Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

react-overlays flagged by legal/compliance scan because of dependency 'uncontrollable' #1036

Open
ghost opened this issue Apr 21, 2023 · 0 comments

Comments

@ghost
Copy link

ghost commented Apr 21, 2023

Not a feature but more of a kind of request...

This package has 'uncontrollable@7.2.1' as a direct dependency.

Some organizations do not accept any code that has any reference to React's BSD license.

Since 2017, Facebook/React does not have a BSD license anymore, but an MIT license.

Uncontrollable, at file utils.js, on line 54, has a comment with a copy of the old React BSD copyright notice.

Packages that rely on Uncontrollable are being flagged in compliance scans because of the outdated copyright notice. Even packages that don't have it as a direct dependency are being flagged if they have react-overlays as a dependency (like react-bootstrap-typeahead, for example).

Solution

I've already raised an issue to Uncontrollable maintainers, asking them to change the mention to a BSD license to an MIT license.

If they're responsive, please try to reach them and ask them to release a new, updated version and update the version in your package.

Alternative

Use an alternative to Uncontrollable.

@ghost ghost changed the title react-overlays flagged by legal/compllicance scan because of dependency 'uncontrollable' react-overlays flagged by legal/complliance scan because of dependency 'uncontrollable' Apr 21, 2023
@ghost ghost changed the title react-overlays flagged by legal/complliance scan because of dependency 'uncontrollable' react-overlays flagged by legal/compliance scan because of dependency 'uncontrollable' Apr 21, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

0 participants