Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

license_tests: pip-license-checker v0.46.1 fails on PEP 639 packages

Open Beginner friendly
#10 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
2/5
Estimated time
1-3 hours
Newbie friendliness
65/100
Issue type
Bug
Clarity
Clearly specified
Activity status
Stale
Tech stack
github-actions, python
Domain
ci-cd

Research direction

Start with .github/workflows/license_tests.yml and inspect how pilosus/action-pip-license-checker is configured, including its version and branch input. Update the action to v3 and assess whether github.ref_name should replace github.head_ref for push events. Done means the workflow uses the supported checker version and checkout behavior works for both pull requests and pushes.

Written by the indexing model from the issue text.

Description

Summary

The shared license_tests.yml workflow is failing across repos (e.g. ovos-skill-laugh) with Error: Checker License sources not found for common, well-known packages:

click:8.3.1              Error    Error: Checker License sources not found
idna:3.11                Error    Error: Checker License sources not found
importlib_metadata:8.7.1 Error    Error: Checker License sources not found
RapidFuzz:3.14.3         Error    Error: Checker License sources not found
regex:2026.2.28          Error    Error: Checker License sources not found
typing_extensions:4.15.0 Error    Error: Checker License sources not found
urllib3:2.6.3            Error    Error: Checker License sources not found
zipp:3.23.0              Error    Error: Checker License sources not found

Root Cause

pilosus/action-pip-license-checker@v2 pins to pip-license-checker 0.46.1, which queries the PyPI JSON API for the old License metadata field. Many packages have migrated to PEP 639's License-Expression field. The checker doesn't understand this format, so it returns Error instead of the actual license string.

Since the workflow sets fail: 'Copyleft,Other,Error', every unresolved package fails the check.

Fix

Upgrade pilosus/action-pip-license-checker to v3 in .github/workflows/license_tests.yml. v3 adds support for the new PyPI metadata format.

Secondary Issue

The workflow passes branch: ${{ github.head_ref }} from calling repos. github.head_ref is only set on pull_request events — on push events it is empty, causing the checkout step to silently fall back to the commit SHA. This works by accident but is fragile. Consider defaulting to github.ref_name instead.

Dominant language
No language data
Stars
0
Forks
7
PR merge metrics
No merged PRs in 30d

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Similar issues

More DevOps issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.