Bug 1003854

Summary: Third party license problem (non-free and new license)
Product: [Fedora] Fedora Reporter: mejiko <private>
Component: glassfish-toplink-essentialsAssignee: gil cattaneo <puntogil>
Status: CLOSED NOTABUG QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: unspecified Docs Contact:
Priority: unspecified    
Version: 19CC: java-sig-commits, puntogil, tcallawa
Target Milestone: ---   
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2013-09-03 20:16:40 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Bug Depends On:    
Bug Blocks: 901759    

Description mejiko 2013-09-03 11:31:02 UTC
Hello.

glassfish-toplink-essentials include 3rd party License text.

See: glassfish-bootstrap/legal/3RD-PARTY-LICENSE.txt

This license included Json license (Its non-free), and New License (Stax API).
but this licensed code is unknown.

Suggests:

1. Search there licensed code, license review, and remove or replace non-free code.

2. Contact upstream author.

3. Remove fedora repos.

Thanks

Reference:

http://lintian.debian.org/tags/license-problem-json-evil.html
https://fedoraproject.org/wiki/Licensing:Main?rd=Licensing#Bad_Licenses
https://www.gnu.org/licenses/license-list.en.html#JSON
http://lintian.debian.org/tags/license-problem-json-evil.html

Comment 1 mejiko 2013-09-03 11:31:49 UTC
Blocking FE-Legal, This is license problem.

Comment 2 Tom "spot" Callaway 2013-09-03 20:16:40 UTC
This is a false positive. Nothing in this package is actually under the non-free JSON license, and the Stax API code is not present.

This "3RD-PARTY-LICENSE.txt" appears to be a "cover all the bases" sort of license text.