| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
…d configs The source release ships verbatim or lightly edited copies of manifests and configuration files from cert-manager, ingress-nginx, Kubegres, Milvus Operator, Milvus and its Helm chart (with the rendered Pulsar, Bitnami etcd and MinIO charts), the MongoDB Community Operator, the Prometheus community chart and Apache Kvrocks. All are Apache-2.0 but none were listed in the top-level LICENSE. List them with their upstream locations and versions, and propagate the NOTICE attribution for the two ASF upstreams (Pulsar, Kvrocks). Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…bundles oplugins/util/upload.js, oplugins/util/config/configurator.js and oplugins/admin/usage/usage.js are bun-built bundles that statically embed npm packages under the MIT, ISC, BSD-3-Clause and Apache-2.0 licences. They were attributed only in oplugins/NOTICE; the top-level LICENSE claimed every bundled component was Apache-2.0. List each embedded package with its version, licence and copyright holder, and reproduce the MIT, ISC and BSD-3-Clause texts. Versions and licences were verified against the shipped lockfiles and the npm registry. Two corrections to the list in oplugins/NOTICE: the configurator lockfile pins @clack/core 0.3.4, and stream-chain is not embedded in upload.js. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
|
This includes the changes from #250 but I'd prefer to merge that while we decide what to do about these javascript files. |
Sorry, something went wrong.
|
the problem here looks like I forgot to analyzed the package.json of the utilities, luckily they are all compiant but they shoud have been included in the source license. Thank you for pointing out. |
Sorry, something went wrong.
|
I think we need to look at removing them from future source releases. |
Sorry, something went wrong.
|
managed after updating the references and cleaned the code |
Sorry, something went wrong.
| Back | FazBrowse Home | New Git URL |
What
Lists, in the top-level LICENSE, the npm packages statically embedded in the three pre-built JavaScript bundles that the source release ships, and reproduces the MIT, ISC and BSD-3-Clause licence texts they require.
Found while verifying the 0.9.0-incubating RC5 source tarball. The bundles are bun build outputs checked into the oplugins submodule; they were attributed only in oplugins/NOTICE, while the top-level LICENSE stated that every bundled component is Apache-2.0. ASF policy puts pointers to permissive third-party licences in LICENSE, not NOTICE.
Bundles covered
Every package's licence was checked against the npm registry for the exact version pinned in the shipped lockfiles (oplugins/util/upload/bun.lock, oplugins/admin/usage/usagechecker/package-lock.json) and, for the configurator, the lockfile at the tagged oplugins commit (its source directory is excluded from the tarball by no-release.txt). All are ASF Category A.
Two corrections relative to the list in oplugins/NOTICE:
The intro sentence of the "Bundled components" section no longer claims that every component is Apache-2.0.
Stacked on #250
This branch is based on the branch of #250 because both PRs append to the end of LICENSE. Once #250 merges, this PR's diff reduces to the single commit LICENSE: attribute npm packages embedded in the pre-built JavaScript bundles.
Follow-ups outside this repo
🤖 Generated with Claude Code