Skip to content

Correct license for flatted 3.4.2 - ISC (false Artistic-2.0 detection from README)#32350

Merged
capfei merged 1 commit intomasterfrom
clearlydefinedbot_260326_200229.057
Mar 26, 2026
Merged

Correct license for flatted 3.4.2 - ISC (false Artistic-2.0 detection from README)#32350
capfei merged 1 commit intomasterfrom
clearlydefinedbot_260326_200229.057

Conversation

@clearlydefinedbot
Copy link
Copy Markdown
Contributor

Type: Incorrect

Summary:
Correct license for flatted 3.4.2 - ISC (false Artistic-2.0 detection from README)

Details:
The scancode/licensee tools incorrectly detect Artistic-2.0 AND ISC from the README.md file. The actual LICENSE file, package.json, and all source files (php, python, go) consistently declare ISC. This is the same false positive that was already curated for version 3.3.3.

Resolution:
https://github.com/WebReflection/flatted/blob/main/LICENSE

Affected definitions:

@clearlydefinedbot
Copy link
Copy Markdown
Contributor Author

You can review the change introduced to the full definition at ClearlyDefined.

@picnich
Copy link
Copy Markdown

picnich commented Mar 26, 2026

Hi curators — requesting review on this curation. This is a straightforward false positive: scancode/licensee is detecting Artistic-2.0 from the README.md, but the actual LICENSE file, package.json license field, and all source file headers (PHP, Python, Go) consistently declare ISC.

This is the exact same false positive that was already curated for flatted 3.3.3 — the README.md content is nearly identical between versions.

This is currently blocking dependency review checks for security updates (CVE-2026-32141, CVE-2026-33228) in downstream projects. Would appreciate a timely review. Thank you!

@capfei
Copy link
Copy Markdown
Member

capfei commented Mar 26, 2026

@picnich Thank you for the contribution!

@capfei capfei merged commit 8d49156 into master Mar 26, 2026
2 checks passed
@capfei capfei deleted the clearlydefinedbot_260326_200229.057 branch March 26, 2026 22:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants