arrow
Return

Open Source License Inconsistencies on GitHub

delete2023-07-22
delete7
PRE
AI
T
Thomas Wolter *
A
Ann Barcomb
D
Dirk Riehle
N
Nikolay Harutyunyan
DOI:10.1145/3571852delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Almost all software, open or closed, builds on open source software and therefore needs to comply with the license obligations of the open source code. Not knowing which licenses to comply with poses a legal danger to anyone using open source software. This article investigates the extent of inconsistencies between licenses declared by an open source project at the top level of the repository and the licenses found in the code. We analyzed a sample of 1,000 open source GitHub repositories. We find that about half of the repositories did not fully declare all licenses found in the code. Of these, approximately 10% represented a permissive vs. copyleft license mismatch. Furthermore, existing tools cannot fully identify licences. We conclude that users of open source code should not just look at the declared licenses of the open source code they intend to use, but rather examine the software to understand its actual licenses.
Keywords:
License management
license conflicts

Journal

A
ACM Transactions on Software Engineering and Methodology
IF:
6.2
Papers:
1.2K
Citations:
3.4K

Organization

U
University of Calgary
Scholars:
3.8W
Papers: 3.3W
Citations: 52
U
University of Erlangen Nuremberg
Scholars:
3.2W
Papers: 2.6W
Citations: 29