alright

On Thu, Aug 27, 2026 at 1:23 PM Aman Mittal <[email protected]>
wrote:

> Hi Aleks,
>
> If you're referring to https://github.com/apache/fineract/pull/6340, it
> is a work-in-progress draft PR that I’m using to test the implementation on
> my fork, as the change relates to GitHub Actions. I opened the discussion
> separately to keep the proposal transparent and get feedback on the
> approach while working on the implementation. In fact, the discussion
> helped simplify the implementation. I was initially thinking of using the
> CycloneDX dependency data, but your suggestion pointed me towards keeping
> the check contained in a single file, which makes the approach much simpler.
>
>
>
>
>
>
> On Thu, Aug 27, 2026 at 3:25 PM Aleksandar Vidakovic <
> [email protected]> wrote:
>
>> .... so was there then a need to open a discussion in the first place
>> when we have the PR already?
>>
>>
>> On Thu, Aug 27, 2026 at 10:49 AM Aman Mittal <
>> [email protected]> wrote:
>>
>>> Hi Aleks
>>>
>>> you are right Com.github.jk1.dependency-licence-report is already
>>> applied but it's for informational purposes only.  But nothing gates it
>>> based on content. The main goal is that we can catch problematic dependency
>>> on PR itself. Right now what I am proposing if to use existing plugins that
>>> are already in fineract and draft a GitHub action based on that. Note:
>>> required dependency is already there. What we need it to automate this in
>>> actions file. What i am proposing is to enforce as CI check based on plugin
>>> results no new scanner is built.
>>>
>>> Regards,
>>> Aman
>>>
>>>
>>> On Thu, 27 Aug, 2026, 1:30 pm Aleksandar Vidakovic, <
>>> [email protected]> wrote:
>>>
>>>> Hi,
>>>>
>>>> ... not sure about the development part... there are a ton of Gradle
>>>> plugins out there that do this, so wouldn't advise to put something
>>>> together yourself; I think that would be wasted effort for an already
>>>> solved problem... e.g. this one comes to mind
>>>> https://github.com/jk1/Gradle-License-Report... technically I think we
>>>> are required to list all licenses of all artifacts we use somewhere (I
>>>> think the NOTICE file is usually the place if I'm not mistaken, maybe could
>>>> be LICENSE).
>>>>
>>>> On Thu, Aug 27, 2026 at 8:23 AM Aman Mittal <[email protected]>
>>>> wrote:
>>>>
>>>>> Hi all,
>>>>>
>>>>> I like to propose adding a CI check for Category X transitive
>>>>> dependencies for Fineract.
>>>>>
>>>>> At present, there is no check in the build that catches this. A
>>>>> Category X license could be introduced transitively through an otherwise
>>>>> unrelated dependency bump and remain unnoticed until a release audit. Or
>>>>> even direct dependency license changes  [One example i recall is at the
>>>>> time of liquibase where they changes their license on the new release] and
>>>>> sometime needs manual reviews
>>>>>
>>>>> What's already in place, and why it doesn't cover this:
>>>>>
>>>>> - Apache RAT (./gradlew rat) already runs in CI, but RAT checks
>>>>> whether our own source files have the correct Apache license headers. It
>>>>> does not audit dependency licenses, including transitive dependencies,
>>>>> so it is not a substitute for dependency license compliance checking.
>>>>>
>>>>> - CycloneDX is already applied at the root of build.gradle and
>>>>> generates a complete SBOM. However, nothing currently consumes the SBOM to
>>>>> enforce license policy.
>>>>>
>>>>> This would involve generating an SBOM for the `develop` branch and for
>>>>> the PR head, then comparing the changes to flag any dependency using a
>>>>> license that requires review. [This will also keep the existing
>>>>> dependencies as it is but will flag for new changes]
>>>>>
>>>>> I'd like to gather feedback and reach consensus on the approach before
>>>>> starting implementation. Please share your thoughts, concerns, or
>>>>> objections.
>>>>>
>>>>> Once there is rough agreement, I'll follow up with a JIRA ticket to
>>>>> track the implementation.
>>>>>
>>>>> Thanks and Regards
>>>>> Aman
>>>>>
>>>>

Reply via email to