Skip to content

Are license expressions validated ? #158

@zvr

Description

@zvr

I was very surprised when a document with arbitrary strings for license names was validated as valid SPDX.

Is the validation only on the structural level and not on the value of strings?

For example, https://gist.github.com/zvr/0c07cf7c88c12abb62822592cf73e033 has a complete document that the online tools show as valid SPDX (and happily convert to other formats).

I would imagine that the license strings Apache-2.0-with-LLVM-exception, GPL-2.0-with-OpenSSL-exception, and GPL-3.0-with-GCC-exception are not valid SPDX License Expresssions.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions