    Caused by: ArtifactResolutionException: Could not find artifact jakarta.validation:jakarta.validation-api:pom:3.0.0-SNAPSHOT in central (https://repo.maven.apache.org/maven2)
    Caused by: ArtifactNotFoundException: Could not find artifact jakarta.validation:jakarta.validation-api:pom:3.0.0-SNAPSHOT in central (https://repo.maven.apache.org/maven2)

Maven:org.beanvalidation:spec-examples:1.0-SNAPSHOT (spec-examples/pom.xml)

VCS Information

Type Git
URL https://github.com/jakartaee/validation-spec.git
Path spec-examples
Revision f2fe4f7c4acaa01cd086dd6a6a758353344a675d

Packages

# Package Scopes Licenses Analyzer Issues Scanner Issues
1 Maven:org.beanvalidation:spec-examples:1.0-SNAPSHOT Detected Licenses (from VCS):
Apache-2.0 (exemplary link to the first of 100 locations)
Effective License:
      2 Maven:jakarta.validation:jakarta.validation-api:3.0.0-SNAPSHOT
      • test
      • 2023-04-05T14:34:36.581977102Z [ERROR]: Maven - Could not get package information for dependency 'jakarta.validation:jakarta.validation-api:3.0.0-SNAPSHOT': ProjectBuildingException: Error resolving project artifact: Could not find artifact jakarta.validation:jakarta.validation-api:pom:3.0.0-SNAPSHOT in central (https://repo.maven.apache.org/maven2) for project jakarta.validation:jakarta.validation-api:pom:3.0.0-SNAPSHOT
        Caused by: ArtifactResolutionException: Could not find artifact jakarta.validation:jakarta.validation-api:pom:3.0.0-SNAPSHOT in central (https://repo.maven.apache.org/maven2)
        Caused by: ArtifactNotFoundException: Could not find artifact jakarta.validation:jakarta.validation-api:pom:3.0.0-SNAPSHOT in central (https://repo.maven.apache.org/maven2)

        3 Maven:junit:junit:4.12
        • test
        Concluded License:
        Declared Licenses:
        Detected Licenses (from VCS):
        Apache-2.0 (exemplary link to the first of 2 locations)
        EPL-1.0 (exemplary link to the first of 4 locations)
        NOASSERTION (link to the location)
        Effective License:
            4 Maven:org.hamcrest:hamcrest-core:1.3
            • test
            Concluded License:
            Declared Licenses:
            Effective License:

                Unmanaged::validation-spec:f2fe4f7c4acaa01cd086dd6a6a758353344a675d ()

                VCS Information

                Type Git
                URL https://github.com/jakartaee/validation-spec
                Path
                Revision f2fe4f7c4acaa01cd086dd6a6a758353344a675d

                Packages

                # Package Scopes Licenses Analyzer Issues Scanner Issues
                1 Unmanaged::validation-spec:f2fe4f7c4acaa01cd086dd6a6a758353344a675d Detected Licenses (from VCS):
                Apache-2.0 (exemplary link to the first of 146 locations)
                BSD-3-Clause (link to the location)
                EPL-2.0 (link to the location)
                LicenseRef-scancode-efsl-1.0 (link to the location)
                NOASSERTION (exemplary link to the first of 4 locations)
                Effective License:
                Apache-2.0 AND BSD-3-Clause AND EPL-2.0 AND LicenseRef-scancode-efsl-1.0 AND NOASSERTION OR Apache-2.0 AND EPL-2.0 AND LicenseRef-scancode-efsl-1.0 AND NOASSERTION

                    Repository Configuration

                    
                    ---
                    excludes:
                      paths:
                      - pattern: "**/META-INF/DEPENDENCIES"
                        reason: "BUILD_TOOL_OF"
                        comment: "Licenses contained in this directory reflect content analysed elsewhere."
                      - pattern: "**/META-INF/NOTICE*"
                        reason: "BUILD_TOOL_OF"
                        comment: "Licenses contained in this directory reflect content analysed elsewhere."
                      - pattern: "**/*.svg"
                        reason: "BUILD_TOOL_OF"
                        comment: "SVG files do not contain any license information."
                      - pattern: "package-lock.json"
                        reason: "BUILD_TOOL_OF"
                        comment: "Does not contain any license information."