FazBrowse GitHub Viewer | Trending |
URL:
| Home
Tools: [Download Repo ZIP]   [Original HTTPS Page]

Bundle headers: state that the bun-built bundles embed third-party npm packages by pjfanning · Pull Request #234 · apache/openserverless-task · GitHub

Bundle headers: state that the bun-built bundles embed third-party npm packages - #234

Open
pjfanning wants to merge 2 commits into
apache:0.9.0from
pjfanning:bundle-license-headers
Open

pjfanning wants to merge 2 commits into
apache:0.9.0from
pjfanning:bundle-license-headers

Conversation

Copy link
Copy Markdown
Member

What

The three bun build outputs checked into this repo carried only the standard ASF licence header:

  • util/upload.js (1.0 MB)
  • util/config/configurator.js
  • admin/usage/usage.js

That header misrepresents the files. Most of upload.js is third-party code from npm: minio (Apache-2.0), 24 MIT packages (lodash, async, xml2js, readable-stream, ...), inherits and sax (ISC), stream-json (BSD-3-Clause). The configurator embeds @clack/core, @clack/prompts, sisteransi (MIT) and picocolors (ISC); usage.js embeds yaml (ISC).

This PR keeps the ASF header for the ASF-authored part of each bundle and adds a second comment block naming the embedded packages grouped by licence, pointing to LICENSE for copyright holders and licence texts, and noting the file is generated.

Checks

  • Apache RAT 0.18 over the repo: Unapproved: 0 (the ASF header block is unchanged, so RAT and license-eye still match it).
  • node --check passes on all three files.
  • Package lists were taken from the node_modules/ path markers inside each bundle and cross-checked against util/upload/bun.lock, util/config/configurator/bun.lock and admin/usage/usagechecker/package-lock.json. Licences were verified on the npm registry for the pinned versions. stream-chain is listed in NOTICE but is not actually embedded in upload.js.

Related

  • LICENSE: attribute npm packages embedded in the pre-built JavaScript bundles openserverless#251 adds the same packages, with copyright holders and the MIT/ISC/BSD-3-Clause texts, to the umbrella repo's top-level LICENSE.
  • This repo's own LICENSE should carry that list too; today it lives only in NOTICE, which per ASF policy should hold required attributions only. Happy to do that as a follow-up.
  • If the build scripts in the three package.json files gained a --banner, the header would be regenerated on every rebuild instead of being re-added by hand.

🤖 Generated with Claude Code

michele-sciabarra and others added 2 commits September 15, 2026 14:27
…m packages

util/upload.js, util/config/configurator.js and admin/usage/usage.js are
bun build outputs. Each carried only the standard ASF licence header,
which misrepresents the file: most of upload.js is third-party MIT, ISC,
BSD-3-Clause and Apache-2.0 code from npm. Keep the ASF header for the
ASF-authored part and add a second block naming the embedded packages
and their licences, pointing to LICENSE for copyright holders and
licence texts.

The ASF header block is unchanged, so Apache RAT and license-eye still
approve the files (RAT 0.18: Unapproved 0). Bundles still parse.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode characters
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants


Back | FazBrowse Home | New Git URL