vendredi 10 février 2017

How to deal with Sonatype reported critical license threats?

Vote count: 0

The application I built was analysed by Sonatype (an issue tracker tool) for license threats. It shows some critical threats for jersey jars (core, servlet, client, json) version 1.17. The jars come under CDDL-1.1 or GPL-2.0-CPE license. The report was like:

License Threat:- CDDL-1.1 or GPL-2.0-CPE

Component:- com.sun.jersey : jersey-core : 1.17

Type:- Severe

Status:- Open, and so on...

I dont have much knowledge about software licenses and so I cant make much out of the report. Please suggest how to deal with this issue. Internet doesnt seem to help regarding this. I found this on some of the sites:

As a special exception, the copyright holders of this library give you permission to link this library with independent modules to produce an executable, regardless of the license terms of these independent modules, and to copy and distribute the resulting executable under terms of your choice, provided that you also meet, for each linked independent module, the terms and conditions of the license of that module. An independent module is a module which is not derived from or based on this library. If you modify this library, you may extend this exception to your version of the library, but you are not obligated to do so. If you do not wish to do so, delete this exception statement from your version.

But I cant find how to implement this. Any solution/suggestion would be much appreciated. If this is not the right platform to ask this kindly help me find the appropriate one.

asked 29 secs ago

Let's block ads! (Why?)



How to deal with Sonatype reported critical license threats?

Aucun commentaire:

Enregistrer un commentaire