{"record":{"id":"fd5f7a2d7aed4ee6","repo":"slint-ui/slint","slug":"license-expression-of-crate-is-not-in-the-accepted-list","errorCode":null,"errorMessage":"License `{expression}` of crate {} {} is not in the accepted list","messagePattern":"License `(.+?)` of crate (.+?) (.+?) is not in the accepted list","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"xtask/src/license.rs","lineNumber":161,"sourceCode":"\n        // Lax parsing accepts the deprecated `/` OR-separator and imprecise\n        // identifiers (e.g. `apache2`) still found in older crates.\n        let expr =\n            spdx::Expression::parse_mode(&expression, spdx::ParseMode::LAX).with_context(|| {\n                format!(\"Cannot parse license `{expression}` of {} {}\", pkg.name, pkg.version)\n            })?;\n\n        // A `[package.metadata.slint-license.allow]` entry in the analyzed\n        // crate's manifest extends the accepted set for *that one dependency\n        // only*, so an exceptional license (e.g. LGPL-3.0 via dynamic linking)\n        // is approved explicitly per-crate rather than relaxed project-wide.\n        let pkg_allow = allow.get(pkg.name.as_str()).map(String::as_str);\n        let pkg_accepted = |req: &spdx::LicenseReq| {\n            let id = license_string(req);\n            accepted.contains(id.as_str()) || pkg_allow == Some(id.as_str())\n        };\n        if !expr.evaluate(pkg_accepted) {\n            bail!(\n                \"License `{expression}` of crate {} {} is not in the accepted list\",\n                pkg.name,\n                pkg.version\n            );\n        }\n\n        // Record the license ids the crate uses, so each gets a body.\n        for req in expr.requirements() {\n            if !pkg_accepted(&req.req) {\n                continue;\n            }\n            let id = license_string(&req.req);\n            license_names.entry(id.clone()).or_insert_with(|| license_full_name(&req.req));\n            used_ids.insert(id);\n        }\n\n        // The `authors` field is optional and newer crates increasingly omit\n        // it; salvage the copyright holder(s) from the license files shipped","sourceCodeStart":143,"sourceCodeEnd":179,"githubUrl":"https://github.com/slint-ui/slint/blob/bb937076de3f7919766c1f25e2e969367cf77e9a/xtask/src/license.rs#L143-L179","documentation":"The `xtask` license checker validates that every dependency crate's declared SPDX license expression is on the project's accepted-licenses list (with optional per-crate allow entries). When a crate's license is not accepted and not allowed, the `generate` step bails with this error. It guards the dependency set against licenses the project cannot ship.","triggerScenarios":"Adding or upgrading a dependency whose Cargo.toml `license` field contains an SPDX expression not present in the accepted list and not covered by a per-package entry in the allow list; a dependency changing its license in a new version.","commonSituations":"`cargo xtask` license/dependency checks in CI after `cargo update` pulls a crate version with a new license; introducing a crate with a copyleft or nonstandard license.","solutions":["Add an allow entry for the package in xtask's license allow list if the license is acceptable for this use","Downgrade or pin the dependency to a version with an accepted license","Replace the dependency with an alternative that has an accepted license, or negotiate/approve the new license and add its SPDX id to the accepted list"],"exampleFix":"// before (allow list in xtask license.rs / config)\nlet allow = \"\"; // crate with ISC license not listed\n// after\nlet pkg_allow = Some(\"ISC\"); // explicit per-crate allow added for the new dependency","handlingStrategy":"validation","validationCode":"# Check a crate's license before adding it\ncargo add foo --dry-run\ngrep '^license' $(cargo metadata ... | jq -r '.packages[] | select(.name==\"foo\") | .manifest_path')","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Check new dependencies' SPDX licenses before adding them","After cargo update, run the xtask license check locally before pushing","Keep the allow list documented so additions are deliberate"],"tags":["license","spdx","ci","xtask"],"backgroundTag":"schema-validation-failed","analyzedSha":"bb937076de3f7919766c1f25e2e969367cf77e9a","analyzedAt":"2026-09-16T01:37:20.251Z","contentChangedAt":"2026-09-16T01:37:20.251Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}