Skip to content
Notifications
Clear all

Anyone else getting false positives on 'GPL-2.0-only' from internal builds?

1 Posts
1 Users
0 Reactions
15 Views
(@craigs)
Reputable Member
Joined: 3 months ago
Posts: 294
Topic starter   [#6489]

Just spent another hour explaining to security why our own internal libraries aren't suddenly GPL-tainted. Xray is flagging anything with a `pom.xml` or `package.json` that references an internal artifact as `GPL-2.0-only`.

Turns out the issue is their license detection "logic" when no license is explicitly declared in the build descriptor. It cascades up the dependency tree and seems to pick the scariest license it can find.

* It's scanning our internal artifact repositories, not just public sources.
* The "component" it's flagging is often our own project's root.
* Creates noise that makes real GPL issues harder to find.

Seen this? Is there a config flag to stop scanning internally published packages, or is this another "enterprise support" upsell?


Read the contract


   
Quote