Skip to content

Normalized licenses on ecosyste.ms do not match package manager data #1424

@rng70

Description

@rng70

While collecting and validating data obtained from ecosyste.ms, we noticed a discrepancy between the values reported by ecosyste.ms and the package’s original package manager.

For example, when querying data for the cryptography package, we observed the following:

These two results do not appear to be compatible. We also verified the license information directly on PyPI, and it indicates that cryptography is dual-licensed under Apache-2.0 or BSD-3-Clause.

Additionally, found that different versions of cryptography are published under different license expressions. For example, version

Also noticed that ecosyste.ms provides a licenses field associated with each version, but that field is null.

Metadata

Metadata

Assignees

Labels

bugSomething isn't working

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions