Pith. sign in

REVIEW 3 major objections 6 minor 216 references

Open Source, Hidden Costs: A Systematic Literature Review on OSS License Management

T0 review · 3 major / 6 minor · reviewed 2026-08-06 · deepseek-v4-flash

Pith's one-line read This paper claims to be the first systematic literature review of open-source software license management, mapping 80 studies into a three-stage taxonomy of identification, risk assessment, and mitigation, and using that map to expose…

desk verdict Useful SLR with a real contribution in the taxonomy; the coverage claim is a bit over-strong, but the fix is straightforward and the paper deserves a serious referee. read the letter →

arxiv 2507.05270 v2 pith:3QPJ3NMH submitted 2025-07-03 cs.SE

classification cs.SE
keywords opensourcelicensemanagementsystematicliteraturereviewidentificationcompatibilitycompliancesoftwarecompositionanalysisriskmitigationproliferation
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

This paper claims to be the first systematic literature review of open-source software (OSS) license management, covering 80 primary studies published between 2000 and September 2024. Its central contribution is a taxonomy that organizes the field into three functional stages — license identification, license risk assessment, and license risk mitigation — derived from the workflow of commercial software composition analysis tools. The review then uses this map to identify persistent gaps: academic tools handle fine-grained license terms while industry tools rely on coarse metadata; most research targets a small set of obligations and licenses; and emerging generative coding tools introduce new licensing risks that neither side addresses. If the map is accurate, it gives researchers and practitioners a shared frame for where the field stands and where investment is needed.

What carries the argument

The load-bearing structure is the three-category taxonomy (license identification, license risk assessment, license risk mitigation) constructed from the functionalities of twelve leading software composition analysis tools surveyed through a recognized industry evaluation report. The taxonomy does the argument's work: it is used to classify all 80 primary studies into twelve finer-grained classes (e.g., rule-based versus fuzzy-matching identification; incompatible-pair versus term-conflict detection), and then to read each study against the corresponding industrial capability. The review's claims about gaps between academia and industry are produced by comparing each paper's objective and granularity with what the surveyed tools actually implement.

What would settle it

Re-run the search with the same keywords and databases but without the venue-quality filter, or add one or two additional digital libraries or a general scholarly search engine, and check whether new primary studies appear that change the gap analysis — for instance, a body of term-level license analysis from the legal-informatics community that the current corpus omits.

Watch

Extended reading notes

Core claim

The paper's central claim is that existing OSS license management research can be coherently organized by the three-stage workflow that industrial software composition analysis tools follow: first identify the license attached to a component or snippet, then assess the legal risks (compatibility between licenses and compliance with obligations), then mitigate those risks by remediation or license selection. The authors assert that no prior review has studied this workflow and the state-of-the-art approaches end to end, making this the first systematic literature review in the area. On the basis of 80 papers, they argue that academic research has moved toward term-level, context-aware analysis of license texts and obligations, while industry tools predominantly rely on static metadata databases and coarse compatibility knowledge; they further argue that license proliferation and ambiguous legal terms such as 'derivative works' are the main structural obstacles, and that generative software engineering intensifies these problems.

Load-bearing premise

The whole map stands on the assumption that the search and screening steps captured the relevant literature, because the relevance exclusions and the venue-quality filter are applied by the authors' judgment and could systematically miss valid work.

Editorial extensions

If this is right

  • The field's center of gravity is shifting from identifying license names to identifying license terms, and future tools should support term-level compatibility and compliance analysis.
  • Industrial software composition analysis tools lag academic research on fine-grained identification, mitigation automation, and license recommendation, so closing that gap is a concrete opportunity.
  • License proliferation and ambiguous legal terms such as 'derivative works' are the main bottlenecks, requiring standardized meta-models and measurable metrics for automated detection.
  • Emerging generative code models create a licensing gray area around derivative status and training-data opacity that existing license management approaches do not cover.
  • Contributor license agreements and developer certificates of origin are essentially unstudied in the 80-paper corpus, marking an open research direction.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • The three-stage taxonomy could be used as a benchmarking schema for future reviews or for industry–academia gap analyses, and it could be stress-tested by applying it to papers published after September 2024.
  • If the gap claims hold, software composition analysis vendors could plausibly adopt term-level analysis from academic tools to detect customized licenses, but the adoption path would require solving explainability and liability concerns that the paper does not discuss.
  • The call for measurable metrics suggests a testable research program: operationalize ambiguous license terms such as 'derivative work' as concrete similarity or usage thresholds and validate them against legal decisions, an extension the paper gestures at but does not itself perform.
  • The finding that contributor license agreements and developer certificates of origin are unstudied implies that empirical studies of their adoption, administrative burden, and effectiveness in real projects would be a natural next contribution.
Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

3 major / 6 minor

Summary. This manuscript reports a systematic literature review of 80 primary studies on open-source software license management, spanning 2000 to September 2024. The authors propose a taxonomy grounded in industrial software composition analysis (SCA) workflows, with three high-level categories (license identification, license risk assessment, license risk mitigation) and twelve leaf-level categories. The review summarizes each category, compares academic approaches with industrial SCA tool capabilities, identifies seven challenges and four research opportunities, and gives practitioner recommendations. The method is described in detail: five digital databases, a PRISMA-inspired flow diagram, explicit exclusion criteria, snowballing, and Cohen's kappa statistics for screening and classification.

Significance. If the selected corpus is representative, this SLR provides a useful map of a fragmented research area and a taxonomy that connects academic work to industrial practice. The paper's strengths include the explicit screening protocol, the use of an external industrial benchmark (Forrester Wave) to anchor the taxonomy, high reported inter-rater agreement, and a forward-looking discussion of license issues for generative AI. These features make the review a potentially valuable reference for both researchers and practitioners. However, the central claim of being a comprehensive map depends on the completeness and reproducibility of the corpus selection, which raises the concerns detailed below.

major comments (3)
  1. [III.B.1 (EC5), Section V.D] The CORE-ranking exclusion criterion EC5 removed 39 of 100 full-text papers, and the snowballing procedure starts only from the 78 papers that survive this filter. As the paper itself concedes in Section V.D, EC5 'may inadvertently exclude some high-quality work,' but the manuscript does not provide the list of excluded papers, nor a sensitivity analysis showing that the taxonomy and gap analysis are unchanged when these papers are included. Because the paper's headline claim is the first comprehensive map of OSS license management, the possibility that EC5 systematically removes a coherent cluster of relevant literature (e.g., workshop or regional-venue publications that neither cite nor are cited by the seed set) is load-bearing. I request that the authors publish the 39 EC5-excluded papers and re-run the classification on them (or otherwise demonstrate that they do not alter the map).
  2. [III.A (Search Strategy)] The search strategy is reported only at the level of two keyword groups (Table I) and the statement that queries were 'tailored to the specific rules of each database.' The actual query strings, search fields, wildcard usages, and date filters for ACM, IEEE, SpringerLink, ScienceDirect, and DBLP are not provided. For an SLR, this is a reproducibility gap: a reader cannot verify that the 7,242 retrieved records follow from the described strategy, nor can they update or replicate the review. I ask that the full per-database queries be placed in an appendix or the replication package.
  3. [III.B.1 (Full-text screening and Cohen's kappa)] The inter-rater reliability statement is internally inconsistent: the text says 'inclusion disagreements occurred in only five of the 78 reviewed papers,' yet the full-text assessment involved 178 papers, of which 100 were excluded and 78 retained. It is unclear whether the reported Cohen's kappa of 0.95 is computed over the 178 full-text papers, the 78 retained papers, or some other subset. This ambiguity affects the credibility of the screening reliability claim and should be corrected with the exact denominator.
minor comments (6)
  1. [Throughout] The phrase 'legitimate risks' is used repeatedly (e.g., Abstract, Sections I and V) where 'legal risks' or 'licensing risks' appears to be intended; please correct this terminology.
  2. [Table I] The Group 1 keyword 'software:' appears to be a formatting artifact; if the intended keyword is 'software,' please state it plainly, and describe the Boolean combination of groups (g1 AND g2) explicitly rather than informally.
  3. [Figure 1] The PRISMA flow diagram places the label 'IdentificationScreeningIncluded' awkwardly along one edge, which harms readability; consider formatting the four phases as separate labeled stages.
  4. [Section V.B, Opportunity 4] The discussion cites arXiv preprint [214] as evidence about LLM license compliance; since EC2 excludes arXiv preprints from primary studies, please clarify in the text that this citation is used as related work, not as a selected primary study.
  5. [Replication package (reference [105])] The replication package currently appears to be a single image of a literature list; a structured list of included and excluded studies (with reasons, per PRISMA) would materially improve the transparency of this SLR.
  6. [Table VII] There is a typo in the row for Di Penta et al.: 'Inaccessable' should be 'Inaccessible.'

