We would like to start monitoring the licenses of our open source gems. We need to make sure that we don't use a gem which has a license that is not approved.
As far as I can see the license_finder gem handles gems very well that are newly added and all gems that have a proper license information in their gemspec. Also, manually managing gem licenses is very easy.
But it seems to me that it's not possible approve a license for a specific gem version only?
An example:
The Jsons Gem (https://github.com/flori/json) licence is detected as 'other'. We manually approve it and afterwards, with a new version, the gem owner might change the license to one we don't approve. LicenseFinder does not detect that as an invalid license, does it?
Am I overlooking something? Is that case not relevant as it does happen very rarely? Or do you plan to implement something like that in the future?
best regards
Meike