fix(guix): restore MPL-2.0 (squisher clobber downgraded it to PMPL) - #30
Conversation
guix.scm declared (license ... "PMPL-1.0-or-later") while its OWN SPDX header on line 1 said MPL-2.0, and the repo's root LICENSE is the Mozilla Public License. The file contradicted itself: the signature of the squisher-corpus clobber, which wrote one package definition across the estate carrying another project's identity and licence. Measured across all 418 estate repos: 64 guix.scm files asserted PMPL. Exactly 2 were self-consistent (SPDX header ALSO PMPL) and are untouched -- palimpsest-license and polystack. The other 62, including this one, were contradictory. Now uses Guix's built-in `mpl2.0` rather than the hand-rolled licence record, which also removes the palimpsest-license URL that had no business on an MPL-2.0 package. Verified: no PMPL remains, and the file still parses as Scheme. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
|
Note Automatic reviews are paused because your trial's included automatic processing has been used for this period. Upgrade now, or comment "Gitar review" to run a review anytime. Code Review ✅ ApprovedRestores MPL-2.0 in guix.scm to resolve the contradiction with the SPDX header and root LICENSE file. No issues found.
OptionsDisplay: compact → Showing less information. Comment with these commands to change the behavior for this request:
Was this helpful? React with 👍 / 👎 | Gitar |
|
|
🔍 Hypatia Security ScanFindings: 51 issues detected
View findings[
{
"reason": "Issue in scorecard.yml",
"type": "missing_workflow",
"file": "scorecard.yml",
"action": "create",
"rule_module": "workflow_audit",
"severity": "high"
},
{
"reason": "Issue in ci.yml",
"type": "npermissions_typo",
"file": "ci.yml",
"action": "fix_typo",
"rule_module": "workflow_audit",
"severity": "high"
},
{
"reason": "codeql.yml lists `language: javascript-typescript` but the repo has no source files in any CodeQL-scannable language. The analyze job will exit 'no source files' on every run. Switch the matrix to `actions` (which scans workflow files — every repo has those).",
"type": "codeql_language_matrix_mismatch",
"file": "codeql.yml",
"action": "switch_codeql_matrix_to_actions",
"rule_module": "workflow_audit",
"severity": "high"
},
{
"reason": "Issue in boj-build.yml",
"type": "missing_timeout_minutes",
"file": "boj-build.yml",
"action": "flag",
"rule_module": "workflow_audit",
"severity": "medium"
},
{
"reason": "Issue in casket-pages.yml",
"type": "missing_timeout_minutes",
"file": "casket-pages.yml",
"action": "flag",
"rule_module": "workflow_audit",
"severity": "medium"
},
{
"reason": "Issue in casket-pages.yml",
"type": "missing_timeout_minutes",
"file": "casket-pages.yml",
"action": "flag",
"rule_module": "workflow_audit",
"severity": "medium"
},
{
"reason": "Issue in ci.yml",
"type": "missing_timeout_minutes",
"file": "ci.yml",
"action": "flag",
"rule_module": "workflow_audit",
"severity": "medium"
},
{
"reason": "Issue in codeql.yml",
"type": "missing_timeout_minutes",
"file": "codeql.yml",
"action": "flag",
"rule_module": "workflow_audit",
"severity": "medium"
},
{
"reason": "Issue in hypatia-scan.yml",
"type": "missing_timeout_minutes",
"file": "hypatia-scan.yml",
"action": "flag",
"rule_module": "workflow_audit",
"severity": "medium"
},
{
"reason": "Issue in instant-sync.yml",
"type": "missing_timeout_minutes",
"file": "instant-sync.yml",
"action": "flag",
"rule_module": "workflow_audit",
"severity": "medium"
}
]Powered by Hypatia Neurosymbolic CI/CD Intelligence |
guix.scmdeclaredPMPL-1.0-or-laterwhile its own SPDX header said MPL-2.0 and the rootLICENSEis the Mozilla Public License — the file contradicted itself. That is the squisher-corpus clobber signature.Measured across all 418 estate repos: 64 guix.scm files asserted PMPL; exactly 2 were self-consistent and are deliberately untouched (
palimpsest-license,polystack). The other 62, including this one, were contradictory.Now uses Guix's built-in
mpl2.0instead of the hand-rolled licence record, which also drops the palimpsest-license URL that had no business on an MPL-2.0 package.Verified: no PMPL remains; file still parses as Scheme.
🤖 Generated with Claude Code