Circularity Check

0 steps flagged · score 1.0 of 10

No significant circularity: the SLR's taxonomy is anchored to an external industry benchmark, and its synthesis does not reduce to its own inclusion criteria.

full rationale

This paper is a systematic literature review rather than a derivation, so the classical circularity failure modes do not apply. The taxonomy (license identification, license risk assessment, license risk mitigation) is explicitly anchored to an external benchmark: 'Guided by the Forrester Wave evaluation report [104], a well-established and influential industry evaluation, we selected 12 leading SCA products with license-related capabilities.' The classification of the 80 papers into the resulting twelve subcategories was performed by three independent reviewers with reported Cohen's kappa values of 0.95 for screening and 0.87 for classification, making the map a measured judgment rather than a tautology. The 'first SLR' claim is a gap assertion, not a derived result. The authors' own prior tools (e.g., LiDetector [15], LiResolver [118]) do appear among the primary studies and are cited in the synthesis; this is normal for an SLR and does not carry the argument, because the inclusion criteria, snowballing procedure, and SCA-tool-derived taxonomy are independent of those papers. The main validity concern is the EC5 CORE-venue filter, which excluded 39 full-text papers and is acknowledged in Section V.D as a filter that 'may inadvertently exclude some high-quality work.' That is a completeness risk about corpus representativeness, not circularity: the selection criteria are external to the review's conclusions, and no fitted parameter is renamed as a prediction. No circular step can be exhibited, so the appropriate finding is no significant circularity.

Assumptions & free parameters 0 free parameters · 4 assumptions · 0 invented entities

As a review, the paper introduces no free parameters and no new entities. Its load-bearing assumptions are about the completeness and representativeness of the literature corpus and the industrial tools chosen as the basis for the taxonomy.

assumptions (4)
  • domain assumption The CORE ranking is a reliable proxy for publication quality.
    EC5 excludes papers in venues not in the latest CORE ranking, so the entire corpus is filtered by this assumption. The paper cites [57] as precedent but does not validate the ranking against the license management field specifically.
  • domain assumption Searching IEEE Xplore, ACM DL, SpringerLink, ScienceDirect, and DBLP with the given keyword sets captures the relevant literature.
    The search in Section III.A defines the initial corpus. If the keyword g1 AND g2 expression or the database choice misses relevant work, the review cannot claim comprehensive coverage. Snowballing partially mitigates this, but seed-set bias remains.
  • domain assumption The 12 SCA tools selected via the Forrester Wave report adequately represent industrial license management practice.
    Section III.C builds the taxonomy from these tools. The paper notes that no comprehensive list of SCA tools exists and follows [38], but the representativeness of the chosen 12 tools is an assumption about the industry landscape.
  • domain assumption Exclusion criteria EC3 and EC6 (out-of-scope and limited relevance) can be applied reliably based on author judgment.
    The paper reports high Cohen's kappa (0.95 and 0.87), supporting internal consistency, but the criteria are inherently subjective and could exclude work that another team would include.

how reviews work

0 comments
Cite this review

Pith. "Pith review of Open Source, Hidden Costs: A Systematic Literature Review on OSS License Management." pith.science (2026). https://pith.science/paper/3QPJ3NMH

@misc{pith2026250705270,
  author       = {Pith},
  title        = {Pith review of: Open Source, Hidden Costs: A Systematic Literature Review on OSS License Management},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/3QPJ3NMH}},
  note         = {Machine review of arXiv:2507.05270}
}
read the original abstract

Integrating third-party software components is a common practice in modern software development, offering significant advantages in terms of efficiency and innovation. However, this practice is fraught with risks related to software licensing. A lack of understanding may lead to disputes, which can pose serious legal and operational challenges. To these ends, both academia and industry have conducted various investigations and proposed solutions and tools to deal with these challenges. However, significant limitations still remain. Moreover, the rapid evolution of open-source software (OSS) licenses, as well as the rapidly incorporated generative software engineering techniques, such as large language models for code (CodeLLMs), are placing greater demands on the systematic management of software license risks. To unveil the severe challenges and explore possible future directions, we conduct the first systematic literature review (SLR) on 80 carefully selected OSS license-related papers, classifying existing research into three key categories, i.e., license identification, license risk assessment, and license risk mitigation. Based on these, we discuss challenges in existing solutions, conclude the opportunities to shed light on future research directions and offer practical recommendations for practitioners. We hope this thorough review will help bridge the gaps between academia and industry and accelerate the ecosystem-wide governance of legitimate software risks within the software engineering community.

Figures

Figures reproduced from arXiv: 2507.05270 by the authors.

Figure 1
Figure 1. Overview of literature retrieval and selection process [PITH_FULL_IMAGE:figures/full_fig_p003_1.png] view at source ↗
Figure 2
Figure 2. The Overview of research works on OSS license management [PITH_FULL_IMAGE:figures/full_fig_p004_2.png] view at source ↗

Discussion (0). Sign in to comment.

Reference graph

Works this paper leans on

216 extracted references · 77 canonical work pages

  1. [214]

    Licoeval: Evaluating llms on license compliance in code generation,

    W. Xu, K. Gao, H. He, and M. Zhou, “Licoeval: Evaluating llms on license compliance in code generation,” arXiv preprint arXiv:2408.02487, 2024

  2. [1]

    A Summary of Census II: Open Source Software Application Libraries the World Depends On - Linux Foundation,

    “A Summary of Census II: Open Source Software Application Libraries the World Depends On - Linux Foundation,” https://www.linuxfound ation.org/blog/blog/a-summary-of-census-ii-open-source-software-ap plication-libraries-the-world-depends-on, [Accessed: May 9, 2025]

  3. [2]

    D ´ej`avu: a map of code duplicates on github,

    C. V . Lopes, P. Maj, P. Martins, V . Saini, D. Yang, J. Zitny, H. Sajnani, and J. Vitek, “D ´ej`avu: a map of code duplicates on github,” ACM on Programming Languages, vol. 1, no. OOPSLA, pp. 1–28, 2017

  4. [3]

    Towards exploring the code reuse from stack overflow during software devel- opment,

    Y . Huang, F. Xu, H. Zhou, X. Chen, X. Zhou, and T. Wang, “Towards exploring the code reuse from stack overflow during software devel- opment,” in 30th IEEE/ACM International Conference on Program Comprehension, 2022, pp. 548–559

  5. [4]

    GOOGLE LLC v. ORACLE AMERICA, INC

    “GOOGLE LLC v. ORACLE AMERICA, INC.” https://www.suprem ecourt.gov/opinions/20pdf/18-956 d18f.pdf, 2020, [Accessed: May 9, 2025]

  6. [5]

    Does TikTok Live Studio Violate GPL v2?

    F. E. Team, “Does TikTok Live Studio Violate GPL v2?” https://fo ssa.com/blog/does-tiktok-live-studio-violate-the-gpl-v2/, 2021, [Accessed: May 9, 2025]

  7. [6]

    We’ve filed a lawsuit challenging github copilot, an ai product that relies on unprecedented open-source software piracy,

    M. Butterick, “We’ve filed a lawsuit challenging github copilot, an ai product that relies on unprecedented open-source software piracy,” https://githubcopilotlitigation.com, 2022, [Accessed: May 9, 2025]

  8. [7]

    J. doe 1 & j. doe 2 v. github, inc., microsoft corp., openai, inc., et al

    J. Saveri, C. Zirpoli, T. Manfredi, and M. Butterick, “J. doe 1 & j. doe 2 v. github, inc., microsoft corp., openai, inc., et al.” https://gith ubcopilotlitigation.com/pdf/06823/1-0-github complaint.pdf, 2022, [Accessed: May 9, 2025]

Show all 216 references
  1. [8]

    License integration patterns: Addressing license mismatches in component-based development,

    D. M. German and A. E. Hassan, “License integration patterns: Addressing license mismatches in component-based development,” in 2009 IEEE 31st international conference on software engineering . IEEE, 2009, pp. 188–198

  2. [9]

    A large-scale empirical study of open source license usage: Practices and challenges,

    J. Wu, L. Bao, X. Yang, X. Xia, and X. Hu, “A large-scale empirical study of open source license usage: Practices and challenges,” in 2024 IEEE/ACM 21st International Conference on Mining Software Repositories. IEEE, 2024, pp. 595–606

  3. [10]

    A sentence-matching method for automatic license identification of source code files,

    D. M. German, Y . Manabe, and K. Inoue, “A sentence-matching method for automatic license identification of source code files,” in 25th IEEE/ACM International Conference on Automated Software Engineering, 2010, pp. 437–446

  4. [11]

    The fossology project,

    R. Gobeille, “The fossology project,” in 2008 international working conference on Mining software repositories , 2008, pp. 47–50

  5. [12]

    An insight into license tools for open source software systems,

    G. M. Kapitsaki, N. D. Tselikas, and I. E. Foukarakis, “An insight into license tools for open source software systems,” Journal of Systems and Software, vol. 102, pp. 72–87, 2015

  6. [13]

    Tool support for open source software license compli- ance: The first two decades of the millennium,

    T. Tuunanen, “Tool support for open source software license compli- ance: The first two decades of the millennium,” JYU dissertations , 2021

  7. [14]

    Automating the license compatibility process in open source software with spdx,

    G. M. Kapitsaki, F. Kramer, and N. D. Tselikas, “Automating the license compatibility process in open source software with spdx,” Journal of systems and software , vol. 131, pp. 386–401, 2017

  8. [15]

    Lidetector: License incompatibility detection for open source software,

    S. Xu, Y . Gao, L. Fan, Z. Liu, Y . Liu, and H. Ji, “Lidetector: License incompatibility detection for open source software,” ACM Transactions on Software Engineering and Methodology , vol. 32, no. 1, pp. 1–28, 2023

  9. [16]

    Understanding and remediating open-source license incompatibilities in the pypi ecosystem,

    W. Xu, H. He, K. Gao, and M. Zhou, “Understanding and remediating open-source license incompatibilities in the pypi ecosystem,” in 2023 38th IEEE/ACM International Conference on Automated Software Engineering (ASE), 2023, pp. 178–190

  10. [17]

    An empirical study of license conflict in free and open source software,

    X. Cui, J. Wu, Y . Wu, X. Wang, T. Luo, S. Qu, X. Ling, and M. Yang, “An empirical study of license conflict in free and open source software,” in 2023 IEEE/ACM 45th International Conference on Software Engineering: Software Engineering in Practice (ICSE-SEIP) . IEEE, 2023, pp...

