/
/
# What does this implement/fix? The dependency security workflow flagged dependency bumps as having "no license information" for packages that are perfectly fine. Packages that moved to the modern packaging standard (PEP 639) publish their license as an SPDX expression in a new field, and the safety check only looked at the old field. Anything that had made the switch came back as unknown, turning the security status red and requiring a manual review label. This hit `chardet` in #5724 (its license is `0BSD`, one of the most permissive there is). Checking all 112 of our dependencies against PyPI, 46 were being flagged; with this change 10 are, and all 10 are correct (7 are genuinely GPL/AGPL, 3 publish no license at all). ## Changes - Read the license from the SPDX field first, then the old license field, then the license classifiers - Understand SPDX license expressions such as `0BSD`, `MIT OR Apache-2.0` and `MPL-2.0 AND (Apache-2.0 OR MIT)` - Judge those expressions on the licenses they name, instead of guessing from the wording - Stop a permissive license name from hiding a restrictive one next to it, in an expression, in the classifiers, or behind a `WITH` - Match license names as whole words, so `MPL 2.0` is recognised while `permitted` and `this copyright` are not - Added tests for the license lookup and the compatibility check ## Types of changes - [ ] Bugfix (non-breaking change which fixes an issue) — `bugfix` - [ ] New feature (non-breaking change which adds functionality) — `new-feature` - [ ] Enhancement to an existing feature — `enhancement` - [ ] New music/player/metadata/plugin provider — `new-provider` - [ ] Breaking change (fix or feature that would cause existing functionality to not work as expected) — `breaking-change` - [ ] Refactor (no behaviour change) — `refactor` - [ ] Documentation only — `documentation` - [x] Maintenance / chore — `maintenance` - [ ] CI / workflow change — `ci` - [ ] Dependencies bump — `dependencies` ## Checklist - [x] The code change is tested and works locally. - [x] `pre-commit run --all-files` passes. - [x] `pytest` passes, and tests have been added/updated under `tests/` where applicable. - [ ] For changes to shared models, the companion PR in `music-assistant/models` is linked. - [ ] For changes affecting the UI, the companion PR in `music-assistant/frontend` is linked. - [x] I have read and complied with the project's [AI Policy](https://github.com/music-assistant/.github/blob/main/AI_POLICY.md) for any AI-assisted contributions. - [ ] I have [raised a PR against the documentation repository](https://github.com/music-assistant/music-assistant.io/blob/main/CONTRIBUTING.md) targeting the main or beta branch as appropriate.