nexB / scancode-toolkit

:mag: ScanCode detects licenses, copyrights, dependencies by "scanning code" ... to discover and inventory open source and third-party packages used in your code. Sponsored by NLnet project https://nlnet.nl/project/vulnerabilitydatabase, the Google Summer of Code, Azure credits, nexB and others generous sponsors!
https://github.com/nexB/scancode-toolkit/releases/
2.02k stars 533 forks source link

Treat CLA specially #3831

Open pombredanne opened 1 week ago

pombredanne commented 1 week ago

We likely should not treat a generic-cla as something important. When a package is only used, a CLA is not relevant See for instance: https://github.com/open-telemetry/opentelemetry-swift/blob/main/CONTRIBUTING.md

The same would apply to other related Code of conduct and non-usage related legal documents... these are NOT licenses. And even if we use license detection to find them, they should not be reported as a license