Image pipeline detects GPL-3 code
Background
Initial test on image pipeline for v2026dev2 detects GPL-3 code in the following packages
ERROR on package libgcc-s1 license GPL-3+ found, whitelisted True ERROR on package libstdc++6 license GPL-3+ found, whitelisted True ERROR on package libunistring5 license LGPL-3 found, whitelisted False
Reproducibility
How often the issue is hit when repeating the steps to reproduce and changing nothing?
Put the
-
✅ always - often, but not always
- rarely
Impact of bug
Having GPL-3 in target images is a violation to Apertis policies. However, initial research seems to point to the fact that this is a false possitive.
Outcomes
TBD
Management data
This section is for management only, it should be the last one in the description.
/cc @em @balasubramanian @sudarshan @wlozano
Phabricator link: https://phabricator.apertis.org/T11032