feat(build): generate the IP-clearance license row from the SBOM - #245
Closed
adityamparikh wants to merge 1 commit into
Closed
adityamparikh wants to merge 1 commit into
adityamparikh wants to merge 1 commit into
Conversation
adityamparikh
force-pushed
the
feat/ip-clearance-license-row
branch
2 times, most recently
from
October 4, 2026 22:09
b435f1e to
703f634
Compare
Add generateIpClearanceLicenseReport, which writes build/generated/license/ip-clearance-licenses.xml: the "all items depended upon by the project are covered by approved licenses" row of the Incubator IP-clearance status document, listing group:artifact and license for every bundled dependency as reported by the CycloneDX SBOM. A dependency missing from the SBOM fails the task, the same completeness gate the binary LICENSE uses. Add the generateLicenseDocs aggregate (LICENSE, NOTICE and the IP-clearance row) and make check depend on it, so a plain ./gradlew build leaves all three in build/generated/license/. CI uploads that directory as the solr-mcp-license-docs artifact. Extract the SBOM license lookup into a shared SbomLicenses helper used by both license tasks. Document the row on the Licensing & Notices page, in AGENTS.md and in buildSrc/README.md, including a table of the generated files with the Gradle task that produces each. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> Signed-off-by: Aditya Parikh <aditya.m.parikh@gmail.com>
adityamparikh
force-pushed
the
feat/ip-clearance-license-row
branch
from
October 5, 2026 01:07
3322b74 to
a3ce531
Compare
This was referenced Oct 5, 2026
Contributor
Author
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Generates the "all items depended upon by the project are covered by approved licenses" row of the Incubator IP-clearance status document from the CycloneDX SBOM, and documents how and where it shows up. The row has to be refreshed for every release, so it is built, not hand-written.
generateIpClearanceLicenseReport(new) writesbuild/generated/license/ip-clearance-licenses.xml: a single<tr>in the format used by Incubator IP clearance documents (completion date, the standard checklist wording, a<ul>ofgroup:artifact — licensefor every bundled dependency). It uses the same inputs asgenerateBinaryLicense: the shippedproductionRuntimeClasspathand the SBOM. A dependency missing from the SBOM fails the task.generateLicenseDocs(new aggregate) runsgenerateBinaryLicense,generateBinaryNoticeand the IP-clearance task, so all license documents land inbuild/generated/license/. It is part ofcheck, so a plain./gradlew buildproduces all three.build-and-publish.yml): after./gradlew build, uploadsbuild/generated/license/as thesolr-mcp-license-docsartifact (30 days), next to the SBOM artifact.docs/site/.../licensing.md) covering how to generate it, where it shows up locally and in CI, what it contains and how to use it; plusAGENTS.mdandbuildSrc/README.md.SbomLicenseshelper used by both license tasks.What the build generates
LICENSEMETA-INF/LICENSEin the executable JAR and the Docker imagesLICENSEplus an appendix listing every bundled dependency (version, license, link), read from the CycloneDX SBOM and filtered to the shippedproductionRuntimeClasspathgenerateBinaryLicenseNOTICEMETA-INF/NOTICEin the executable JAR and the Docker imagesNOTICEplus theMETA-INF/NOTICEfiles lifted verbatim (de-duplicated) from the bundled jarsgenerateBinaryNoticeip-clearance-licenses.xml<tr>row<ul>ofgroup:artifact — license(no versions)generateIpClearanceLicenseReportapplication.cdx.json(the SBOM)META-INF/sbom/application.cdx.json, served at/actuator/sbom/applicationin HTTP modecyclonedxBomLICENSE,NOTICEandip-clearance-licenses.xmlare written tobuild/generated/license/; the SBOM is written tobuild/reports/.generateLicenseDocsruns the first three tasks, andcheck(and sobuild) depends on it. TheLICENSEand IP-clearance tasks depend oncyclonedxBombecause they read the SBOM; theNOTICEtask reads the bundled jars instead.Design notes
generateBinaryLicense, so wiring it intocheckadds no new failure condition.Testing
./gradlew -p buildSrc test— 14 tests pass, including a well-formed-XML check on the generated row../gradlew build(JDK 25) — 421 tests, 0 failed, 0 skipped; leavesLICENSE,NOTICEand a well-formedip-clearance-licenses.xmllisting 157 dependencies inbuild/generated/license/../gradlew spotlessCheckpasses.For review
Two SBOM labels look imprecise and should be checked upstream before any "Category A/B" sign-off:
org.antlr:antlr-runtime/ST4are labelled "BSD licence" / BSD-4-Clause (believed to be BSD-3-Clause), andorg.springaicommunity:mcp-server-securityis labelled "Apache-1.0" (believed to be Apache-2.0).@epugh, please review.
🤖 Generated with Claude Code