  11. [18]

    A method to detect license inconsistencies in large-scale open source projects,

    Y . Wu, Y . Manabe, T. Kanda, D. M. German, and K. Inoue, “A method to detect license inconsistencies in large-scale open source projects,” in 2015 IEEE/ACM 12th Working Conference on Mining Software Repositories. IEEE, 2015, pp. 324–333. JOURNAL OF LATEX CLASS FILES, VOL. XX,...

  12. [19]

    Analysis of license inconsistency in large collections of open source projects,

    Wu, Yuhao and Manabe, Yuki and Kanda, Tetsuya and German, Daniel M and Inoue, Katsuro, “Analysis of license inconsistency in large collections of open source projects,” Empirical Software Engineering , vol. 22, pp. 1194–1222, 2017

  13. [20]

    Open source license violation check for spdx files,

    G. M. Kapitsaki and F. Kramer, “Open source license violation check for spdx files,” in Software Reuse for Dynamic Systems in the Cloud and Beyond: 14th International Conference on Software Reuse, ICSR 2015, Miami, FL, USA, January 4-6, 2015. Proceedings 14 . Springer, 2014, p...

  14. [21]

    Identifying open- source license violation and 1-day security risk at large scale,

    R. Duan, A. Bijlani, M. Xu, T. Kim, and W. Lee, “Identifying open- source license violation and 1-day security risk at large scale,” in 2017 ACM SIGSAC Conference on computer and communications security , 2017, pp. 2169–2185

  15. [22]

    A preliminary analysis of gpl-related license violations in docker images,

    Y . Higashi, K. Fukui, K. Yutaro, and M. Ohira, “A preliminary analysis of gpl-related license violations in docker images,” in 2022 IEEE International Conference on Software Analysis, Evolution and Reengineering (SANER). IEEE, 2022, pp. 444–448

  16. [23]

    Tracing software build processes to uncover license compliance inconsistencies,

    S. Van Der Burg, E. Dolstra, S. McIntosh, J. Davies, D. M. German, and A. Hemel, “Tracing software build processes to uncover license compliance inconsistencies,” in 29th ACM/IEEE international confer- ence on Automated software engineering , 2014, pp. 731–742

  17. [24]

    A method for open source license compliance of java applications,

    D. German and M. Di Penta, “A method for open source license compliance of java applications,” IEEE software , vol. 29, no. 3, pp. 58–63, 2012

  18. [25]

    Do software developers understand open source licenses?

    D. A. Almeida, G. C. Murphy, G. Wilson, and M. Hoye, “Do software developers understand open source licenses?” in 2017 IEEE/ACM 25th International Conference on Program Comprehension (ICPC) . IEEE, 2017, pp. 1–11

  19. [26]

    Investigating whether and how software developers understand open source software licensing,

    D. A. Almeida, G. C. Murphy, G. Wilson, and M. Hoye, “Investigating whether and how software developers understand open source software licensing,” Empirical Software Engineering , vol. 24, pp. 211–239, 2019

  20. [27]

    ‘the law doesn’t work like a computer’: Exploring software licensing issues faced by legal practitioners,

    N. Wintersgill, T. Stalnaker, L. A. Heymann, O. Chaparro, and D. Poshyvanyk, “‘the law doesn’t work like a computer’: Exploring software licensing issues faced by legal practitioners,” ACM on Soft- ware Engineering, vol. 1, no. FSE, pp. 882–905, 2024

  21. [28]

    Standardizing open source license compliance with openchain,

    S. Coughlan, “Standardizing open source license compliance with openchain,” Computer, vol. 53, no. 11, pp. 70–74, 2020

  22. [29]

    International Organization for Standardization and International Elec- trotechnical Commission, ISO/IEC 5230:2020 - OpenChain Specifica- tion, https://www.iso.org/standard/81039.html, ISO/IEC Std., 2020, [Accessed: May 9, 2025]

  23. [30]

    Software package data ex- change (spdx) specification,

    K. Stewart, P. Odence, and E. Rockett, “Software package data ex- change (spdx) specification,” IFOSS L. Rev., vol. 2, p. 191, 2010

  24. [31]

    Software bill of mate- rials,

    N. Telecommunications and I. Administration, “Software bill of mate- rials,” https://www.ntia.gov/page/software-bill-materials, [Accessed: May 9, 2025]

  25. [32]

    Software Supply Chain Management — Sonatype,

    “Software Supply Chain Management — Sonatype,” https://www.sona type.com/, 2024, [Accessed: May 9, 2025]

  26. [33]

    Application Security Software(AppSec) — Black Duck,

    “Application Security Software(AppSec) — Black Duck,” https://ww w.blackduck.com/, 2024, [Accessed: May 9, 2025]

  27. [34]

    Mend.io,

    “Mend.io,” https://www.mend.io/, 2025, [Accessed: May 9, 2025]

  28. [35]

    Software license management: What, why, how?

    “Software license management: What, why, how?” https://cdn.openlm .com/wp-content/uploads/2023/01/Whitepaper-Software-License- Management-What-Why-How-By-OpenLM-2.pdf, 2022, [Accessed: May 9, 2025]

  29. [36]

    Open-source license - Wikipedia,

    “Open-source license - Wikipedia,” https://en.wikipedia.org/wiki/Open -source license, Nov. 2024, [Accessed: May 9, 2025]

  30. [37]

    License proliferation - Wikipedia,

    “License proliferation - Wikipedia,” https://en.wikipedia.org/wiki/Lice nse proliferation, Nov. 2023, [Accessed: May 9, 2025]

  31. [38]

    2024 Open Source Security and Risk Analysis (OSSRA) Report,

    Synopsys, “2024 Open Source Security and Risk Analysis (OSSRA) Report,” https://www.blackduck.com/content/dam/black-duck/en-us/r eports/rep-ossra-2024.pdf, 2024, accessed on 11/26/2024

  32. [39]

    License compatibility - Wikipedia,

    “License compatibility - Wikipedia,” https://en.wikipedia.org/wiki/Li cense compatibility, [Accessed: May 9, 2025]

  33. [40]

    LICENSE COMPLIANCE – A COMPLETE GUIDE,

    F. Filipsson, “LICENSE COMPLIANCE – A COMPLETE GUIDE,” https://redresscompliance.com/license-compliance-a-complete-guide/, Jan. 2024, [Accessed: May 9, 2025]

  34. [41]

    Managing license compliance in free and open source software development,

    G. Gangadharan, V . D’Andrea, S. De Paoli, and M. Weiss, “Managing license compliance in free and open source software development,” Information Systems Frontiers, vol. 14, pp. 143–154, 2012

  35. [42]

    Predicting licenses for changed source code,

    X. Liu, L. Huang, J. Ge, and V . Ng, “Predicting licenses for changed source code,” in 2019 34th IEEE/ACM International Conference on Automated Software Engineering (ASE) . IEEE, 2019, pp. 686–697

  36. [43]

    Catch the butterfly: Peeking into the terms and conflicts among spdx licenses,

    T. Liu, C. Liu, T. Liu, H. Wang, G. Wu, Y . Liu, and Y . Zhang, “Catch the butterfly: Peeking into the terms and conflicts among spdx licenses,” in 2024 IEEE International Conference on Software Analysis, Evolution and Reengineering (SANER) . IEEE, 2024

  37. [44]

    License Exceptions - Software Package Data Exchange,

    “License Exceptions - Software Package Data Exchange,” https://spdx .org/licenses/exceptions-index.html, [Accessed: May 9, 2025]

  38. [45]

    GPL linking exception - Wikipedia,

    “GPL linking exception - Wikipedia,” https://en.wikipedia.org/wiki/ GPL linking exception, 2025, [Accessed: May 9, 2025]

  39. [46]

    Guidelines for performing systematic literature reviews in software engineering,

    B. Kitchenham and S. Charters, “Guidelines for performing systematic literature reviews in software engineering,” Technical report, ver. 2.3 ebse technical report. ebse, Tech. Rep., 2007

  40. [47]

    Guidelines for snowballing in systematic literature studies and a replication in software engineering,

    C. Wohlin, “Guidelines for snowballing in systematic literature studies and a replication in software engineering,” in 18th international con- ference on evaluation and assessment in software engineering , 2014, pp. 1–10

  41. [48]

    Static analysis of android apps: A systematic literature review,

    L. Li, T. F. Bissyand ´e, M. Papadakis, S. Rasthofer, A. Bartel, D. Octeau, J. Klein, and L. Traon, “Static analysis of android apps: A systematic literature review,” Information and Software Technology , vol. 88, pp. 67–95, 2017

  42. [49]

    Research on third-party libraries in android apps: A taxonomy and systematic literature review,

    X. Zhan, T. Liu, L. Fan, L. Li, S. Chen, X. Luo, and Y . Liu, “Research on third-party libraries in android apps: A taxonomy and systematic literature review,” IEEE Transactions on Software Engineering , 2021

  43. [50]

    Prisma2020: An r package and shiny app for producing prisma 2020-compliant flow diagrams, with interactivity for optimised digital transparency and open synthesis,

    N. R. Haddaway, M. J. Page, C. C. Pritchard, and L. A. McGuinness, “Prisma2020: An r package and shiny app for producing prisma 2020-compliant flow diagrams, with interactivity for optimised digital transparency and open synthesis,”Campbell systematic reviews, vol. 18, no. 2, ...

