FazBrowse GitHub Viewer | Trending |
URL:
| Home
Tools: [Download Repo ZIP]   [Original HTTPS Page]

LICENSE: attribute npm packages embedded in the pre-built JavaScript bundles by pjfanning · Pull Request #251 · apache/openserverless · GitHub

LICENSE: attribute npm packages embedded in the pre-built JavaScript bundles - #251

Closed
pjfanning wants to merge 2 commits into
apache:0.9.0from
pjfanning:license-js-bundles
Closed

pjfanning wants to merge 2 commits into
apache:0.9.0from
pjfanning:license-js-bundles

Conversation

Copy link
Copy Markdown
Member

What

Lists, in the top-level LICENSE, the npm packages statically embedded in the three pre-built JavaScript bundles that the source release ships, and reproduces the MIT, ISC and BSD-3-Clause licence texts they require.

Found while verifying the 0.9.0-incubating RC5 source tarball. The bundles are bun build outputs checked into the oplugins submodule; they were attributed only in oplugins/NOTICE, while the top-level LICENSE stated that every bundled component is Apache-2.0. ASF policy puts pointers to permissive third-party licences in LICENSE, not NOTICE.

Bundles covered

Bundle Embedded packages Licences
oplugins/util/upload.js (1.0 MB) minio 8.0.1 + 27 dependencies Apache-2.0, MIT ×24, ISC ×2, BSD-3-Clause ×1
oplugins/util/config/configurator.js @clack/core, @clack/prompts, sisteransi, picocolors MIT ×3, ISC ×1
oplugins/admin/usage/usage.js yaml 2.8.3 ISC

Every package's licence was checked against the npm registry for the exact version pinned in the shipped lockfiles (oplugins/util/upload/bun.lock, oplugins/admin/usage/usagechecker/package-lock.json) and, for the configurator, the lockfile at the tagged oplugins commit (its source directory is excluded from the tarball by no-release.txt). All are ASF Category A.

Two corrections relative to the list in oplugins/NOTICE:

  • @clack/core is pinned at 0.3.4, not 0.3.5.
  • stream-chain is not embedded in upload.js (only stream-json/jsonl and stream-json/utils are); it is omitted here.

The intro sentence of the "Bundled components" section no longer claims that every component is Apache-2.0.

Stacked on #250

This branch is based on the branch of #250 because both PRs append to the end of LICENSE. Once #250 merges, this PR's diff reduces to the single commit LICENSE: attribute npm packages embedded in the pre-built JavaScript bundles.

Follow-ups outside this repo

  • The bundles themselves carry a plain ASF licence header above a megabyte of MIT/ISC/BSD code. A separate PR against apache/openserverless-task should make those headers state that the file embeds third-party code.
  • oplugins/NOTICE should be trimmed to required attributions only; the per-package list belongs in oplugins/LICENSE.

🤖 Generated with Claude Code

pjfanning and others added 2 commits September 15, 2026 21:29
…d configs

The source release ships verbatim or lightly edited copies of manifests
and configuration files from cert-manager, ingress-nginx, Kubegres,
Milvus Operator, Milvus and its Helm chart (with the rendered Pulsar,
Bitnami etcd and MinIO charts), the MongoDB Community Operator, the
Prometheus community chart and Apache Kvrocks. All are Apache-2.0 but
none were listed in the top-level LICENSE. List them with their upstream
locations and versions, and propagate the NOTICE attribution for the two
ASF upstreams (Pulsar, Kvrocks).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…bundles

oplugins/util/upload.js, oplugins/util/config/configurator.js and
oplugins/admin/usage/usage.js are bun-built bundles that statically
embed npm packages under the MIT, ISC, BSD-3-Clause and Apache-2.0
licences. They were attributed only in oplugins/NOTICE; the top-level
LICENSE claimed every bundled component was Apache-2.0. List each
embedded package with its version, licence and copyright holder, and
reproduce the MIT, ISC and BSD-3-Clause texts.

Versions and licences were verified against the shipped lockfiles and
the npm registry. Two corrections to the list in oplugins/NOTICE: the
configurator lockfile pins @clack/core 0.3.4, and stream-chain is not
embedded in upload.js.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

Copy link
Copy Markdown
Member Author

This includes the changes from #250 but I'd prefer to merge that while we decide what to do about these javascript files.
It appears that they are built and maybe we don't need to ship them in our tar.gz file and just build them as part of the build. That means we don't have the same requirements for listing the licenses in our source release tar.gz.

Copy link
Copy Markdown
Contributor

the problem here looks like I forgot to analyzed the package.json of the utilities, luckily they are all compiant but they shoud have been included in the source license. Thank you for pointing out.

Copy link
Copy Markdown
Member Author

I think we need to look at removing them from future source releases.
You should be able to add bun build commands to the build scripts to regenerate them.

Copy link
Copy Markdown
Contributor

managed after updating the references and cleaned the code

This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode characters
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants


Back | FazBrowse Home | New Git URL