Logstash OSS contains some dependencies from component containing GPL License

Hi,

I did FOSSA of Logstash 6.6.1 and Logstash-codec-plugin, both these software are under Apache 2.0 License. However both contains sub-components that are GPL, LGPL copyleft license.

Fossa scanning reveals Logstash contains dependencies that are copyleft license:

jmh-core
jmh-core-benchmarks
jmh-generator-annprocess
jruby-complete"
ruby-core"
diff-lcs
filesize
jruby-openssl+0.9.19
minitar+0.5.4
rubyzip+1.1.7

  1. What type of dependencies Logstash has on above components

  2. How is Logstash offered under Apache 2.0 license, when it contains above sub components that has copyleft license - GPL, LGPL.

  3. Are these dependencies ‘part of the program’ or ‘separate program’?

  4. Are these dependencies shipped along with logstash binary? Are these build time or runtime dependencies?

Thankyou,

Sunil

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.