…m packages
util/upload.js, util/config/configurator.js and admin/usage/usage.js are
bun build outputs. Each carried only the standard ASF licence header,
which misrepresents the file: most of upload.js is third-party MIT, ISC,
BSD-3-Clause and Apache-2.0 code from npm. Keep the ASF header for the
ASF-authored part and add a second block naming the embedded packages
and their licences, pointing to LICENSE for copyright holders and
licence texts.
The ASF header block is unchanged, so Apache RAT and license-eye still
approve the files (RAT 0.18: Unapproved 0). Bundles still parse.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
What
The three bun build outputs checked into this repo carried only the standard ASF licence header:
That header misrepresents the files. Most of upload.js is third-party code from npm: minio (Apache-2.0), 24 MIT packages (lodash, async, xml2js, readable-stream, ...), inherits and sax (ISC), stream-json (BSD-3-Clause). The configurator embeds @clack/core, @clack/prompts, sisteransi (MIT) and picocolors (ISC); usage.js embeds yaml (ISC).
This PR keeps the ASF header for the ASF-authored part of each bundle and adds a second comment block naming the embedded packages grouped by licence, pointing to LICENSE for copyright holders and licence texts, and noting the file is generated.
Checks
Related
🤖 Generated with Claude Code