License Scan report

Project: cncf-3
Subproject: kubevela
Snapshot on: 2024-03-15 (show repos)
catalog 8d6dcdcc
charts f52ff410
cloudshell 901bfdb7
community f7820f4e
cue a976b0e3
killercoda-scenario 89756ad4
kube-trigger ac10e579
kubevela 24756fc5
kubevela-core-api 012dadc2
kubevela-github-actions 3f99556f
microservices-demo 65b55227
otv 18035e70
pkg b0273a7f
plugin-tools 648d226c
prism 1ecdbb4a
samples 625fec57
terraform-controller 0845592e
tools-image f9196d6d
traefik-helm-chart d864ae50
vector-controller 41b8c430
vela-hello-world 6c6df12b
velad c3beea6a
velaux 127f5325
workflow f187b42d

Key findings:

Finding #1
Priority: Very High
These files are under the AGPL-3.0 license (a very strong copyleft license) which conflicts with the project license, as well as CNCF licensing policies. These files must be removed from your repos.
1 file (show files)
kubevela-2024-03-15.zip/catalog/experimental/addons/minio-operator/metadata.yaml
Finding #2
Priority: High
These files are under the MPL-2.0 license (a weak copyleft license) which conflicts with the project license, as well as CNCF licensing policies. If the files are not needed you should remove them from your repos. If the files are required, you may request a CNCF License Exception (see email for details).
2 files (show files)
kubevela-2024-03-15.zip/terraform-controller/hack/tool/backup_restore/internal/app/tfstate.go
kubevela-2024-03-15.zip/terraform-controller/controllers/util/decompress.go

License summary:

Project Licenses:
  Apache-2.0   2183
Copyleft:
  AGPL-3.0   1
Weak Copyleft:
  Apache-2.0 AND MPL-2.0   1
  MPL-2.0   1
Attribution:
  Apache-2.0 AND BSD-3-Clause   26
  Apache-2.0 AND MIT   2
  BSD-2-Clause   2
  BSD-3-Clause   12
  ISC   2
  MIT   65
  OFL-1.1   5
No license found:
  No license found in file   8035
  No license found in file - excluded file extension   395
  No license found in file - empty file   35
  No license found in file - third party directory   1
TOTAL   10766  

Counts are numbers of files detected in the scanned repos.


Please contact the provider of this report with any questions, comments, etc. regarding its contents.