| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
Sorry, something went wrong.
Apache-2.0 §4(d) requires propagating NOTICE attribution for third-party components. This file enumerates them with name, version, license, and package URL. Generated from the project's CycloneDX SBOM.
…LICENSES.md Apache-2.0 §4(d) requires propagating upstream NOTICEs, not enumerating every transitive dep. The previous NOTICE inlined 127 dep entries; the new one preserves Coinbase's upstream copyright and points to the SBOM for the full bill of materials. THIRD-PARTY-LICENSES.md is a category- level summary alongside.
Drop the regen instructions and tool references — this file is a human-readable summary; the canonical bill of materials lives in the CycloneDX SBOM kept with the DD inventory.
| Back | FazBrowse Home | New Git URL |
Summary
Why
The fork didn't ship a NOTICE file. Apache-2.0 §4(d) requires propagating upstream NOTICEs for Apache-licensed dependencies — the new NOTICE preserves Coinbase's copyright and points to the SBOM (per-dep license texts are retained in Go's module cache and the release binaries, which is what §4(d) actually requires).
Surfaced during the current OSS due-diligence review.
Test plan