  44. [51]

    ACM Digital Library,

    “ACM Digital Library,” https://dl.acm.org, [Accessed: May 9, 2025]

  45. [52]

    IEEE Xplore Digital Library,

    “IEEE Xplore Digital Library,” https://ieeexplore.ieee.org/Xplore/hom e.jsp, [Accessed: May 9, 2025]

  46. [53]

    SpringerLink,

    “SpringerLink,” https://link.springer.com, [Accessed: May 9, 2025]

  47. [54]

    ScienceDirect,

    “ScienceDirect,” https://www.sciencedirect.com, [Accessed: May 9, 2025]

  48. [55]

    “dblp,” https://dblp.org, [Accessed: May 9, 2025]

  49. [56]

    Google Scholar,

    “Google Scholar,” https://scholar.google.com/, [Accessed: May 9, 2025]

  50. [57]

    Data preparation for software vulnerability prediction: A systematic literature review,

    R. Croft, Y . Xie, and M. A. Babar, “Data preparation for software vulnerability prediction: A systematic literature review,” IEEE Trans- actions on Software Engineering , vol. 49, no. 3, pp. 1044–1063, 2022

  51. [58]

    ICORE Conference Portal,

    “ICORE Conference Portal,” https://portal.core.edu.au/conf-ranks/, [Accessed: May 9, 2025]

  52. [59]

    CORE Journal Ranking Portal,

    “CORE Journal Ranking Portal,” https://portal.core.edu.au/jnl-ranks/, [Accessed: May 9, 2025]

  53. [60]

    Code siblings: Technical and legal implications of copying code between applications,

    D. M. German, M. Di Penta, Y .-G. Gueheneuc, and G. Antoniol, “Code siblings: Technical and legal implications of copying code between applications,” in 2009 6th IEEE International Working Conference on Mining Software Repositories . IEEE, 2009, pp. 81–90

  54. [61]

    The impact of project licence and operating system on the effectiveness of the defect-fixing process in open source software projects,

    A. H. Ghapanchi and A. Aurum, “The impact of project licence and operating system on the effectiveness of the defect-fixing process in open source software projects,” International Journal of Business Information Systems, vol. 8, no. 4, pp. 413–424, 2011

  55. [62]

    Open Source License Compliance Software For Eradicating Risks,

    “Open Source License Compliance Software For Eradicating Risks,” https://www.sonatype.com/solutions/legal-open-source-license-compl iance, 2024, [Accessed: May 9, 2025]

  56. [63]

    Government intervention, the rise of the SBOM and the evolution of software supply chain security,

    “Government intervention, the rise of the SBOM and the evolution of software supply chain security,” https://www.sonatype.com/hubfs/Whi te Papers/Rise of SBOM and evolution of SSC security.pdf, 2023, [Accessed: May 9, 2025]

  57. [64]

    License Policy Governance,

    “License Policy Governance,” https://help.sonatype.com/en/license-pol icy-governance.html, [Accessed: May 9, 2025]

  58. [65]

    Black Duck Software Composition Analysis,

    “Black Duck Software Composition Analysis,” https://www.blackduck. com/software-composition-analysis-tools/black-duck-sca.html, 2025, [Accessed: May 9, 2025]

  59. [66]

    Open Source License Compliance,

    “Open Source License Compliance,” https://www.blackduck.com/solu tions/open-source-security.html, 2024, [Accessed: May 9, 2025]

  60. [67]

    Managing open source licenses,

    “Managing open source licenses,” https://documentation.blackduck.co m/bundle/bd-hub/page/Licenses/Overview LicenseProcess.html, 2025, [Accessed: May 9, 2025]

  61. [68]

    Black Duck: Managing Deep License Data,

    “Black Duck: Managing Deep License Data,” https://community.blac kduck.com/s/article/Black-Duck-Managing-Deep-License-Data, 2025, [Accessed: May 9, 2025]

  62. [69]

    Managing open source licenses,

    “Managing open source licenses,” https://documentation.blackduc k.com/bundle/bd-hub/page/Licenses/ConflictsAbout.html, 2025, [Accessed: May 9, 2025]

  63. [70]

    Open source license compliance,

    “Open source license compliance,” https://www.mend.io/open-source- license-compliance/, 2025, [Accessed: May 9, 2025]

  64. [71]

    The License Compatibility Report,

    “The License Compatibility Report,” https://docs.mend.io/legacy-sca/ latest/the-license-compatibility-report, 2025, [Accessed: May 9, 2025]. JOURNAL OF LATEX CLASS FILES, VOL. XX, NO. XX, JUNE 2025 20

  65. [72]

    License attribution for modified transitive dependencies,

    “License attribution for modified transitive dependencies,” https://do cs.mend.io/wsk/license-attribution-for-modified-transitive-depend, 2025, [Accessed: May 9, 2025]

  66. [73]

    Understanding Risk Score Attribution and License Analysis,

    “Understanding Risk Score Attribution and License Analysis,” https: //docs.mend.io/platform/latest/understanding-risk-score-attribution-an d-license-a, 2025, [Accessed: May 9, 2025]

  67. [74]

    Creating Policies for Mend Repository License Checks,

    “Creating Policies for Mend Repository License Checks,” https://docs .mend.io/wsk/creating-policies-for-mend-repository-license-chec, 2025, [Accessed: May 9, 2025]

  68. [75]

    Licenses and Libraries API,

    “Licenses and Libraries API,” https://docs.mend.io/legacy-sca/latest/l icenses-and-libraries-api, 2025, [Accessed: May 9, 2025]

  69. [76]

    Application Security for the AI Era,

    “Application Security for the AI Era,” https://www.veracode.com/, 2025, [Accessed: May 9, 2025]

  70. [77]

    Custom rules for agent-based scanning,

    “Custom rules for agent-based scanning,” https://docs.veracode.com/r/ c sc policies custom, 2025, [Accessed: May 9, 2025]

  71. [78]

    Mitigate license risk with Veracode SCA,

    “Mitigate license risk with Veracode SCA,” https://docs.veracode.com/ r/Mitigate License Risk with Veracode SCA, 2025, [Accessed: May 9, 2025]

  72. [79]

    “Snyk,” https://snyk.io/, 2025, [Accessed: May 9, 2025]

  73. [80]

    Open Source License Compliance Management — Snyk,

    “Open Source License Compliance Management — Snyk,” https://sn yk.io/product/open-source-security-management/license-compliance/, 2025, [Accessed: May 9, 2025]

  74. [81]

    Snyk License Compliance Management,

    “Snyk License Compliance Management,” https://docs.snyk.io/scan-wi th-snyk/snyk-open-source/scan-open-source-libraries-and-licenses/sny k-license-compliance-management, 2025, [Accessed: May 9, 2025]

  75. [82]

    Checkmarx,

    “Checkmarx,” https://checkmarx.com/, 2025, [Accessed: May 9, 2025]

  76. [83]

    Generating a CxOSA Scan Results Report - License Risk and Com- pliance,

    “Generating a CxOSA Scan Results Report - License Risk and Com- pliance,” https://docs.checkmarx.com/en/34965-46899-generating-a-c xosa-scan-results-report.html#UUID-7616620b-e23c-bd31-f233-89a 93a1b5c19 id GeneratingaCxOSAScanResultsReport-LicenseRiskan dCompliance, 2025, [Ac...

