Visitar URL original
Unzip.scala contains Stack Overflow code, not allowed by ASF licensing policy · Issue #259 · apache/openserverless · GitHub
Skip to content

Unzip.scala contains Stack Overflow code, not allowed by ASF licensing policy #259

Description

@pjfanning

build/openwhisk/core/standalone/src/main/scala/org/apache/openwhisk/standalone/Unzip.scala (in the openserverless-build submodule, shipped in the 0.9.0-incubating-RC7 source release) contains code taken from Stack Overflow:

  def apply(is: InputStream, dir: File): Unit = {
    //Based on https://stackoverflow.com/a/40547896/1035417

Stack Overflow contributions are licensed under CC BY-SA, and the ASF third-party licensing policy does not allow this code in an Apache project without the original author's permission:

Can Stack Overflow code be included? No, not without contacting the original author and getting permission from them to use the code in an Apache project under the Apache License 2.0.

— https://www.apache.org/legal/resolved.html#stackoverflow

The file was vendored unchanged from Apache OpenWhisk (core/standalone/.../Unzip.scala), so the problem is inherited, but it is still part of our release.

The code is small: it iterates a ZipInputStream and writes each entry to disk. It has one caller, UserEventLauncher.scala:139.

Possible fixes:

  1. Rewrite Unzip from scratch (clean-room) using java.util.zip directly, or replace it with an existing Apache-licensed utility (e.g. Apache Commons Compress). Drop the Stack Overflow reference.
  2. Or, if the code is kept, obtain and record permission from the answer's author to use it under the Apache License 2.0.

While rewriting it, it would also be worth guarding against "zip slip" (entries whose names contain ../ resolving outside dir). The current code writes to dest.resolve(zipEntry.getName) without checking that the result stays under dest.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions