Security: Incopatible 3rd party package license

Created on 10 April 2023, over 1 year ago
Updated 11 April 2023, over 1 year ago

Problem/Motivation

Module requires "giggsey/libphonenumber-for-php" but this package uses Apache 2.0 licenses. This license doesn't compatible with GPLv2 what is a critical issue here.

Proposed resolution

- Remove "giggsey/libphonenumber-for-php" from module requirements.
- Add to the description of the module that it can use the functionality of the "giggsey/libphonenumber-for-php" package, but the user must install it on their own.
- Make it possible to use the module without "giggsey/libphonenumber-for-php" (extra check conditions to determine whether the package was installed or not)

📌 Task
Status

Closed: works as designed

Version

1.0

Component

Miscellaneous

Created by

🇺🇦Ukraine HitchShock Ukraine

Live updates comments and jobs are added and updated live.
  • Security

    It is used for security vulnerabilities which do not need a security advisory. For example, security issues in projects which do not have security advisory coverage, or forward-porting a change already disclosed in a security advisory. See Drupal’s security advisory policy for details. Be careful publicly disclosing security vulnerabilities! Use the “Report a security vulnerability” link in the project page’s sidebar. See how to report a security issue for details.

  • Security Advisory follow-up

    This tag is to be applied to issues where an official security release has been made, but the fix needs to be ported to the development version of the code.

Sign in to follow issues

Comments & Activities

Production build 0.71.5 2024