← Back to issue list

Review SPDX package

View original Github issue

Metadata

Project
rockcraft
Number
#169
Type
issue
State
open
Author
tigarmo
Labels
Created
2022-12-16 11:01:59+00:00
Updated
2024-07-24 16:20:16+00:00
Closed

Current evaluation

No evaluation has been recorded for this issue yet.

Issue body

Looks like the `spdx-license-list` package is gone from PyPI. We use it to validate that the chosen license is valid. #168 replaces that package with `spdx-lookup` as a stop-gap to "unbreak" `main`, but as @lengau points out that one has a single release and an outdated license db. We should review this situation and come up with something more sustainable.

Evaluation history

No evaluation history available.