Skip to content

docs: add the IP-clearance license rows for the incubator form - #248

Open
adityamparikh wants to merge 5 commits into
apache:mainfrom
adityamparikh:docs/ip-clearance-license-row
Open

adityamparikh wants to merge 5 commits into
apache:mainfrom
adityamparikh:docs/ip-clearance-license-row

Conversation

@adityamparikh

@adityamparikh adityamparikh commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Adds the "Check and make sure that all items depended upon by the project are covered by one or more of the following approved licenses" row of the IP-clearance status document for #216, as paste-ready XML <tr> fragments. Each row lists direct runtime dependencies only (group:artifact — license); transitive dependencies are out of scope.

File Covers Entries
dev-docs/ip-clearance-licenses-solr-mcp-server.xml The code base as imported: adityamparikh/solr-mcp-server @ cda37f29, the last commit of that repository and an ancestor of main 6
dev-docs/ip-clearance-licenses.xml main @ 93ffdb79 14
  • The dependencies are the productionRuntimeClasspath entries declared directly in each build.gradle.kts; the OpenTelemetry BOM is a version platform, not a jar, so it is not listed. Licenses come from the CycloneDX SBOM, except mcp-server-security, whose POM label the SBOM misreads as Apache-1.0; the project is Apache-2.0.
  • Every entry is Apache-2.0 or BSD-2-Clause.
  • IP clearance is a one-time job, so the rows are committed files, not build output.
  • dev-docs/** is already excluded from RAT, so the fragments carry no license header and can be pasted as is.

Testing

  • ./gradlew build rat (JDK 25): 421 tests, 0 failed, 0 skipped; RAT passes.
  • Both files are well-formed XML (xmllint --noout).

Refs #216

@epugh, please review.

🤖 Generated with Claude Code

The "all items depended upon are covered by approved licenses" row of the
IP-clearance status document (apache#216), as a paste-ready XML <tr>. It lists
the 157 runtime dependencies bundled in the executable JAR with the
license the CycloneDX SBOM reports for each, generated once from main
@ 93ffdb7. IP clearance is a one-time job, so the row is committed as a
file rather than produced by the build.

Refs apache#216

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Signed-off-by: Aditya Parikh <aditya.m.parikh@gmail.com>
adityamparikh and others added 3 commits October 5, 2026 13:27
Its published POM names the license only as "Apache License", with a
URL to LICENSE-2.0.txt, which the CycloneDX plugin maps to Apache-1.0.
The project is Apache-2.0 (github.com/spring-ai-community/mcp-security).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Signed-off-by: Aditya Parikh <aditya.m.parikh@gmail.com>
ST4 and antlr-runtime 3 are under the three-clause BSD license (see
LICENSE.txt in antlr/stringtemplate4). Their POMs name it only as
"The BSD License" / "BSD licence", which the SBOM reports as
BSD-4-Clause and as free text.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Signed-off-by: Aditya Parikh <aditya.m.parikh@gmail.com>
Transitive dependencies are not part of the check, so the row now lists
the project's direct runtime dependencies as declared in
build.gradle.kts (14, instead of all 157 bundled jars).

Also add the same row for the code base as it was imported,
adityamparikh/solr-mcp-server @ cda37f2 (the last commit of that
repository and an ancestor of main): its 6 direct runtime dependencies.

Refs apache#216

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Signed-off-by: Aditya Parikh <aditya.m.parikh@gmail.com>
@adityamparikh adityamparikh changed the title docs: add the IP-clearance license row for the incubator form docs: add the IP-clearance license rows for the incubator form Oct 5, 2026
Match the accepted Solr Orbit row, which ends by stating the ASF license
categories of the listed dependencies.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Signed-off-by: Aditya Parikh <aditya.m.parikh@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant