+1, I would also add that these are external and unilateral declarations
of additional permissions.
I agree that declarations of additional permissions made outside of a
codebase are a different issue for SPDX, in large part because SPDX's most
common use case is source code scanners that only look at codebases.
FWIW, as a tool smith, I have no technical issue with combining the
license and copyright holder scans and therefore returning a GPL +
rider license if the holder is offering such a rider. It can even be
one rider per holder. That's a very easy one and that would likely be
the only clues needed for such determination.

A similar logic applies to the infamous BSD-4-Clause: if the copyright
is from the UC Regent, then the 4th clause has be rescinded and this
is equivalent to a 3 clause aka. a BSD-4-Clause-UC. Otherwise, it is a
regular 4 clause. The only different between the two is the copyright

