docs: add the IP-clearance license rows for the incubator form - #248
Open
adityamparikh wants to merge 5 commits into
Open
adityamparikh wants to merge 5 commits into
adityamparikh wants to merge 5 commits into
Conversation
The "all items depended upon are covered by approved licenses" row of the IP-clearance status document (apache#216), as a paste-ready XML <tr>. It lists the 157 runtime dependencies bundled in the executable JAR with the license the CycloneDX SBOM reports for each, generated once from main @ 93ffdb7. IP clearance is a one-time job, so the row is committed as a file rather than produced by the build. Refs apache#216 Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Signed-off-by: Aditya Parikh <aditya.m.parikh@gmail.com>
Its published POM names the license only as "Apache License", with a URL to LICENSE-2.0.txt, which the CycloneDX plugin maps to Apache-1.0. The project is Apache-2.0 (github.com/spring-ai-community/mcp-security). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Signed-off-by: Aditya Parikh <aditya.m.parikh@gmail.com>
ST4 and antlr-runtime 3 are under the three-clause BSD license (see LICENSE.txt in antlr/stringtemplate4). Their POMs name it only as "The BSD License" / "BSD licence", which the SBOM reports as BSD-4-Clause and as free text. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Signed-off-by: Aditya Parikh <aditya.m.parikh@gmail.com>
Transitive dependencies are not part of the check, so the row now lists the project's direct runtime dependencies as declared in build.gradle.kts (14, instead of all 157 bundled jars). Also add the same row for the code base as it was imported, adityamparikh/solr-mcp-server @ cda37f2 (the last commit of that repository and an ancestor of main): its 6 direct runtime dependencies. Refs apache#216 Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Signed-off-by: Aditya Parikh <aditya.m.parikh@gmail.com>
Match the accepted Solr Orbit row, which ends by stating the ASF license categories of the listed dependencies. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Signed-off-by: Aditya Parikh <aditya.m.parikh@gmail.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Adds the "Check and make sure that all items depended upon by the project are covered by one or more of the following approved licenses" row of the IP-clearance status document for #216, as paste-ready XML
<tr>fragments. Each row lists direct runtime dependencies only (group:artifact — license); transitive dependencies are out of scope.dev-docs/ip-clearance-licenses-solr-mcp-server.xmlcda37f29, the last commit of that repository and an ancestor ofmaindev-docs/ip-clearance-licenses.xmlmain@93ffdb79productionRuntimeClasspathentries declared directly in eachbuild.gradle.kts; the OpenTelemetry BOM is a version platform, not a jar, so it is not listed. Licenses come from the CycloneDX SBOM, exceptmcp-server-security, whose POM label the SBOM misreads as Apache-1.0; the project is Apache-2.0.dev-docs/**is already excluded from RAT, so the fragments carry no license header and can be pasted as is.Testing
./gradlew build rat(JDK 25): 421 tests, 0 failed, 0 skipped; RAT passes.xmllint --noout).Refs #216
@epugh, please review.
🤖 Generated with Claude Code