Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

SCTK detecting mongodb-sspl-1.0 in the OpenSearch README incorrectly #3923

Open
DennisClark opened this issue Sep 16, 2024 · 0 comments
Open
Assignees
Labels

Comments

@DennisClark
Copy link
Contributor

A recent scan of the OpenSearch source package available from https://github.com/opensearch-project/OpenSearch/archive/refs/tags/2.16.0.tar.gz returned the overall license of apache-2.0 correctly, but it incorrectly reports finding mongodb-sspl-1.0 in the README.md file, probably because of this bit:

**OpenSearch** is [a community-driven, open source fork](https://aws.amazon.com/blogs/opensource/introducing-opensearch/) of [Elasticsearch](https://en.wikipedia.org/wiki/Elasticsearch) and [Kibana](https://en.wikipedia.org/wiki/Kibana) following the [license change](https://blog.opensource.org/the-sspl-is-not-an-open-source-license/) in early 2021. We're looking to sustain (and evolve!) a search and analytics suite for the multitude of businesses who are dependent on the rights granted by the original, [Apache v2.0 License](LICENSE.txt).

This is unfortunate because the overall licensing is clearly apache-2.0. Scan results attached.

OpenSearch-2.16.0.tar.gz_scan.zip
OpenSearch-2.16.0.tar.gz_scan.zip

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

2 participants