Provides empirical evidence that minor textual variants in licenses are a primary cause of 10.7% of downstream compliance failures in the PyPI ecosystem.
Analysis of the top 8,000 PyPI packages reveals that textual variations in open-source licenses are pervasive (median similarity 0.90 to SPDX standards), though only 2% represent substantive legal modifications. These 'substantial variants'—often adding trademark restrictions or proprietary prohibitions on modification—cause significant compliance failures, with 10.7% of their downstream dependencies found to be license-incompatible. The research introduces the LV-Parser approach, which uses diff-based analysis and LLMs to identify meaningful legal changes while reducing query costs by 30%. A companion tool, LV-Compat, demonstrated a 5.2x improvement in detecting incompatible packages over standard methods by specifically accounting for these variants and embedded third-party terms.
The study confirms that even minor textual changes can introduce proprietary restrictions, causing 10.7% of downstream users to be out of compliance.
unintentional violation of non-standard license terms that have been 'sneaked' into a familiar template
detecting modified licenses is the only way to catch the 2% of packages that use variant texts to impose high-risk legal obligations.
10.7% of downstream dependencies were found to be incompatible with their upstream variant licenses, highlighting a widespread failure to map complex dependency trees.
legal liability for copyright infringement due to incompatible transitive dependencies
license mismatch is a systemic risk in PyPI, where variant upstream licenses frequently conflict with standard downstream ones.
Substantive license variants lead to significant compliance issues, with 10.7% of their downstream dependencies found to be license-incompatible.
Risk Guard treats licenses as standard templates but does not perform 'Substantive Diff' analysis to catch variants that add proprietary restrictions.
Risk Guard would be better if it performed line-level diffs against standard SPDX texts and flagged 'Substantive Clauses' (like trademark or SaaS restrictions) that differ from the norm.