<!-- 
RSS generated by JIRA (8.20.10#820010-sha1:ace47f9899e9ee25d7157d59aa17ab06aee30d3d) at Wed Feb 07 20:45:39 UTC 2024

It is possible to restrict the fields that are returned in this document by specifying the 'field' parameter in your request.
For example, to request only the issue key and summary append 'field=key&field=summary' to the URL of your request.
-->
<rss version="0.92" >
<channel>
    <title>OpenDaylight JIRA</title>
    <link>https://jira.opendaylight.org</link>
    <description>This file is an XML representation of an issue</description>
    <language>en-us</language>    <build-info>
        <version>8.20.10</version>
        <build-number>820010</build-number>
        <build-date>22-06-2022</build-date>
    </build-info>


<item>
            <title>[TSC-250] New ODL project PLASTIC needs a code scan</title>
                <link>https://jira.opendaylight.org/browse/TSC-250</link>
                <project id="10101" key="TSC">tsc</project>
                    <description>&lt;p&gt;The attached zip contains the source code for the Plastic project.&lt;/p&gt;

&lt;p&gt;Please have it code scanned.&lt;/p&gt;

&lt;p&gt;The project was accepted by the TSC on Oct 17, 2019&lt;/p&gt;

&lt;p&gt;Project page is&#160;&lt;a href=&quot;https://wiki.opendaylight.org/view/Project_Proposals:Plastic&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://wiki.opendaylight.org/view/Project_Proposals:Plastic&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&#160;&lt;/p&gt;</description>
                <environment></environment>
        <key id="32156">TSC-250</key>
            <summary>New ODL project PLASTIC needs a code scan</summary>
                <type id="10001" iconUrl="https://jira.opendaylight.org/images/icons/issuetypes/story.svg">Story</type>
                                            <priority id="2" iconUrl="https://jira.opendaylight.org/images/icons/priorities/critical.svg">High</priority>
                        <status id="10003" iconUrl="https://jira.opendaylight.org/images/icons/status_generic.gif" description="">Confirmed</status>
                    <statusCategory id="2" key="new" colorName="blue-gray"/>
                                    <resolution id="-1">Unresolved</resolution>
                                        <assignee username="swinslow">Stephen Winslow</assignee>
                                    <reporter username="allanclarke">Allan Clarke</reporter>
                        <labels>
                    </labels>
                <created>Thu, 31 Oct 2019 18:36:36 +0000</created>
                <updated>Fri, 1 Nov 2019 16:42:17 +0000</updated>
                                                            <fixVersion>Magnesium</fixVersion>
                                        <due></due>
                            <votes>0</votes>
                                    <watches>5</watches>
                                                                                                                <comments>
                            <comment id="67342" author="swinslow" created="Thu, 31 Oct 2019 19:54:44 +0000"  >&lt;p&gt;I&apos;ve completed a license scan of the attached zip file&apos;s contents using Fossology. Overall looks very good, most files contain EPL-1.0 notices and only one other finding was detected. Just a couple of minor notes below.&lt;/p&gt;
&lt;ol&gt;
	&lt;li&gt;Not a licensing issue, but note that there were a few files in the .zip archive that appear to be Mac metadata files (__MACOSX/ directory and .DS_Store). You&apos;ll likely want to exclude those from the repo.&lt;/li&gt;
	&lt;li&gt;In the file /release-version, below the EPL-1.0 header there is an additional notice: &quot;&lt;em&gt;Use of the software files and documentation is subject to license terms.&lt;/em&gt;&quot; Although this might be strictly true (as it&apos;s subject to EPL-1.0), it could be misread as saying that additional terms apply. I would recommend that the contributor remove this line before contributing it to the ODL repo.&lt;/li&gt;
	&lt;li&gt;In the root directory, the files mvnw and mvnw.cmd contain Apache-2.0 license notices. This is likely not a significant issue because it appears these are intended to be standalone scripts, and Apache-2.0 is generally understood as a permissive license. However, if these files are not essential, it might be preferable to omit them from the repo so that it is only EPL-1.0.&lt;/li&gt;
	&lt;li&gt;In the &quot;No license found&quot; tab, there are roughly 50 files listed where license notices were not detected. To improve license notice coverage, EPL-1.0 notices could likely be added to many of these files. Please note though that this can be an ongoing improvement and does not need to be addressed before pulling it into the ODL repo.
	&lt;ol&gt;
		&lt;li&gt;Further down, that tab also lists several &quot;excluded file extension&quot; files such as JSON files where license info cannot be easily added, due to a lack of a comments format; these can be disregarded.&lt;/li&gt;
	&lt;/ol&gt;
	&lt;/li&gt;
&lt;/ol&gt;


&lt;p&gt;I hope this is helpful &#8211; happy to discuss if any questions.&lt;/p&gt;

&lt;p&gt;Report: &lt;span class=&quot;nobr&quot;&gt;&lt;a href=&quot;https://jira.opendaylight.org/secure/attachment/15502/15502_plastic-2019-10-31.xlsx&quot; title=&quot;plastic-2019-10-31.xlsx attached to TSC-250&quot;&gt;plastic-2019-10-31.xlsx&lt;sup&gt;&lt;img class=&quot;rendericon&quot; src=&quot;https://jira.opendaylight.org/images/icons/link_attachment_7.gif&quot; height=&quot;7&quot; width=&quot;7&quot; align=&quot;absmiddle&quot; alt=&quot;&quot; border=&quot;0&quot;/&gt;&lt;/sup&gt;&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;</comment>
                            <comment id="67343" author="allanclarke" created="Thu, 31 Oct 2019 20:42:11 +0000"  >&lt;p&gt;Will resolve #1-3 (mostly by removing unwanted files)&lt;/p&gt;

&lt;p&gt;#4 will probably remain (and won&apos;t be an issue)&lt;/p&gt;</comment>
                    </comments>
                    <attachments>
                            <attachment id="15501" name="odl-plastic.zip" size="302100" author="allanclarke" created="Thu, 31 Oct 2019 18:41:58 +0000"/>
                            <attachment id="15502" name="plastic-2019-10-31.xlsx" size="11888" author="swinslow" created="Thu, 31 Oct 2019 19:54:04 +0000"/>
                    </attachments>
                <subtasks>
                    </subtasks>
                <customfields>
                                                                            <customfield id="customfield_11400" key="com.atlassian.jira.plugins.jira-development-integration-plugin:devsummary">
                        <customfieldname>Development</customfieldname>
                        <customfieldvalues>
                            
                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                <customfield id="customfield_10000" key="com.pyxis.greenhopper.jira:gh-lexo-rank">
                        <customfieldname>Rank</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>0|i03ps7:</customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                            </customfields>
    </item>
</channel>
</rss>