Thanks Justin for pointing out the license issues. The issues have been 
resolved via PRs #11761 <https://github.com/apache/gravitino/pull/11761> and 
#11750 <https://github.com/apache/gravitino/pull/11750>, so I would like to 
cancel this vote. The RC5 vote has been initiated. See 
<https://lists.apache.org/thread/ohcwlw6pjghccz7lc3o0l4w08ygfgz1y> for more 
details.

Thanks all for the test and vote. 

Best,
Minghuang Li

On 2026/06/22 05:06:57 Justin Mclean wrote:
> Hi,
> 
> Sorry, it's still -1 (binding) from me.
> 
> Signatures, etc., are fine, but there are a few issues:
> 
> - In the binary NOTICE, the required notices for bundled Apache Arrow and 
> Apache Kafka are not propagated. In the source NOTICE, the RC4 LICENSE 
> additions were not added: Apache Paimon and Apache Doris should be added 
> (Iceberg is already present, and Lance Namespace does not need anything, as 
> it ships no NOTICE file). [1]
> 
> - Export control for Bouncy Castle. Bouncy Castle is a new cryptographic 
> component in 1.3. The required ECCN cryptographic software notice is missing 
> from the README, the entry on the ASF exports page, and the BIS/ENC 
> notification, which must be completed before distribution. [2]
> 
> - Category X dependency: Aviator (LGPL-3.0) in the binaries. 
> aviator-5.4.3.jar is bundled in the main binary (libs/and 
> iceberg-rest-server/libs/) and in the standalone iceberg-rest-server binary. 
> Its licence is LGPL-3.0, confirmed from Aviator's own upstream licenses.txt. 
> LGPL is Category X and must not be distributed in an Apache release. As this 
> is not a new issue, it might be worth discussing it on legal-discuss to 
> determine whether other releases need to be corrected/removed. [3]
> 
> Kind Regards,
> Justin
> 
> 1. https://infra.apache.org/licensing-howto.html#alv2-dep
> 2. https://infra.apache.org/crypto.html
> 3. https://www.apache.org/legal/resolved.html#prohibited

Reply via email to