license_tests: pip-license-checker v0.46.1 fails on PEP 639 packages
Nobody has claimed this yet.
Assessment
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 65/100
Research direction
Start with .github/workflows/license_tests.yml and inspect how pilosus/action-pip-license-checker is configured, including its version and branch input. Update the action to v3 and assess whether github.ref_name should replace github.head_ref for push events. Done means the workflow uses the supported checker version and checkout behavior works for both pull requests and pushes.
Written by the indexing model from the issue text.
Description
Summary
The shared license_tests.yml workflow is failing across repos (e.g. ovos-skill-laugh) with Error: Checker License sources not found for common, well-known packages:
click:8.3.1 Error Error: Checker License sources not found
idna:3.11 Error Error: Checker License sources not found
importlib_metadata:8.7.1 Error Error: Checker License sources not found
RapidFuzz:3.14.3 Error Error: Checker License sources not found
regex:2026.2.28 Error Error: Checker License sources not found
typing_extensions:4.15.0 Error Error: Checker License sources not found
urllib3:2.6.3 Error Error: Checker License sources not found
zipp:3.23.0 Error Error: Checker License sources not found
Root Cause
pilosus/action-pip-license-checker@v2 pins to pip-license-checker 0.46.1, which queries the PyPI JSON API for the old License metadata field. Many packages have migrated to PEP 639's License-Expression field. The checker doesn't understand this format, so it returns Error instead of the actual license string.
Since the workflow sets fail: 'Copyleft,Other,Error', every unresolved package fails the check.
Fix
Upgrade pilosus/action-pip-license-checker to v3 in .github/workflows/license_tests.yml. v3 adds support for the new PyPI metadata format.
Secondary Issue
The workflow passes branch: ${{ github.head_ref }} from calling repos. github.head_ref is only set on pull_request events — on push events it is empty, causing the checkout step to silently fall back to the commit SHA. This works by accident but is fragile. Consider defaulting to github.ref_name instead.
- Dominant language
- No language data
- Stars
- 0
- Forks
- 7
- PR merge metrics
- No merged PRs in 30d
Getting set up
- No Dockerfile or Docker Compose file
- No pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Similar issues
-
automated issue report
Difficulty 1/5 Under an hour Newbie friendliness 65/100
lirantal/discoprint#32 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 86/100
lawndoc/stack-back#122 ·
-
ai-inspected
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
Maintainers usually reply within 1 day
-
software-development-practices software-development-practices:nist-ssdf
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
githubnext/gh-aw-cao#15860 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 Half a day Newbie friendliness 68/100
Maintainers usually reply within 1 day