Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Licensing Vulnerability in react-use Dependency #2615

Open
klaw772 opened this issue Dec 19, 2024 · 0 comments
Open

Licensing Vulnerability in react-use Dependency #2615

klaw772 opened this issue Dec 19, 2024 · 0 comments

Comments

@klaw772
Copy link

klaw772 commented Dec 19, 2024

What is the current behavior?

When running a FOSSA scan, the 'throttle-debounce' package version 3.0.1 returns a flag of 'Flagged: GPL-2.0-only' for its licensing. The most up-to-date version of the throttle-debounce package (5.0.2) has since adjusted to use MIT as its licensing. Additional behavior changes in throttle-debounce do not seem to affect how it's being currently used in react-use.

What is the expected behavior?
FOSSA scan no longer flagging GPL licensing as an issue.

A little about versions:

  • OS: N/A
  • Browser (vendor and version): N/A
  • React: 18.2.0
  • react-use: 17.6.0
  • Did this worked in the previous package version? unsure but likely not
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant