Please update NuGet License of CommunityToolkit to SPDX-Format

Your .NET MAUI Community Toolkit (https://www.syncfusion.com/net-maui-toolkit) is featured in NuGet with a MIT License. However, you use a direct link specific license (https://www.nuget.org/packages/Syncfusion.Maui.Toolkit/1.0.9/license). This is deprecated and results in "Unknown - see https://aka.ms/deprecateLicenseUrl" when using SBOM-Tools (see attachment).

Can you please consider the SPDX License Format instead? (https://licenses.nuget.org/MIT)



Attachment: SFLicense_2e2b6725.png


1 Reply

VA Valan Arockiya Kiraswin Arockiya Jesu Syncfusion Team March 4, 2026 02:35 PM UTC

Hi,

Thank you for contacting us. We were able to reproduce the license URL validation warnings you reported in the SBOM output. However, when generating the SBOM report using an alternative tool, these warnings did not occur.

During our investigation, we identified that the issue is caused by an automatically generated <licenseUrl> tag being inserted during the NuGet packing process. This auto‑added tag is what triggers the validation error in the SBOM report.

We have already reached out to the NuGet support team regarding this behavior and are working with them to identify a resolution. We will provide you with an update as soon as we receive further information from their team.

If you need any additional information, please let us know.

Regards,

Valan


Loader.
Up arrow icon