goutamadwant commented on code in PR #12309:
URL: https://github.com/apache/seatunnel/pull/12309#discussion_r4003789291
##########
seatunnel-connectors-v2/connector-file/connector-file-base/pom.xml:
##########
@@ -122,6 +122,11 @@
<version>${commons.lang3.version}</version>
</dependency>
+ <dependency>
+ <groupId>org.apache.commons</groupId>
+ <artifactId>commons-secure-xml</artifactId>
Review Comment:
This adds `commons-secure-xml-1.0.0.jar` as a compile/runtime dependency,
but the release inventory is not updated.
I confirmed that the connector's runtime dependency tree includes this jar,
while the current diff has no matching entry in
`tools/dependencies/known-dependencies.txt`,
`seatunnel-dist/release-docs/LICENSE`, or `seatunnel-dist/release-docs/NOTICE`.
The dependency-license check performs an exact runtime-jar allowlist
comparison, so it will fail after the Build workflow is authorized, and the
binary release metadata would remain incomplete.
Please add the dependency and its license/NOTICE metadata following the four
steps in `docs/en/developer/new-license.md`.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]