[ 
https://issues.apache.org/jira/browse/HADOOP-12893?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=15342115#comment-15342115
 ] 

Arpit Agarwal commented on HADOOP-12893:
----------------------------------------

Thanks for the explanation [~xiaochen]. For jcip, their licensing terms appear 
to require we include the copyright and license notice. I can make this update 
if we agree it is necessary.
{code}
Any republication or derived work distributed in source code form
must include this copyright and license notice.
{code}

Also I think we need to include references to bundled permissively-licensed 
works in LICENSE.txt as Sean described above.
bq. That's correct, you should not include anything from BSD or MIT licensed 
deps in NOTICE. That includes bundled JARs; in both source and bundled binary 
cases you should have a reference in the LICENSE file for the included work. 
(ref licensing howto on permissive licenses)
http://www.apache.org/dev/licensing-howto.html#permissive-deps

e.g. we bundle okio but there is no reference to it in NOTICE.txt. I still 
haven't done a full audit so there may be more. I can help fix this too.

> Verify LICENSE.txt and NOTICE.txt
> ---------------------------------
>
>                 Key: HADOOP-12893
>                 URL: https://issues.apache.org/jira/browse/HADOOP-12893
>             Project: Hadoop Common
>          Issue Type: Bug
>    Affects Versions: 2.8.0, 2.7.3, 2.6.5, 3.0.0-alpha1
>            Reporter: Allen Wittenauer
>            Assignee: Xiao Chen
>            Priority: Blocker
>             Fix For: 2.7.3, 2.6.5
>
>         Attachments: HADOOP-12893-addendum-branch-2.7.01.patch, 
> HADOOP-12893.002.patch, HADOOP-12893.003.patch, HADOOP-12893.004.patch, 
> HADOOP-12893.005.patch, HADOOP-12893.006.patch, HADOOP-12893.007.patch, 
> HADOOP-12893.008.patch, HADOOP-12893.009.patch, HADOOP-12893.01.patch, 
> HADOOP-12893.011.patch, HADOOP-12893.012.patch, HADOOP-12893.10.patch, 
> HADOOP-12893.branch-2.01.patch, HADOOP-12893.branch-2.6.01.patch, 
> HADOOP-12893.branch-2.7.01.patch, HADOOP-12893.branch-2.7.02.patch, 
> HADOOP-12893.branch-2.7.3.01.patch
>
>
> We have many bundled dependencies in both the source and the binary artifacts 
> that are not in LICENSE.txt and NOTICE.txt.



--
This message was sent by Atlassian JIRA
(v6.3.4#6332)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to