Repository navigation
Checks on artifact licensing #8808
parshimers
started this conversation in
General
Replies: 1 comment
|
I agree that each fix should explain why the existing checks missed it. The linked issues suggest a coverage gap: headers can pass while bundled datasets, images, or vendored tools still lack licensing information. One useful approach from AsterixDB is reusable license templates that I believe also records bundled image paths and attribution. Could we use a shared provenance record for Texera’s datasets, images, and copied code to generate the licensing sections for each distribution, then check those records against the packaged contents? |
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Hi folks,
We already have some checks on artifact licensing, via actions and other things. However, these don't seem to be enough. In 1.2.0 there were some artifacts that slipped though. In 1.2.1, which should only be a bugfix release, we still have regressions:
#8799
#8800
#8801
#8802
For each of these, just fixing the specific file(s) is not enough. It needs to be understood why it fell through the existing checks, and what can be done to avoid making the same or a similar mistake in the future. We have very helpful folks like PJ in the Incubator to help us at this point, but we will not have them for long. It needs to be shown that we have our bases covered in this area and can be trusted to catch these issues ourselves.
Thoughts?
All reactions