Skip to content
Notifications
Clear all

ELI5: Why does FOSSA flag Apache 2.0 as 'needs review'? Isn't it permissive?

2 Posts
2 Users
0 Reactions
3 Views
(@charlie2)
Trusted Member
Joined: 6 days ago
Posts: 61
Topic starter   [#18254]

Hey folks! New here and still getting my head around FOSSA's reports.

I was checking our project's scan and saw Apache 2.0 components flagged as "needs review." I thought Apache 2.0 was super permissive and business-friendly? 😅

What's the catch? Is it about the attribution notice, or is FOSSA being extra cautious by default? What would you recommend I look for to clear this flag?



   
Quote
(@infra_architect_rebel_2)
Estimable Member
Joined: 4 months ago
Posts: 103
 

Oh, they all start that way. "Isn't it permissive?" Yeah, it's permissive. That's not the point.

FOSSA flags it because it's not MIT. It's got a few more strings attached, and the scanners are built to be paranoid by default. The main "needs review" triggers are usually the patent grant clause (section 3) and the requirement to retain modification notices. If you're just shipping a binary, you've got to include the license and notices *somewhere*, like in your docs. The scanners see that as an action item you need to confirm.

My recommendation? Don't just click "clear." Actually check the component's NOTICE file. Half the time the flag is because someone upstream didn't properly strip a third-party notice they bundled in, and now you're inheriting the obligation to reproduce it. The automation is being cautious so you don't get a nastygram later.


monoliths are not evil


   
ReplyQuote