以下的要求不是强制性的, 未按模板评论时对issue无任何影响
issue处理注意事项:
1. 当前issue受影响的分支提交pr时, 须在pr描述中填写当前issue编号进行关联, 否则无法关闭当前issue;
2. 模板内容需要填写完整, 无论是受影响或者不受影响都需要填写完整内容,未引入的分支不需要填写, 否则无法关闭当前issue;
3. 以下为模板中需要填写完整的内容, 请复制到评论区回复, 注: 内容的标题名称(影响性分析说明, 缺陷严重等级, 受影响版本排查(受影响/不受影响), 修复是否涉及abi变化(是/否))不能省略,省略后defect-manager将无法正常解析填写内容.
评论区可能使用到的指令说明:
| 指令 | 指令说明 | 使用权限 |
|---|---|---|
| /check-issue | 触发defect-manager校验 | 不限 |
| /reason xxx | /reason +挂起或取消条件 | 不限 |
影响性分析说明:
缺陷严重等级:(Critical/High/Moderate/Low)
缺陷根因说明:
受影响版本排查(受影响/不受影响):
- openEuler-20.03-LTS-SP4:
- openEuler-22.03-LTS-SP4:
- openEuler-24.03-LTS-SP1:
- openEuler-24.03-LTS-SP3:
- openEuler-24.03-LTS-SP4:
abi变化(是/否):
- openEuler-20.03-LTS-SP4:
- openEuler-22.03-LTS-SP4:
- openEuler-24.03-LTS-SP1:
- openEuler-24.03-LTS-SP3:
- openEuler-24.03-LTS-SP4:
缺陷issue处理具体操作请参考:
https://atomgit.com/openeuler/cve-manager/blob/master/cve-vulner-manager/doc/md/defect-manager-manual.md
pr关联issue具体操作请参考:
https://docs.atomgit.com/docs/help/home/org_project/pullrequests/pr-related-issue


Welcome To openEuler Community
Hey @SPYFAMILY , thanks for your contribution to the community.
Bot Usage Manual
I'm the Bot here serving you. You can find the instructions on how to interact with me at Here . That means you can comment below every pull request or issue to trigger Bot Commands. You can self-configure the PR merge rules for this repository. For more details, please refer to Here.
Contact Guide
If you have any questions, please contact the SIG: Application ,
and any of the maintainers: @kaitiandu, @small_leek, @zhuchunyi ,
and any of the committers: @caodongxia, @starlet-dx, @wk333 .


GFDL-1.3-no-invariants-or-later
LicenseRef-Fedora-UltraPermissive
LicenseRef-Fedora-Public-Domain
这三个license unknow导致需要评审


LicenseRef-Fedora-Public-Domain 更新为社区认可的 Public Domain
LicenseRef-Fedora-UltraPermissive 在fedora使用,含义是不受限制,更新为之前使用的 Copyright only
GFDL-1.3-no-invariants-or-later 相对于 GFDL-1.3-or-later 更精准,提交issue合规审阅建议oe认可
https://atomgit.com/openeuler/compliance/issues/182


@small_leek 未对受影响版本排查/abi变化进行分析


@small_leek 未对受影响版本排查/abi变化进行分析


@small_leek 未对受影响版本排查/abi变化进行分析


【缺陷描述】:请补充详细的缺陷问题现象描述
【软件信息】
1) OS版本及分支: openEuler-26.09 Round 4
【issue说明】
扫描内容: openEuler社区License 合规问题(规则基线)第4条-项目全部使用经过 FSF 或 OSI 认证的 License
https://atomgit.com/openeuler/compliance/blob/master/doc/rule/baseline.md
License信息列表合规License要求:fsfApproved、osiApproved、oeApproved其中任一为Y,且lowRisk、black为N
【问题复现步骤】
License检查API:https://compliance.openeuler.org/check?license=
(访问请使用License的url编码拼接)
当前存在4类License:
GPL-1.0-or-later AND LPPL-1.3c AND LicenseRef-Fedora-Public-Domain
LicenseRef-Fedora-UltraPermissive
LicenseRef-Fedora-Public-Domain
GPL-3.0-or-later AND LPPL-1.3c AND GFDL-1.3-no-invariants-or-later
结果访问:https://compliance.openeuler.org/check?license=GPL-1.0-or-later AND LPPL-1.3c AND LicenseRef-Fedora-Public-Domain
【预期结果】
“ALLOW”
【实际结果】
UNKNOW 与 NOT_ALLOW
“UNKONW”排查建议:
“NOT ALLOW”排查建议:
当前License均存在于License信息列表,但存在License不符合License信息列表合规License要求(fsfApproved、osiApproved、oeApproved其中任一为Y,且lowRisk、black为N)
【不满足二进制包列表】
texlive-digestif, texlive-dtl, texlive-dvidvi, texlive-ebong, texlive-mex, texlive-optex, texlive-texfot, texlive-texlive-scripts-extra, texlive-xpdfopen
【整改要求】
解压源码包,确认源码许可证、版本、格式是否正确。
若确定无误,请检查issue说明中的License信息列表是否包含License,并且是否符合License信息列表合规要求。
若License在信息列表中不存在或不符合要求,请查看《合规SIG组License准入审阅流程》:https://atomgit.com/openeuler/compliance/blob/master/doc/rule/合规SIG组License准入审阅流程.md