  77. [84]

    Everything You Need to Mitigate Open Source Risk,

    “Everything You Need to Mitigate Open Source Risk,” https://chec kmarx.com/cxsca-open-source-scanning/, 2025, [Accessed: May 9, 2025]

  78. [85]

    Triaging SCA Results,

    “Triaging SCA Results,” https://docs.checkmarx.com/en/34965-2492 23-triaging-sca-results.html#UUID-945497b2-9333-f98f-72d8-21a8 a9c31f6a, 2025, [Accessed: May 9, 2025]

  79. [86]

    Revenera,

    “Revenera,” https://www.revenera.com/, 2025, [Accessed: May 9, 2025]

  80. [87]

    Continuous Open Source Software License Compliance,

    “Continuous Open Source Software License Compliance,” https://ww w.revenera.com/software-composition-analysis/business-solutions/op en-source-license-compliance, 2025, [Accessed: May 9, 2025]

  81. [88]

    Automate Attribution Fulfillment via Third-Party Notices Generation,

    “Automate Attribution Fulfillment via Third-Party Notices Generation,” https://www.revenera.com/sites/default/files/fnci-oss-third-party-noti ces.pdf, 2022, [Accessed: May 9, 2025]

  82. [89]

    Technical Due Diligence for Mergers & Acquisitions (M&A),

    “Technical Due Diligence for Mergers & Acquisitions (M&A),” https: //www.revenera.com/software-composition-analysis/audits-and-servic es/m-a-support, 2024, [Accessed: May 9, 2025]

  83. [90]

    Yaakov, “JFrog,” https://jfrog.com/, 2024, [Accessed: May 9, 2025]

    E. Yaakov, “JFrog,” https://jfrog.com/, 2024, [Accessed: May 9, 2025]

  84. [91]

    Get Your License Compliance Reports with a Click of a Button,

    E. Yaakov, “Get Your License Compliance Reports with a Click of a Button,” https://jfrog.com/blog/get-your-license-compliance-reports-w ith-a-click-of-a-button/, 2018, [Accessed: May 9, 2025]

  85. [92]

    Managing Compliance Licenses,

    “Managing Compliance Licenses,” https://jfrog.com/help/r/jfrog-secur ity-user-guide/products/xray/features-and-capabilities/sca/legal, 2024, (Accessed on 11/11/2024)

  86. [93]

    Palo Alto Networks,

    “Palo Alto Networks,” https://www.paloaltonetworks.com/, 2025, [Accessed: May 9, 2025]

  87. [94]

    License Compliance in Software Composition Analysis (SCA),

    “License Compliance in Software Composition Analysis (SCA),” https: //docs.prismacloud.io/en/enterprise-edition/content-collections/applicat ion-security/risk-management/monitor-and-manage-code-build/softw are-composition-analysis/license-compliance-in-sca, 2024, [Accessed: Ma...

  88. [95]

    “GitHub,” https://github.com/, 2025, [Accessed: May 9, 2025]

  89. [96]

    Dependabot quickstart guide - GitHub Docs,

    “Dependabot quickstart guide - GitHub Docs,” https://docs.github.co m/en/code-security/getting-started/dependabot-quickstart-guide, 2025, [Accessed: May 9, 2025]

  90. [97]

    Licensing a repository - GitHub Docs,

    “Licensing a repository - GitHub Docs,” https://docs.github.com/en/r epositories/managing-your-repositorys-settings-and-features/customiz ing-your-repository/licensing-a-repository, 2025, [Accessed: May 9, 2025]

  91. [98]

    “GitLab,” https://gitlab.com/gitlab-com, 2025, [Accessed: May 9, 2025]

  92. [99]

    GitLab Licensing and Compatibility,

    “GitLab Licensing and Compatibility,” https://docs.gitlab.com/ee/dev elopment/licensing.html, 2025, [Accessed: May 9, 2025]

  93. [100]

    License approval policies,

    “License approval policies,” https://docs.gitlab.com/ee/user/complian ce/license approval policies.html, 2025, [Accessed: May 9, 2025]

  94. [101]

    Aqua Cloud Native Security, Container & Serverless Security,

    “Aqua Cloud Native Security, Container & Serverless Security,” https: //www.aquasec.com/, 2025, [Accessed: May 9, 2025]

  95. [102]

    5 Open Source Licenses and Compliance Risks to Know About,

    “5 Open Source Licenses and Compliance Risks to Know About,” https://www.aquasec.com/cloud-native-academy/supply-chain-se curity/open-source-license/, 2022, [Accessed: May 9, 2025]

  96. [103]

    What Is Open Source Security?

    “What Is Open Source Security?” https://www.aquasec.com/cloud-na tive-academy/devsecops/open-source-security/, 2025, [Accessed: May 9, 2025]

  97. [104]

    The Forrester Wave™: Software Composition Analysis, Q2 2023,

    J. Worthington, A. DeMartine, D. Beaton, and P. Harrison, “The Forrester Wave™: Software Composition Analysis, Q2 2023,” https: //www.forrester.com/report/the-forrester-wave-tm-software-composit ion-analysis-q2-2023/RES178483, 2023, [Accessed: May 9, 2025]

  98. [105]

    Github - lby2001/replication-package-of-oss-license-slr/literature list.png,

    “Github - lby2001/replication-package-of-oss-license-slr/literature list.png,” https://github.com/LBY2001/Replication-Package-of-OSS- License-SLR/blob/master/Literature%20List.png, 2025, [Accessed: May 9, 2025]

  99. [106]

    Automated software license analysis,

    T. Tuunanen, J. Koskinen, and T. K ¨arkk¨ainen, “Automated software license analysis,” Automated Software Engineering , vol. 16, pp. 455– 490, 2009

  100. [107]

    Github - fossology/fossology/src/nomos,

    “Github - fossology/fossology/src/nomos,” https://github.com/fossolo gy/fossology/tree/master/src/nomos, [Accessed: May 9, 2025]

  101. [108]

    Hierarchical clustering of oss license statements toward automatic generation of license rules,

    Y . Higashi, M. Ohira, Y . Kashiwa, and Y . Manabe, “Hierarchical clustering of oss license statements toward automatic generation of license rules,” Journal of information processing , vol. 27, pp. 42–50, 2019

  102. [109]

    Automating license rule generation to help maintain rule-based oss license identification tools,

    Y . Higashi, M. Ohira, and Y . Manabe, “Automating license rule generation to help maintain rule-based oss license identification tools,” Journal of Information Processing , vol. 31, pp. 2–12, 2023

  103. [110]

    Efficient string matching: an aid to bibliographic search,

    A. V . Aho and M. J. Corasick, “Efficient string matching: an aid to bibliographic search,” Commun. ACM, vol. 18, no. 6, p. 333–340, Jun

  104. [111]

    Identifying licensing of jar archives using a code-search approach,

    M. Di Penta, D. M. German, and G. Antoniol, “Identifying licensing of jar archives using a code-search approach,” in 2010 7th IEEE Working Conference on Mining Software Repositories , 2010, pp. 151–160

  105. [112]

    Automatic checking of license compliance,

    H. Zhang, B. Shi, and L. Zhang, “Automatic checking of license compliance,” in 2010 IEEE International Conference on Software Maintenance. IEEE, 2010, pp. 1–3

  106. [113]

    Sorrel: an ide plugin for managing licenses and detecting license incompatibilities,

    D. Pogrebnoy, I. Kuznetsov, Y . Golubev, V . Tankov, and T. Bryksin, “Sorrel: an ide plugin for managing licenses and detecting license incompatibilities,” in 2021 IEEE International Conference on Software Maintenance and Evolution (ICSME) . IEEE, 2021, pp. 574–578

  107. [114]

    Open source license inconsistencies on github,

    T. Wolter, A. Barcomb, D. Riehle, and N. Harutyunyan, “Open source license inconsistencies on github,” ACM Transactions on Software Engineering and Methodology , vol. 32, no. 5, pp. 1–23, 2023

  108. [115]

    Machine learning-based detection of open source license exceptions,

    C. Vendome, M. Linares-V ´asquez, G. Bavota, M. Di Penta, D. German, and D. Poshyvanyk, “Machine learning-based detection of open source license exceptions,” in 2017 IEEE/ACM 39th International Conference on Software Engineering (ICSE) . IEEE, 2017, pp. 118–129

  109. [116]

    Identifying terms in open source software license texts,

    G. M. Kapitsaki and D. Paschalides, “Identifying terms in open source software license texts,” in 2017 24th Asia-Pacific Software Engineering Conference (APSEC). IEEE, 2017, pp. 540–545

  110. [117]

    Lisum: Open source software license summarization with multi- task learning,

    L. Li, S. Xu, Y . Liu, Y . Gao, X. Cai, J. Wu, W. Song, and Z. Liu, “Lisum: Open source software license summarization with multi- task learning,” in 2023 38th IEEE/ACM International Conference on Automated Software Engineering (ASE) . IEEE, 2023, pp. 787–799

  111. [118]

    LiResolver: License incompatibility resolution for open source software,

    S. Xu, Y . Gao, L. Fan, L. Li, X. Cai, and Z. Liu, “LiResolver: License incompatibility resolution for open source software,” in 32nd ACM SIGSOFT International Symposium on Software Testing and Analysis , 2023, pp. 652–663

  112. [119]

    Clustering oss license state- ments toward automatic generation of license rules,

    Y . Higashi, Y . Manabe, and M. Ohira, “Clustering oss license state- ments toward automatic generation of license rules,” in 2016 7th International Workshop on Empirical Software Engineering in Practice (IWESEP), 2016, pp. 30–35

  113. [120]

    GitHub - fossology/fossology/wiki/Monk,

    “GitHub - fossology/fossology/wiki/Monk,” https://github.com/fossolo gy/fossology/wiki/Monk, [Accessed: May 9, 2025]

  114. [121]

    An analysis of open source software licensing questions in stack exchange sites,

    M. Papoutsoglou, G. M. Kapitsaki, D. German, and L. Angelis, “An analysis of open source software licensing questions in stack exchange sites,” Journal of Systems and Software , vol. 183, p. 111113, 2022

  115. [122]

    Understanding the usage, impact, and adoption of non-osi approved licenses,

    R. Meloca, G. Pinto, L. Baiser, M. Mattos, I. Polato, I. Wiese, and D. M. German, “Understanding the usage, impact, and adoption of non-osi approved licenses,” in 2018 IEEE/ACM 15th International Conference on Mining Software Repositories , 2018, pp. 270–280

  116. [123]

    Label-specific document representation for multi-label text classification,

    L. Xiao, X. Huang, B. Chen, and L. Jing, “Label-specific document representation for multi-label text classification,” in 2019 conference on empirical methods in natural language processing and the 9th in- ternational joint conference on natural language processing (EMNLP- IJC...

