Just spent another hour explaining to security why our own internal libraries aren't suddenly GPL-tainted. Xray is flagging anything with a `pom.xml` or `package.json` that references an internal artifact as `GPL-2.0-only`.
Turns out the issue is their license detection "logic" when no license is explicitly declared in the build descriptor. It cascades up the dependency tree and seems to pick the scariest license it can find.
* It's scanning our internal artifact repositories, not just public sources.
* The "component" it's flagging is often our own project's root.
* Creates noise that makes real GPL issues harder to find.
Seen this? Is there a config flag to stop scanning internally published packages, or is this another "enterprise support" upsell?
Read the contract