LiDetector : License Incompatibility Detection for Open Source Software

Author:

Xu Sihan1ORCID,Gao Ya2,Fan Lingling1ORCID,Liu Zheli1,Liu Yang3ORCID,Ji Hua1

Affiliation:

1. TKLNDST, College of Cyber Science, Nankai University, Tongyan Road, Jinnan District, Tianjin, China

2. TKLNDST, College of Computer Science, Nankai University, Tongyan Road, Jinnan District, Tianjin, China

3. Zhejiang Sci-tech University, Hangzhou, Zhejiang, China and Nanyang Technological University, Singapore

Abstract

Open-source software (OSS) licenses dictate the conditions, which should be followed to reuse, distribute, and modify software. Apart from widely-used licenses such as the MIT License, developers are also allowed to customize their own licenses (called custom license), whose descriptions are more flexible. The presence of such various licenses imposes challenges to understand licenses and their compatibility. To avoid financial and legal risks, it is essential to ensure license compatibility when integrating third-party packages or reusing code accompanied with licenses. In this work, we propose LiDetector , an effective tool that extracts and interprets OSS licenses (including both official licenses and custom licenses), and detects license incompatibility among these licenses. Specifically, LiDetector introduces a learning-based method to automatically identify meaningful license terms from an arbitrary license, and employs Probabilistic Context-Free Grammar (PCFG) to infer rights and obligations for incompatibility detection. Experiments demonstrate that LiDetector outperforms existing methods with 93.28% precision for term identification, and 91.09% accuracy for right and obligation inference, and can effectively detect incompatibility with 10.06% FP rate and 2.56% FN rate. Furthermore, with LiDetector , our large-scale empirical study on 1,846 projects reveals that 72.91% of the projects are suffering from license incompatibility, including popular ones such as the MIT License and the Apache License. We highlighted lessons learned from perspectives of different stakeholders and made all related data and the replication package publicly available to facilitate follow-up research.

Funder

National Natural Science Foundation of China

National Key Research Project of China

Publisher

Association for Computing Machinery (ACM)

Subject

Software

Reference70 articles.

1. Thomas A. Alspaugh, Hazeline U. Asuncion, and Walt Scacchi. 2009. Intellectual property rights requirements for heterogeneously-licensed systems. In Proceedings of the 17th IEEE International Requirements Engineering Conference. 24–33.

2. Software licenses in context: The challenge of heterogeneously-licensed systems;Alspaugh Thomas A.;Journal of the Association for Information Systems,2010

3. Benjamin Andow, Samin Yaseer Mahmud, Wenyu Wang, Justin Whitaker, William Enck, Bradley Reaves, Kapil Singh, and Tao Xie. 2019. Policylint: Investigating internal privacy policy contradictions on Google Play. In Proceedings of the 28th USENIX Conference on Security Symposium. 585–602.

4. BDF. 2021. The Backdoor Factory. Retrieved 27th Sep 2021 from https://github.com/secretsquirrel/the-backdoor-factory.

5. Blosc. 2021. A blocking shuffling and lossless compression library. Retrieved 27th Sep 2021 from https://github.com/Blosc/c-blosc.

Cited by 6 articles. 订阅此论文施引文献 订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献

1. A Large-Scale Empirical Study of Open Source License Usage: Practices and Challenges;Proceedings of the 21st International Conference on Mining Software Repositories;2024-04-15

2. Catch the Butterfly: Peeking into the Terms and Conflicts Among SPDX Licenses;2024 IEEE International Conference on Software Analysis, Evolution and Reengineering (SANER);2024-03-12

3. Towards Automated Detection of Unethical Behavior in Open-Source Software Projects;Proceedings of the 31st ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering;2023-11-30

4. The software heritage license dataset (2022 edition);Empirical Software Engineering;2023-11

5. Understanding and Remediating Open-Source License Incompatibilities in the PyPI Ecosystem;2023 38th IEEE/ACM International Conference on Automated Software Engineering (ASE);2023-09-11

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3