  117. [124]

    [Online]

    SPDX License List , The Linux Foundation, 2024, (Accessed on 2/08/2024). [Online]. Available: https://spdx.org/licenses/

  118. [125]

    License tracing in free, open, and proprietary software,

    P. Nordquist, A. Petersen, and A. Todorova, “License tracing in free, open, and proprietary software,” Journal of Computing Sciences in Colleges, vol. 19, no. 2, pp. 101–112, 2003

  119. [126]

    Analyzing open source license compatibility issues with carneades,

    T. F. Gordon, “Analyzing open source license compatibility issues with carneades,” in 13th International Conference on Artificial Intelligence and Law, 2011, pp. 51–55

  120. [127]

    Com- bining software interrelationship data across heterogeneous software repositories,

    N. Ilo, J. Grabner, T. Artner, M. Bernhart, and T. Grechenig, “Com- bining software interrelationship data across heterogeneous software repositories,” in 2015 IEEE International Conference on Software Maintenance and Evolution (ICSME) . IEEE, 2015, pp. 571–575

  121. [128]

    Open-source license compliance in software supply chains,

    D. Riehle and N. Harutyunyan, “Open-source license compliance in software supply chains,” in Towards Engineering Free/Libre Open Source Software (FLOSS) Ecosystems for Impact and Sustainability: Communications of NII Shonan Meetings . Springer, 2019, pp. 83–95

  122. [129]

    Open source software governance: A case study evaluation of supply chain management best practices,

    N. Harutyunyan and D. Riehle, “Open source software governance: A case study evaluation of supply chain management best practices,” 2023

  123. [130]

    A knowledge- driven framework for software supply chain security analysis,

    Z. Sun, Z. Quan, S. Yu, L. Zhang, and D. Mao, “A knowledge- driven framework for software supply chain security analysis,” in 2024 8th International Conference on Control Engineering and Artificial Intelligence, 2024, pp. 267–272

  124. [131]

    Understanding and audit- ing the licensing of open source software distributions,

    D. M. German, M. Di Penta, and J. Davies, “Understanding and audit- ing the licensing of open source software distributions,” in 2010 IEEE 18th International Conference on Program Comprehension . IEEE, 2010, pp. 84–93

  125. [132]

    An empirical study of license violations in open source projects,

    A. Mathur, H. Choudhary, P. Vashist, W. Thies, and S. Thilagam, “An empirical study of license violations in open source projects,” in 2012 35th Annual IEEE Software Engineering Workshop . IEEE, 2012, pp. 168–176

  126. [133]

    On the detection of licenses violations in the android ecosystem,

    O. Mlouki, F. Khomh, and G. Antoniol, “On the detection of licenses violations in the android ecosystem,” in 2016 IEEE 23rd Interna- tional Conference on Software Analysis, Evolution, and Reengineering (SANER), vol. 1. IEEE, 2016, pp. 382–392

  127. [134]

    Empirical study on dependency- related license violation in the javascript package ecosystem,

    S. Qiu, D. M. German, and K. Inoue, “Empirical study on dependency- related license violation in the javascript package ecosystem,” Journal of Information Processing , vol. 29, pp. 296–304, 2021

  128. [135]

    From one to hundreds: multi-licensing in the javascript ecosystem,

    J. P. Moraes, I. Polato, I. Wiese, F. Saraiva, and G. Pinto, “From one to hundreds: multi-licensing in the javascript ecosystem,” Empirical Software Engineering, vol. 26, pp. 1–29, 2021

  129. [136]

    Prevalence and evolution of license violations in npm and rubygems dependency networks,

    I. S. Makari, A. Zerouali, and C. De Roover, “Prevalence and evolution of license violations in npm and rubygems dependency networks,” in International Conference on Software and Software Reuse . Springer, 2022, pp. 85–100

  130. [137]

    Analyzing foss license usage in publicly available software at scale via the swh-analytics framework,

    A. Antelmi, M. Torquati, G. Corridori, D. Gregori, F. Polzella, G. Spinatelli, and M. Aldinucci, “Analyzing foss license usage in publicly available software at scale via the swh-analytics framework,” The Journal of Supercomputing , pp. 1–35, 2024

  131. [138]

    Presenting software license conflicts through argumentation,

    T. A. Alspaugh, H. U. Asuncion, and W. Scacchi, “Presenting software license conflicts through argumentation,” 23rd International Confer- ence on Software Engineering and Knowledge Engineering (SEKE 2011), pp. 35–40, 2011

  132. [139]

    Licenserec: Knowledge based open source license recommendation for oss projects,

    W. Xu, X. Wu, R. He, and M. Zhou, “Licenserec: Knowledge based open source license recommendation for oss projects,” in 2023 IEEE/ACM 45th International Conference on Software Engineering (ICSE-Companion). IEEE, 2023, pp. 180–183

  133. [140]

    Osadl open source license checklists: Osadl - open source automation development lab eg,

    O. S. A. D. L. contributors, “Osadl open source license checklists: Osadl - open source automation development lab eg,” https://www.os adl.org/OSADL-Open-Source-License-Checklists.oss-compliance-list s.0.html, 2024, [Accessed: May 9, 2025]

  134. [141]

    Github - osslab-pku/reclicense/backend/app/knowledgebase/compatibi- lity 63.csv,

    “Github - osslab-pku/reclicense/backend/app/knowledgebase/compatibi- lity 63.csv,” https://github.com/osslab-pku/RecLicense/blob/master/b ackend/app/knowledgebase/compatibility 63.csv, [Accessed: May 9, 2025]

  135. [142]

    Analyzing software licenses in open architecture software systems,

    T. A. Alspaugh, H. U. Asuncion, and W. Scacchi, “Analyzing software licenses in open architecture software systems,” in 2009 ICSE Work- shop on Emerging Trends in Free/Libre/Open Source Software Research and Development. IEEE, 2009, pp. 54–57

  136. [143]

    Intellectual property rights requirements for heterogeneously-licensed systems,

    T. A. Alspaugh, H. U. Asuncion, and W. Scacchi, “Intellectual property rights requirements for heterogeneously-licensed systems,” in 2009 17th IEEE International Requirements Engineering Conference. IEEE, 2009, pp. 24–33

  137. [144]

    Ip license agreement: Sublicensing clause,

    “Ip license agreement: Sublicensing clause,” https://uk.practicallaw.th omsonreuters.com/w-002-9143?transitionType=Default&contextData =(sc.Default)&firstPage=true, 2025, [Accessed: May 9, 2025]

  138. [145]

    Choose an open source license

    “Choose an open source license.” https://choosealicense.com/, 2025, [Accessed: May 9, 2025]

  139. [146]

    Software Licenses in Plain English,

    F. Inc., “Software Licenses in Plain English,” https://tldrlegal.com/, 2025, [Accessed: May 9, 2025]

  140. [147]

    License Show Room,

    K. Gao, Q. Ma, Z. Li, Z. Zheng, and C. Yang, “License Show Room,” https://compliance.openeuler.org/, 2025, [Accessed: May 9, 2025]

  141. [148]

    Copyleft - Wikipedia,

    “Copyleft - Wikipedia,” https://en.wikipedia.org/wiki/Copyleft, 2025, [Accessed: May 9, 2025]

  142. [149]

    Guilty or not guilty: Using clone metrics to determine open source licensing violations,

    A. Monden, S. Okahara, Y . Manabe, and K. Matsumoto, “Guilty or not guilty: Using clone metrics to determine open source licensing violations,” IEEE software, vol. 28, no. 2, pp. 42–47, 2010

  143. [150]

    Multi-language and heterogeneously-licensed software analysis,

    F. Boughanmi, “Multi-language and heterogeneously-licensed software analysis,” in 2010 17th working conference on reverse engineering . IEEE, 2010, pp. 293–296

  144. [151]

    Stack overflow: A code laundering platform?

