Thanks Justin for pointing out the license issues. The issues have been resolved via PRs #11761 <https://github.com/apache/gravitino/pull/11761> and #11750 <https://github.com/apache/gravitino/pull/11750>, so I would like to cancel this vote. The RC5 vote has been initiated. See <https://lists.apache.org/thread/ohcwlw6pjghccz7lc3o0l4w08ygfgz1y> for more details.
Thanks all for the test and vote. Best, Minghuang Li On 2026/06/22 05:06:57 Justin Mclean wrote: > Hi, > > Sorry, it's still -1 (binding) from me. > > Signatures, etc., are fine, but there are a few issues: > > - In the binary NOTICE, the required notices for bundled Apache Arrow and > Apache Kafka are not propagated. In the source NOTICE, the RC4 LICENSE > additions were not added: Apache Paimon and Apache Doris should be added > (Iceberg is already present, and Lance Namespace does not need anything, as > it ships no NOTICE file). [1] > > - Export control for Bouncy Castle. Bouncy Castle is a new cryptographic > component in 1.3. The required ECCN cryptographic software notice is missing > from the README, the entry on the ASF exports page, and the BIS/ENC > notification, which must be completed before distribution. [2] > > - Category X dependency: Aviator (LGPL-3.0) in the binaries. > aviator-5.4.3.jar is bundled in the main binary (libs/and > iceberg-rest-server/libs/) and in the standalone iceberg-rest-server binary. > Its licence is LGPL-3.0, confirmed from Aviator's own upstream licenses.txt. > LGPL is Category X and must not be distributed in an Apache release. As this > is not a new issue, it might be worth discussing it on legal-discuss to > determine whether other releases need to be corrected/removed. [3] > > Kind Regards, > Justin > > 1. https://infra.apache.org/licensing-howto.html#alv2-dep > 2. https://infra.apache.org/crypto.html > 3. https://www.apache.org/legal/resolved.html#prohibited
