naugtur/npm-audit-resolver

Update audit-resolve-core to an open-source license

Closed this issue · 3 comments

My organization uses a license scanner that has a strict whitelist. Right now, the tool fails on this dependency:

Package "audit-resolve-core@1.1.7" is licensed under "UNKNOWN" which is not permitted by the --onlyAllow flag.

Could you please consider updating the license in the package.json of audit-resolve-core?

Thanks for letting me know. Not sure how I missed it.

If you make a PR with apache2 I'll merge it right away from the phone. Otherwise you need to wait till I'm available.

Ah, only issue is I'm not sure I can access that repository! I get a 404 error when I try to follow a link from NPM.

I went to the repository and it's got a license defined in package.json
There was a 1 letter confusion in the repo name between github and elsewhere, so the link didn't work. I guess that's why the tool didn't work too.
But if you searched my repositories, you would have found it.

I renamed the repo in github to match the URLs etc. Let me know if this is still a problem