    L. An, O. Mlouki, F. Khomh, and G. Antoniol, “Stack overflow: A code laundering platform?” in 2017 IEEE 24th International Conference on Software Analysis, Evolution and Reengineering (SANER) . IEEE, 2017, pp. 283–293

  145. [152]

    Code reuse in stack overflow and popular open source java projects,

    A. Lotter, S. A. Licorish, B. T. R. Savarimuthu, and S. Meldrum, “Code reuse in stack overflow and popular open source java projects,” in 2018 25th Australasian Software Engineering Conference (ASWEC). IEEE, 2018, pp. 141–150

  146. [153]

    Usage and attribution of stack overflow code snippets in github projects,

    S. Baltes and S. Diehl, “Usage and attribution of stack overflow code snippets in github projects,” Empirical Software Engineering , vol. 24, no. 3, pp. 1259–1295, 2019

  147. [154]

    Toxic code snippets on stack overflow,

    C. Ragkhitwetsagul, J. Krinke, M. Paixao, G. Bianco, and R. Oliveto, “Toxic code snippets on stack overflow,” IEEE Transactions on Soft- ware Engineering, vol. 47, no. 3, pp. 560–581, 2019

  148. [155]

    A study of potential code borrowing and license violations in java projects on github,

    Y . Golubev, M. Eliseeva, N. Povarov, and T. Bryksin, “A study of potential code borrowing and license violations in java projects on github,” in 17th International Conference on Mining Software Repositories, 2020, pp. 54–64

  149. [156]

    Efficient prior publication identification for open source code,

    D. Serafini and S. Zacchiroli, “Efficient prior publication identification for open source code,” in 18th International Symposium on Open Collaboration, 2022, pp. 1–8

  150. [157]

    To what extent do deep learning-based code recommenders generate predictions by cloning code from the training set?

    M. Ciniselli, L. Pascarella, and G. Bavota, “To what extent do deep learning-based code recommenders generate predictions by cloning code from the training set?” in 19th International Conference on Mining Software Repositories , 2022, pp. 167–178

  151. [158]

    Codeipprompt: intellectual property infringement assessment of code language models,

    Z. Yu, Y . Wu, N. Zhang, C. Wang, Y . V orobeychik, and C. Xiao, “Codeipprompt: intellectual property infringement assessment of code language models,” in International Conference on Machine Learning . PMLR, 2023, pp. 40 373–40 389

  152. [159]

    Generative ai for code generation: Software reuse implications,

    G. M. Kapitsaki, “Generative ai for code generation: Software reuse implications,” in International Conference on Software and Software Reuse. Springer, 2024, pp. 37–47

  153. [160]

    Modelgo: A practical tool for machine learning license analysis,

    M. Duan, Q. Li, and B. He, “Modelgo: A practical tool for machine learning license analysis,” in ACM on Web Conference 2024, 2024, pp. 1158–1169

  154. [161]

    Fast approximate matching of programs for protecting libre/open source software by using spatial indexes,

    A. J. M. Molina and T. Shinohara, “Fast approximate matching of programs for protecting libre/open source software by using spatial indexes,” in Seventh IEEE International Working Conference on Source Code Analysis and Manipulation (SCAM) . IEEE, 2007, pp. 111–122

  155. [162]

    Finding software license violations through binary code clone detection,

    A. Hemel, K. T. Kalleberg, R. Vermaas, and E. Dolstra, “Finding software license violations through binary code clone detection,” in 8th Working Conference on Mining Software Repositories , 2011, pp. 63–72

  156. [163]

    Open-source license violations of binary software at large scale,

    M. Feng, W. Mao, Z. Yuan, Y . Xiao, G. Ban, W. Wang, S. Wang, Q. Tang, J. Xu, H. Su et al., “Open-source license violations of binary software at large scale,” in 2019 IEEE 26th International Conference on Software Analysis, Evolution and Reengineering (SANER) . IEEE, 2019, pp...

  157. [164]

    Osldetector: Identifying open-source libraries through binary analysis,

    D. Zhang, P. Luo, W. Tang, and M. Zhou, “Osldetector: Identifying open-source libraries through binary analysis,” in 35th IEEE/ACM International Conference on Automated Software Engineering , 2020, pp. 1312–1315

  158. [165]

    Who are source code contributors and how do they change?

    M. Di Penta and D. M. German, “Who are source code contributors and how do they change?” in 2009 16th Working Conference on Reverse Engineering. IEEE, 2009, pp. 11–20

  159. [166]

    An exploratory study of the evolution of software licensing,

    M. Di Penta, D. M. German, Y .-G. Gu ´eh´eneuc, and G. Antoniol, “An exploratory study of the evolution of software licensing,” in 32nd ACM/IEEE International Conference on Software Engineering-Volume 1, 2010, pp. 145–154

  160. [167]

    License usage and changes: a large-scale study of java projects on github,

    C. Vendome, M. Linares-V ´asquez, G. Bavota, M. Di Penta, D. German, and D. Poshyvanyk, “License usage and changes: a large-scale study of java projects on github,” in 2015 IEEE 23rd International Conference on Program Comprehension. IEEE, 2015, pp. 218–228. JOURNAL OF LATEX C...

  161. [168]

    License usage and changes: a large-scale study on github,

    C. Vendome, G. Bavota, M. D. Penta, M. Linares-V ´asquez, D. German, and D. Poshyvanyk, “License usage and changes: a large-scale study on github,” Empirical Software Engineering , vol. 22, pp. 1537–1577, 2017

  162. [169]

    Applying the universal version history concept to help de-risk copy-based code reuse,

    D. Reid and A. Mockus, “Applying the universal version history concept to help de-risk copy-based code reuse,” in 2023 IEEE 23rd International Working Conference on Source Code Analysis and Ma- nipulation (SCAM). IEEE, 2023, pp. 1–12

  163. [170]

    Stack Exchange and Stack Overflow have moved to CC BY-SA 4.0,

    “Stack Exchange and Stack Overflow have moved to CC BY-SA 4.0,” https://meta.stackexchange.com/questions/333089/stack-exchange-and -stack-overflow-have-moved-to-cc-by-sa-4-0, Sep. 2019, [Accessed: May 9, 2025]

  164. [171]

    Open source legality patterns: architectural design decisions motivated by legal concerns,

    I. Hammouda, T. Mikkonen, V . Oksanen, and A. Jaaksi, “Open source legality patterns: architectural design decisions motivated by legal concerns,” in 14th International Academic MindTrek Conference: Envisioning Future Media Environments , 2010, pp. 207–214

  165. [172]

    Understanding the role of licenses and evolution in open architecture software ecosystems,

    W. Scacchi and T. A. Alspaugh, “Understanding the role of licenses and evolution in open architecture software ecosystems,” Journal of Systems and Software , vol. 85, no. 7, pp. 1479–1494, 2012

  166. [173]

    A floss license-selection methodology for cloud comput- ing projects,

    R. Viseur, “A floss license-selection methodology for cloud comput- ing projects,” in International Conference on Cloud Computing and Services Science, vol. 2. SCITEPRESS, 2016, pp. 129–136

  167. [174]

    Assisting developers with license compliance,

    C. Vendome and D. Poshyvanyk, “Assisting developers with license compliance,” in 38th International Conference on Software Engineer- ing Companion, 2016, pp. 811–814

  168. [175]

    Modeling and recommend- ing open source licenses with findosslicense,

    G. M. Kapitsaki and G. Charalambous, “Modeling and recommend- ing open source licenses with findosslicense,” IEEE Transactions on Software Engineering, vol. 47, no. 5, pp. 919–935, 2019

  169. [176]

    Your “notice

    K. Huang, Y . Xia, B. Chen, S. He, H. Zeng, Z. Zhou, J. Guo, and X. Peng, “Your “notice” is missing: Detecting and fixing violations of modification terms in open source licenses during forking,” in 33rd ACM SIGSOFT International Symposium on Software Testing and Analysis, 202...

  170. [177]

    Development success in open source software projects: Exploring the impact of copylefted licenses,

    J. A. Colazo, Y . Fang, and D. Neufeld, “Development success in open source software projects: Exploring the impact of copylefted licenses,” in Americas Conference on Information Systems (AMCIS) , 2005, p. 432

  171. [178]

    A preliminary analysis of the influences of licensing and organizational sponsorship on success in open source projects,

    K. J. Stewart, A. P. Ammeter, and L. M. Maruping, “A preliminary analysis of the influences of licensing and organizational sponsorship on success in open source projects,” in 38th Annual Hawaii Interna- tional Conference on System Sciences . IEEE, 2005, pp. 197c–197c

  172. [179]

    Impact of license choice on open source software development activity,

    J. Colazo and Y . Fang, “Impact of license choice on open source software development activity,” Journal of the American Society for Information Science and Technology , vol. 60, no. 5, pp. 997–1011, 2009

  173. [180]

    Matching open source software licenses with corresponding business models,

    J. Lindman, M. Rossi, and A. Paajanen, “Matching open source software licenses with corresponding business models,” IEEE software, vol. 28, no. 4, pp. 31–35, 2011

  174. [181]

    An investigation into the impact of software licenses on copy-and-paste reuse among oss projects,

    Y . Kashima, Y . Hayase, N. Yoshida, Y . Manabe, and K. Inoue, “An investigation into the impact of software licenses on copy-and-paste reuse among oss projects,” in 2011 18th Working Conference on Reverse Engineering. IEEE, 2011, pp. 28–32

