-
Notifications
You must be signed in to change notification settings - Fork 54
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Node-forge license issue as it is installed as dependency #66
Comments
Excuse my ignorance but isnt BSD-3-Clause compatible with MIT ? |
I can see the problem here is that it found GPL-2.0 which is true... but the project is dual licensed and users can use under what licenses they think its apropiate. The tool is not reporting you a problem with BSD-3-clause. https://github.com/digitalbazaar/forge#contributing
|
Any possibility that we could instead use web crypto instead of node-forge? |
I am facing a problem of licensing((BSD-3-Clause OR GPL-2.0)) when I am using @nrwl/angular.
The issue is regarding one of the package that is installed as part of dependency.
Consider below
So I am installing @nrwl/angular and all of its dependent packages are installed under MIT license except node-forge.
My security scan detects this as problem as we don't want to use BSD-3-Clause license.
I expect the node-forge should be removed as part of dependency of @nrwl/angular as this is creating lot of problems of licensing whilst using @nrwl/angular.
The text was updated successfully, but these errors were encountered: