scancode-toolkit
scancode-toolkit copied to clipboard
Address Unicode license updates
This email was sent by @McCoySmith to the SPDX list https://lists.spdx.org/g/Spdx-legal/message/3593
Unicode-TOU External Inbox
McCoy Smith via lists.spdx.org [email protected] 12:47 AM (7 hours ago) to spdx-legal
All:
Unicode recently revised and published its TOUs. See here: https://www.unicode.org/copyright.html
The prior TOUs received at SPDX identifier (https://spdx.org/licenses/Unicode-TOU.html) so at a minimum there probably should be a change to the text associated with that identifier.
However, the TOUs maybe now don't qualify as a license in a way that would make them something that SPDX would want to identify. And the old TOUs aren't likely something that would be used with anything now given they governed the Unicode website and content which now are governed by new TOUs.
Might it make sense given this change to just jettison the Unicode-TOU identifier altogether?
I'll leave it up to the legal team to figure out how to handle that situation, but just a suggestion to perhaps cut back on the size of the identifier list?
McCoy
[FWIW, I represent Unicode so will respond to questions on behalf of them if needed]
We need to review and update license detection for all these licenses. Historically Unicode licenses, ToU and related have been relatively messy
We have already the updated https://scancode-licensedb.aboutcode.org/unicode-v3.html but Unicode project tend also to customize the text in each project, for instance https://github.com/unicode-org/icu4x/blob/main/LICENSE text is slightly different.
Also we will not deprecate ToU if SPDX decides to do so, because these are seen in the wild.