You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Describe the bug
The most recent version of the elliptic package is reported as having a license of MIT AND OFL-1.1. But I'm not sure where the Open Font License is coming from.
Licenses
The following dependencies have incompatible licenses:
pnpm-lock.yaml » [email protected] – License: MIT AND OFL-1.1
Their repo shows an MIT license, and NPM correctly identifies it as having an MIT license. This could be an error on the side of elliptic's maintainers, but I can't find where this license would be coming from on their end.
To Reproduce
Steps to reproduce the behavior:
Run the action on a repo with elliptic version 6.6.1.
See the unexpected package value.
Expected behavior
The dependency review actions reports the license as MIT.
Screenshots
N/A
Action version
4.3.3
Note: if you're not running the latest release please try that first!
Examples
N/A
Additional context
N/A
The text was updated successfully, but these errors were encountered:
Describe the bug
The most recent version of the
elliptic
package is reported as having a license ofMIT AND OFL-1.1
. But I'm not sure where the Open Font License is coming from.Their repo shows an MIT license, and NPM correctly identifies it as having an MIT license. This could be an error on the side of
elliptic
's maintainers, but I can't find where this license would be coming from on their end.To Reproduce
Steps to reproduce the behavior:
elliptic
version6.6.1
.Expected behavior
The dependency review actions reports the license as MIT.
Screenshots
N/A
Action version
4.3.3
Note: if you're not running the latest release please try that first!
Examples
N/A
Additional context
N/A
The text was updated successfully, but these errors were encountered: