Frun1na opened a new issue, #5085:
URL: https://github.com/apache/rocketmq-dashboard/issues/5085
### Before creating
- [x] I have searched the existing issues and found no duplicate.
- [x] I have checked the latest `rocketmq-studio` branch where this problem
still exists.
### Bug report
**Which page or component**
Server build: `mvn package` → `binary-license-gate` (maven-antrun,
`server/scripts/legal.py jar ...`), bound to the default `package` phase in
`server/pom.xml`.
**What happened**
`mvn -DskipTests package` fails on every run at tip `a562601d`:
```
[ERROR] Failed to execute goal
org.apache.maven.plugins:maven-antrun-plugin:3.2.0:run (binary-license-gate)
on project rocketmq-studio: ... exec returned: 1
```
Reproducing the gate command directly shows why — the gate requires
**every** dependency JAR inside `BOOT-INF/lib/` to carry its complete license
text, but the vast majority of Maven-published JARs do not embed one:
```
$ python3 scripts/legal.py jar target/rocketmq-studio-3.0.0.jar --output
target/legal
license gate: release license gate failed:
HikariCP-7.0.2.jar: missing complete upstream LICENSE/COPYING; ...
ST4-4.3.4.jar: missing complete upstream LICENSE/COPYING; ...
... (164 jars in total)
Spring Boot loader: missing the original META-INF/LICENSE.txt or NOTICE.txt
```
I verified one representative: `HikariCP-7.0.2.jar` (extracted from the fat
JAR) contains 98 entries and none named LICENSE/NOTICE/COPYING. The gate's own
synthetic tests only ever exercise a one-component fixture (`legal_test.py`
reports "1 actual components"), so this was never run against the real
dependency set. Consequences:
- `mvn package` fails for every developer;
- the CI / docker compose default image build (server/Dockerfile stage
`build`) fails at the same step;
- the same batch also introduced the web license gate failure tracked in
#5084 (fixed by #5083).
**Expected behaviour**
`mvn -DskipTests package` should complete. The gate's contract needs a
decision before it can pass, e.g.:
- vendor the complete license texts for the dependencies that omit them,
with pinned checksums like the web side does
(`web/licenses/toggle-selection-1.0.6/LICENSE` pattern) — but that is ~164
texts to source and verify; or
- require license materials only for a defined release profile /
redistribute the license obligations differently; or
- relax the per-jar requirement to a curated allowlist of components that
actually ship license files.
I can help implement whichever direction is chosen, but sourcing and
verifying 164 license texts is not something I can do unilaterally, hence
issue-first.
**Environment**
- RocketMQ Studio: upstream `rocketmq-studio` tip `a562601d`
- `mvn -B -ntp package -DskipTests`, OpenJDK 21, Maven 3.9.9
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]