  175. [182]

    When and why developers adopt and change software licenses,

    C. Vendome, M. Linares-V ´asquez, G. Bavota, M. Di Penta, D. M. German, and D. Poshyvanyk, “When and why developers adopt and change software licenses,” in 2015 IEEE international conference on software maintenance and evolution (ICSME). IEEE, 2015, pp. 31–40

  176. [183]

    License choice and the changing structures of work in organization owned open source projects,

    P. K. Medappa and S. C. Srivastava, “License choice and the changing structures of work in organization owned open source projects,” in2017 ACM SIGMIS Conference on Computers and People Research , 2017, pp. 117–123

  177. [184]

    On licensing and other conditions for contributing to widely used open source projects: an exploratory analysis,

    J. Gamalielsson and B. Lundell, “On licensing and other conditions for contributing to widely used open source projects: an exploratory analysis,” in 13th International Symposium on Open Collaboration , 2017, pp. 1–14

  178. [185]

    License recommendation for open source projects in the power industry,

    X. Zhang, H. Xu, Q. Yu, S. Zeng, S. Dai, H. Yang, and S. Wu, “License recommendation for open source projects in the power industry,” Information and Software Technology , vol. 167, p. 107391, 2024

  179. [186]

    Self-admitted library migrations in java, javascript, and python packaging ecosystems: A comparative study,

    H. Gu, H. He, and M. Zhou, “Self-admitted library migrations in java, javascript, and python packaging ecosystems: A comparative study,” in 2023 IEEE International Conference on Software Analysis, Evolution and Reengineering (SANER) . IEEE, 2023, pp. 627–638

  180. [187]

    Practical very large scale crfs,

    T. Lavergne, O. Capp ´e, and F. Yvon, “Practical very large scale crfs,” in 48th Annual Meeting of the Association for Computational Linguistics , 2010, pp. 504–513

  181. [188]

    Libsvm: a library for support vector machines,

    C.-C. Chang and C.-J. Lin, “Libsvm: a library for support vector machines,” ACM transactions on intelligent systems and technology (TIST), vol. 2, no. 3, pp. 1–27, 2011

  182. [189]

    Report of license proliferation committee and draft faq,

    “Report of license proliferation committee and draft faq,” https://open source.org/proliferation-report, 2025, [Accessed: May 9, 2025]

  183. [190]

    The software heritage license dataset (2022 edition),

    J. M. Gonzalez-Barahona, S. Montes-Leon, G. Robles, and S. Zacchi- roli, “The software heritage license dataset (2022 edition),” Empirical Software Engineering, vol. 28, no. 6, p. 147, 2023

  184. [191]

    OSADL Open Source License Checklists,

    OSADL, “OSADL Open Source License Checklists,” https://www.os adl.org/Access-to-raw-data.oss-compliance-raw-data-access.0.html, [Accessed: May 9, 2025]

  185. [192]

    Liscopelens: An open-source license incompatibility analysis tool based on scope representation of license terms,

    Z. Liu, X. Liu, Y . Zhang, Z. Zhang, S. Li, W. Niu, Q. Zhou, R. Zhou, and X. Zhou, “Liscopelens: An open-source license incompatibility analysis tool based on scope representation of license terms,” in 2024 IEEE 35th International Symposium on Software Reliability Engineering ...

  186. [193]

    Clausebench: Enhancing software license analysis with clause-level benchmarking,

    Q. Ke, X. Hou, Y . Zhao, and H. Wang, “Clausebench: Enhancing software license analysis with clause-level benchmarking,” in 2025 IEEE/ACM 47st International Conference on Software Engineering (ICSE). IEEE, 2025

  187. [194]

    Ccfinder: A multilinguistic token-based code clone detection system for large scale source code,

    T. Kamiya, S. Kusumoto, and K. Inoue, “Ccfinder: A multilinguistic token-based code clone detection system for large scale source code,” IEEE transactions on software engineering, vol. 28, no. 7, pp. 654–670, 2002

  188. [195]

    Sourcerercc: Scaling code clone detection to big-code,

    H. Sajnani, V . Saini, J. Svajlenko, C. K. Roy, and C. V . Lopes, “Sourcerercc: Scaling code clone detection to big-code,” in 38th international conference on software engineering , 2016, pp. 1157– 1168

  189. [196]

    A novel neural source code representation based on abstract syntax tree,

    J. Zhang, X. Wang, H. Zhang, H. Sun, K. Wang, and X. Liu, “A novel neural source code representation based on abstract syntax tree,” in 2019 IEEE/ACM 41st International Conference on Software Engineering (ICSE). IEEE, 2019, pp. 783–794

  190. [197]

    Atvhunter: Reliable version detection of third-party libraries for vul- nerability identification in android applications,

    X. Zhan, L. Fan, S. Chen, F. We, T. Liu, X. Luo, and Y . Liu, “Atvhunter: Reliable version detection of third-party libraries for vul- nerability identification in android applications,” in 2021 IEEE/ACM 43rd International Conference on Software Engineering (ICSE). IEEE, 2021,...

  191. [198]

    GNU Lesser General Public License version 3,

    “GNU Lesser General Public License version 3,” https://opensource.o rg/license/lgpl-3-0, 2007, [Accessed: May 9, 2025]

  192. [199]

    Google Maps Platform Terms of Service,

    “Google Maps Platform Terms of Service,” https://cloud.google.com /maps-platform/terms, May 2020, [Accessed: May 9, 2025]

  193. [200]

    Terms and conditions: This is the Android Software Development Kit License Agreement,

    “Terms and conditions: This is the Android Software Development Kit License Agreement,” https://developer.android.com/studio/terms, Jul. 2021, [Accessed: May 9, 2025]

  194. [201]

    BSD 3-Clause No Nuclear License,

    “BSD 3-Clause No Nuclear License,” https://spdx.org/licenses/BSD- 3-Clause-No-Nuclear-License.html, [Accessed: May 9, 2025]

  195. [202]

    The JSON License,

    “The JSON License,” https://www.json.org/license.html, [Accessed: May 9, 2025]

  196. [203]

    Relicensing - LLVM Foundation,

    “Relicensing - LLVM Foundation,” https://llvm.org/docs/DeveloperPol icy.html#relicensing, [Accessed: May 9, 2025]

  197. [204]

    LLAMA 3.2 COMMUNITY LICENSE AGREEMENT,

    “LLAMA 3.2 COMMUNITY LICENSE AGREEMENT,” https://ww w.llama.com/llama3 2/license/, 2024, [Accessed: May 9, 2025]

  198. [205]

    GitHub - deepseek-ai/DeepSeek-Coder/LICENSE-MODEL,

    “GitHub - deepseek-ai/DeepSeek-Coder/LICENSE-MODEL,” https:// github.com/deepseek-ai/deepseek-coder/blob/main/LICENSE-MODE L, 2023, [Accessed: May 9, 2025]

  199. [206]

    The difference between Xorg and XFree86,

    A. Coopersmith, “The difference between Xorg and XFree86,” https: //blogs.oracle.com/solaris/post/the-difference-between-xorg-and-xfree 86, 2004, [Accessed: May 9, 2025]

  200. [207]

    Acquisition of Sun Microsystems by Oracle Corporation - Wikipedia,

    “Acquisition of Sun Microsystems by Oracle Corporation - Wikipedia,” https://en.wikipedia.org/wiki/Acquisition of Sun Microsystems by Oracle Corporation#OpenOffice resignations and forks, [Accessed: May 9, 2025]

  201. [208]

    Contributor License Agreement - Wikipedia,

    “Contributor License Agreement - Wikipedia,” https://en.wikipedia.o rg/wiki/Contributor License Agreement, [Accessed: May 9, 2025]

  202. [209]

    Developer Certificate of Origin - Wikipedia,

    “Developer Certificate of Origin - Wikipedia,” https://en.wikipedia.org /wiki/Developer Certificate of Origin, [Accessed: May 9, 2025]

  203. [210]

    Codegen: An open large language model for code with multi-turn program synthesis,

    E. Nijkamp, B. Pang, H. Hayashi, L. Tu, H. Wang, Y . Zhou, S. Savarese, and C. Xiong, “Codegen: An open large language model for code with multi-turn program synthesis,” ICLR, 2023

  204. [211]

    Github copilot · your ai pair programmer,

    “Github copilot · your ai pair programmer,” https://github.com/feature s/copilot, 2025, [Accessed: May 9, 2025]

  205. [212]

    Chatgpt,

    “Chatgpt,” https://chatgpt.com/, 2025, [Accessed: May 9, 2025]

  206. [213]

    GitHub Trust Center,

    GitHub, “GitHub Trust Center,” https://resources.github.com/copilot-t rust-center, 2025, [Accessed: May 9, 2025]

  207. [215]

    Participate in Our Community - OpenChain,

    “Participate in Our Community - OpenChain,” https://openchainproje ct.org/participate, 2025, [Accessed: May 9, 2025]

  208. [1975]

    Available: https://doi.org/10.1145/360825.360855

    [Online]. Available: https://doi.org/10.1145/360825.360855

Pith tools

Reviewed August 6, 2026 · model on record in the stance chip above.