Scan Report
Created by ORT, the OSS Review Toolkit, version cc543c9380-dirty on 2023-04-27T08:33:57.947929743Z.

Project

Scanned revision 63e434e4a0a7d47d1f13a5f21abfe1cd444f91ec of Git repository https://github.com/eclipse/corrosion.git

Index

Rule Violation Summary (0 errors, 0 warnings, 4 hints to resolve)

# Rule Package License Message
1 PROJECT_LICENSE_CHECK Maven:org.eclipse.corrosion:org.eclipse.corrosion.product:1.2.5-SNAPSHOT DETECTED: LicenseRef-scancode-eclipse-sua-2017

License LicenseRef-scancode-eclipse-sua-2017 of project 'Maven:org.eclipse.corrosion:org.eclipse.corrosion.product:1.2.5-SNAPSHOT' is unclassified.

How to fix

Classify LicenseRef-scancode-eclipse-sua-2017 as either approved or restricted.

2 PROJECT_LICENSE_CHECK Maven:org.eclipse.corrosion:org.eclipse.corrosion.product.branding:1.2.4-SNAPSHOT DETECTED: NOASSERTION

License NOASSERTION of project 'Maven:org.eclipse.corrosion:org.eclipse.corrosion.product.branding:1.2.4-SNAPSHOT' is unclassified.

How to fix

Classify NOASSERTION as either approved or restricted.

3 PROJECT_LICENSE_CHECK Maven:org.eclipse.corrosion:parent:1.2.4-SNAPSHOT DETECTED: LicenseRef-scancode-eclipse-sua-2017

License LicenseRef-scancode-eclipse-sua-2017 of project 'Maven:org.eclipse.corrosion:parent:1.2.4-SNAPSHOT' is unclassified.

How to fix

Classify LicenseRef-scancode-eclipse-sua-2017 as either approved or restricted.

4 PROJECT_LICENSE_CHECK Maven:org.eclipse.corrosion:parent:1.2.4-SNAPSHOT DETECTED: NOASSERTION

License NOASSERTION of project 'Maven:org.eclipse.corrosion:parent:1.2.4-SNAPSHOT' is unclassified.

How to fix

Classify NOASSERTION as either approved or restricted.

Cargo::basic:0.1.0 (org.eclipse.corrosion.tests/projects/basic/Cargo.toml)

VCS Information

Type Git
URL https://github.com/eclipse/corrosion.git
Path org.eclipse.corrosion.tests/projects/basic
Revision 63e434e4a0a7d47d1f13a5f21abfe1cd444f91ec

Packages

# Package Scopes Licenses Analyzer Issues Scanner Issues
1 Cargo::basic:0.1.0 Detected Licenses (from VCS):
EPL-2.0 (link to the location)
Effective License:

      Cargo::basic_errors:0.1.0 (org.eclipse.corrosion.tests/projects/basic_errors/Cargo.toml)

      VCS Information

      Type Git
      URL https://github.com/eclipse/corrosion.git
      Path org.eclipse.corrosion.tests/projects/basic_errors
      Revision 63e434e4a0a7d47d1f13a5f21abfe1cd444f91ec

      Packages

      # Package Scopes Licenses Analyzer Issues Scanner Issues
      1 Cargo::basic_errors:0.1.0 Detected Licenses (from VCS):
      EPL-2.0 (link to the location)
      Effective License:

          Maven:org.eclipse.corrosion:org.eclipse.corrosion.product:1.2.5-SNAPSHOT (repository/pom.xml)

          VCS Information

          Type Git
          URL https://github.com/eclipse/corrosion.git
          Path repository
          Revision 63e434e4a0a7d47d1f13a5f21abfe1cd444f91ec

          Packages

          # Package Scopes Licenses Analyzer Issues Scanner Issues
          1 Maven:org.eclipse.corrosion:org.eclipse.corrosion.product:1.2.5-SNAPSHOT Detected Licenses (from VCS):
          BSD-3-Clause (link to the location)
          EPL-1.0 (link to the location)
          EPL-2.0 (exemplary link to the first of 3 locations)
          LicenseRef-scancode-eclipse-sua-2017 (link to the location)
          Effective License:
          BSD-3-Clause AND EPL-1.0 AND EPL-2.0 AND LicenseRef-scancode-eclipse-sua-2017

              Maven:org.eclipse.corrosion:org.eclipse.corrosion.product.branding:1.2.4-SNAPSHOT (org.eclipse.corrosion.product.branding/pom.xml)

              VCS Information

              Type Git
              URL https://github.com/eclipse/corrosion.git
              Path org.eclipse.corrosion.product.branding
              Revision 63e434e4a0a7d47d1f13a5f21abfe1cd444f91ec

              Packages

              # Package Scopes Licenses Analyzer Issues Scanner Issues
              1 Maven:org.eclipse.corrosion:org.eclipse.corrosion.product.branding:1.2.4-SNAPSHOT Detected Licenses (from VCS):
              EPL-2.0 (exemplary link to the first of 7 locations)
              NOASSERTION (link to the location)
              Effective License:
              EPL-2.0 AND NOASSERTION

                  Maven:org.eclipse.corrosion:parent:1.2.4-SNAPSHOT (pom.xml)

                  VCS Information

                  Type Git
                  URL https://github.com/eclipse/corrosion.git
                  Path
                  Revision 63e434e4a0a7d47d1f13a5f21abfe1cd444f91ec

                  Packages

                  # Package Scopes Licenses Analyzer Issues Scanner Issues
                  1 Maven:org.eclipse.corrosion:parent:1.2.4-SNAPSHOT Detected Licenses (from VCS):
                  Apache-2.0 (exemplary link to the first of 13 locations)
                  BSD-3-Clause (link to the location)
                  CC-BY-3.0 (link to the location)
                  CC-BY-4.0 (exemplary link to the first of 2 locations)
                  EPL-1.0 (exemplary link to the first of 4 locations)
                  EPL-2.0 (exemplary link to the first of 194 locations)
                  LicenseRef-scancode-eclipse-sua-2017 (link to the location)
                  MIT (exemplary link to the first of 4 locations)
                  NOASSERTION (exemplary link to the first of 2 locations)
                  Effective License:
                  Apache-2.0 AND BSD-3-Clause AND CC-BY-3.0 AND CC-BY-4.0 AND EPL-1.0 AND EPL-2.0 AND LicenseRef-scancode-eclipse-sua-2017 AND MIT AND NOASSERTION

                      Repository Configuration

                      
                      ---
                      excludes:
                        paths:
                        - pattern: "**/META-INF/DEPENDENCIES"
                          reason: "BUILD_TOOL_OF"
                          comment: "Licenses contained in this directory reflect content analysed elsewhere."
                        - pattern: "**/META-INF/NOTICE*"
                          reason: "BUILD_TOOL_OF"
                          comment: "Licenses contained in this directory reflect content analysed elsewhere."
                        - pattern: "**/*.svg"
                          reason: "BUILD_TOOL_OF"
                          comment: "SVG files do not contain any license information."
                        - pattern: "package-lock.json"
                          reason: "BUILD_TOOL_OF"
                          comment: "Does not contain any license information."